Wednesday , September 30 2026
cPanel

cPanel Flaw Lets Hosting Accounts With Mail Privileges Execute Code as Root

cPanel has shared CVE-2026-67401, a serious SQL injection flaw in EmailTrack. This flaw could allow attackers with permission to take full control of affected servers. cPanel announced this issue on September 8, 2026. They say that an attacker needs a valid cPanel account with email rights to use this weakness.

This requirement stops unauthorized use of the internet, but it can still seriously affect shared-hosting providers, managed servers, and groups with many cPanel users. CVE-2026-67401 is a weakness in cPanel’s EmailTrack feature that allows SQL injection. EmailTrack checks and looks at email sending activities, like message paths and delivery details.

Apple Zero-Day Exploited: Pentagon Data Breach Reportedly Exposes Sensitive Data of 3 Million People

Apple has launched iOS 26.7.1 and iPadOS 26.7.1 to fix a serious zero-day flaw that it believes might have been...
Read More
Apple Zero-Day Exploited: Pentagon Data Breach Reportedly Exposes Sensitive Data of 3 Million People

JadePuffer Agentic AI targets and destroys Azure’s cloud resources

The JadePuffer ransomware group is attacking Azure users with agent-based attacks that gather information, steal passwords, and damage key components. The...
Read More
JadePuffer Agentic AI targets and destroys Azure’s cloud resources

“InfoSecCon-2026: Bangladesh’s Cybersecurity Leaders Unite to Shape a Safer Digital Future”

The 5th Edition of InfoSecCon-2026, a premier cybersecurity-focused event, has been successfully completed with the participation of cybersecurity professionals, technology...
Read More
“InfoSecCon-2026: Bangladesh’s Cybersecurity Leaders Unite to Shape a Safer Digital Future”

Microsoft Patches CVSS 10.0 Azure AI Foundry Vulnerability Allowing Privilege Escalation

Microsoft has fixed a serious security flaw in Azure AI Foundry that could let bad actors gain privilege escalation. The...
Read More
Microsoft Patches CVSS 10.0 Azure AI Foundry Vulnerability Allowing Privilege Escalation

AWS is unable to restore access to Bahrain, one UAE cloud data zone after war damage

Amazon Web Services cannot restore access to its cloud-computing facility in Bahrain and ‌one of three data-hosting zones in the...
Read More
AWS is unable to restore access to Bahrain, one UAE cloud data zone after war damage

Cisco Warns of Critical ISE 0-Day Flaw and Hackers Allegedly Selling Fortinet FortiGate 1-Day Flaw

A threat actor is allegedly offering a private remote code execution exploit for Fortinet FortiGate SSL VPN appliances, claiming that...
Read More
Cisco Warns of Critical ISE 0-Day Flaw and Hackers Allegedly Selling Fortinet FortiGate 1-Day Flaw

Anthropic prepares “Claude Money” to analyze bank account and financial data

Anthropic is making a new Claude feature called “Money.” It's a separate tab in the mobile app. The new interface...
Read More
Anthropic prepares “Claude Money” to analyze bank account and financial data

GhostCode Phishing Kit Evades Microsoft 365 MFA to Hijack Accounts in 78 Seconds

GhostCode is a new phishing kit that changes a regular Microsoft 365 sign-in into an account theft. It doesn't need...
Read More
GhostCode Phishing Kit Evades Microsoft 365 MFA to Hijack Accounts in 78 Seconds

CISA Warns of Cisco Secure Email Gateway 0-Day Flaw Actively Exploited in Attacks

CISA has added a serious Cisco Secure Email Gateway flaw to its list of known exploits. They warn that attackers...
Read More
CISA Warns of Cisco Secure Email Gateway 0-Day Flaw Actively Exploited in Attacks

VPN flaw exposed 246,000 personnel records in japan

Japan’s Digital Agency found a data leak that may have exposed about 246,000 records with personal information of government workers....
Read More
VPN flaw exposed 246,000 personnel records in japan

A bad user with access can misuse the weak system to make any files on the server. Creating any files is very risky in a hosting setup because it allows attackers to put harmful content in important places.

Cpanel Vulnerability

CPanel said that successful exploitation can lead to code running as the root user. Root access gives full control over the operating system. This allows attackers to reach hosted websites, databases, email accounts, backups, configuration files, and credentials stored on the server.

An attacker with full access could install methods to stay hidden, add bad software, change website content, steal customer information, disable security tools, or use the hacked server to attack again.

Compromising one special cPanel account in shared hosting could endanger other customers on the same server. Security expert Ali Mustafa, known as (nd abe)1526, found the weakness. This weakness impacts all cPanel/WHM versions that are still supported before the fixed builds:

cPanel/WHM Release Patched Version
cPanel & WHM 11.110 11.110.0.143
cPanel & WHM 11.134 11.134.0.55
cPanel & WHM 11.136 11.136.0.39
cPanel & WHM 11.138 11.138.0.4
WP2 release 11.138.1.9

Server admins need to check their cPanel/WHM version right away and upgrade to a fixed release. Groups using managed hosting should also ask their provider to make sure the update is done on all affected systems.

The most important fix is to update cPanel/WHM to the newest patched version. Admins should not just limit public access because attacks need a real logged-in account, not anonymous access.

Security teams should check cPanel accounts that have email permissions and take away unneeded access. Turn on passwords and multi-factor authentication for accounts that might be unsafe or are not needed anymore.

Administrators should look for strange files, unexpected changes to web folders, changed settings files, odd root processes, and unknown outgoing network connections. Checking cPanel, web-server, login, and system logs may help find signs of exploitation attempts.

Check Also

Secure Email Gateway

CISA Warns of Cisco Secure Email Gateway 0-Day Flaw Actively Exploited in Attacks

CISA has added a serious Cisco Secure Email Gateway flaw to its list of known …