logo

cPanel, WHM Release Fixes for Three New Vulnerabilities — Patch Now

ID: bef7e5df-944f-5939-8cf8-4bdfa2f9b208

STIX ID: report--bef7e5df-944f-5939-8cf8-4bdfa2f9b208

Feed Name: The Hacker News

Threat Score
70/100

Date Published: 2026-05-09

Date Updated: 2026-05-11

Author: [email protected] (The Hacker News)

...
...

cPanel published updates to remediate three vulnerabilities in cPanel/WHM—including an arbitrary file read (CVE-2026-29201), arbitrary Perl code execution (CVE-2026-29202), and unsafe symlink handling that can cause DoS or privilege escalation (CVE-2026-29203)—and provided patched version numbers; while these new flaws have no reported in-the-wild exploitation, the advisory warns alongside a recent, separately weaponized cPanel zero-day that delivered Mirai botnet variants and the 'Sorry' ransomware, and advises customers to update immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.