logo

Root Access at Risk: Perl Injection and Symlink Flaws Hit cPanel & WHM

ID: d8c3abad-9aa1-5b0e-a78e-e4a29c8ca75f

STIX ID: report--d8c3abad-9aa1-5b0e-a78e-e4a29c8ca75f

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-05-11

Date Updated: 2026-05-22

Author: Ddos

...
...

Security advisory: Three vulnerabilities were disclosed in cPanel & WHM and WP Squared — two high-severity (CVSS 8.8) issues allowing Perl code injection and unsafe symlink handling that can lead to remote code execution, denial-of-service, or privilege escalation, and one moderate (CVSS 4.3) arbitrary file-read flaw that can expose sensitive files. Administrators are instructed to update to the listed patched versions (and WP Squared 11.136.1.10+), with special updates provided for CentOS/CloudLinux 6 environments; update commands and verification steps are included.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.