logo

CISA warns of critical CentOS Web Panel bug exploited in attacks

ID: 5b7ec3b0-b664-5a4f-9cd0-81f0dceaa601

STIX ID: report--5b7ec3b0-b664-5a4f-9cd0-81f0dceaa601

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2025-11-05

Date Updated: 2026-07-18

Author: Bill Toulas

...
...

CISA warns that CVE-2025-48703—an unauthenticated remote command injection in CentOS Web Panel's file-manager changePerm endpoint—has been exploited; a researcher published a PoC and the vendor released a patch (v0.9.8.1205). The vulnerability was added to CISA’s KEV catalog and federal agencies were given a deadline to patch or stop using the product.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.