logo

CVE-2022-44877, critical RCE in CentOS Control Web Panel exploited in the wild: everything you need to know

ID: ed44c480-3153-50be-b55e-ad8173f267b7

STIX ID: report--ed44c480-3153-50be-b55e-ad8173f267b7

Feed Name: Wiz Blog

Threat Score
80/100

Date Published: 2023-01-17

Date Updated: 2026-05-01

...
...

CVE-2022-44877 is a critical remote code execution vulnerability in CentOS Control Web Panel (CWP) with a CVSS score of 9.8 that allows unauthenticated command execution (often as root). A public proof-of-concept was released and mass exploitation attempts were observed in the wild with several IP addresses identified; operators should patch to CWP version 0.9.8.1147 or later and monitor for the listed indicators of compromise.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.