New cPanel vulnerabilities could allow file access and remote code execution
ID: b030e42c-4117-5dee-90c4-0360a315f4f0
STIX ID: report--b030e42c-4117-5dee-90c4-0360a315f4f0
Feed Name: Security Affairs
cPanel released patches for three vulnerabilities allowing arbitrary file reads (CVE-2026-29201), authenticated arbitrary Perl execution (CVE-2026-29202), and unsafe symlink/chmod handling possibly leading to privilege escalation or DoS (CVE-2026-29203). While no active exploitation has been reported for those three flaws, the report highlights a separate critical authentication-bypass zero-day (CVE-2026-41940) that has been exploited in the wild to deploy Mirai botnet variants and may expose thousands of instances; users are urged to install updates and use detection tools.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
