Wednesday , September 9 2026
cPanel

cPanel Flaw Lets Hosting Accounts With Mail Privileges Execute Code as Root

cPanel has shared CVE-2026-67401, a serious SQL injection flaw in EmailTrack. This flaw could allow attackers with permission to take full control of affected servers. cPanel announced this issue on September 8, 2026. They say that an attacker needs a valid cPanel account with email rights to use this weakness.

This requirement stops unauthorized use of the internet, but it can still seriously affect shared-hosting providers, managed servers, and groups with many cPanel users. CVE-2026-67401 is a weakness in cPanel’s EmailTrack feature that allows SQL injection. EmailTrack checks and looks at email sending activities, like message paths and delivery details.

Nightmare Eclipse Drops New Microsoft Defender ‘ShieldCrash’ zero-day

An unknown security expert called Nightmare Eclipse has drops a new Microsoft Defender flaw called "ShieldCrash" right after Microsoft released...
Read More
Nightmare Eclipse Drops New Microsoft Defender ‘ShieldCrash’ zero-day

cPanel Flaw Lets Hosting Accounts With Mail Privileges Execute Code as Root

cPanel has shared CVE-2026-67401, a serious SQL injection flaw in EmailTrack. This flaw could allow attackers with permission to take...
Read More
cPanel Flaw Lets Hosting Accounts With Mail Privileges Execute Code as Root

FortiSandbox, FortiOS, FortiProxy ZTNA flaws unveil, while Fortigate firewall actively exploited

An ongoing attack is focused on FortiGate firewalls. Hackers use a serious flaw to install a special Node.js remote access...
Read More
FortiSandbox, FortiOS, FortiProxy ZTNA flaws unveil, while Fortigate firewall actively exploited

Microsoft Patch Tuesday September 2026 Fixed 973 Flaws Fixed, 2 Zero-Days

Microsoft shared its September 2026 security updates on September 8. These updates fix 973 flaws, including two serious issues that...
Read More
Microsoft Patch Tuesday September 2026  Fixed 973 Flaws Fixed, 2 Zero-Days

A single call: ShinyHunters Gained Access to 6 Million Customers’ Records

A single phone call caused one of the biggest data breaches in Dutch history. In early February 2026, the big...
Read More
A single call: ShinyHunters Gained Access to 6 Million Customers’ Records

The first zero-click worm to spread through WeChat calls across iOS and Android

A worm called “WeWorm” can spread through WeChat voice calls on iOS and Android. It takes over a target's WeChat...
Read More
The first zero-click worm to spread through WeChat calls across iOS and Android

USA Bimbo Bakeries Confirms Data Stolen in Oracle EBS Zero-Day Attack

Bimbo Bakeries USA has confirmed that hackers stole employee data by exploiting a zero-day vulnerability in Oracle’s E-Business Suite (EBS). In...
Read More
USA Bimbo Bakeries Confirms Data Stolen in Oracle EBS Zero-Day Attack

ALERT
Roundcube Webmail fixes 12 security flaws, including zero-click XSS and SSRF bypass

Roundcube Webmail has given security updates for its 1.6 LTS and 1.7 branches. These updates fix 12 problems that could...
Read More
ALERT  Roundcube Webmail fixes 12 security flaws, including zero-click XSS and SSRF bypass

New HOOKEDGE Backdoor Deployed by Hackers in European Espionage

Russian-backed hacker group BlueDelta, also known as APT28, Fancy Bear, and Forest Blizzard, has used a small Windows backdoor called...
Read More
New HOOKEDGE Backdoor Deployed by Hackers in European Espionage

Hackers Exploiting MikroTik RouterOS Flaw Gaining Network Access

Attackers are misusing MikroTik routers through their Secure Shell (SSH) service, which can be accessed from the internet, to take...
Read More
Hackers Exploiting MikroTik RouterOS Flaw Gaining Network Access

A bad user with access can misuse the weak system to make any files on the server. Creating any files is very risky in a hosting setup because it allows attackers to put harmful content in important places.

Cpanel Vulnerability

CPanel said that successful exploitation can lead to code running as the root user. Root access gives full control over the operating system. This allows attackers to reach hosted websites, databases, email accounts, backups, configuration files, and credentials stored on the server.

An attacker with full access could install methods to stay hidden, add bad software, change website content, steal customer information, disable security tools, or use the hacked server to attack again.

Compromising one special cPanel account in shared hosting could endanger other customers on the same server. Security expert Ali Mustafa, known as (nd abe)1526, found the weakness. This weakness impacts all cPanel/WHM versions that are still supported before the fixed builds:

cPanel/WHM Release Patched Version
cPanel & WHM 11.110 11.110.0.143
cPanel & WHM 11.134 11.134.0.55
cPanel & WHM 11.136 11.136.0.39
cPanel & WHM 11.138 11.138.0.4
WP2 release 11.138.1.9

Server admins need to check their cPanel/WHM version right away and upgrade to a fixed release. Groups using managed hosting should also ask their provider to make sure the update is done on all affected systems.

The most important fix is to update cPanel/WHM to the newest patched version. Admins should not just limit public access because attacks need a real logged-in account, not anonymous access.

Security teams should check cPanel accounts that have email permissions and take away unneeded access. Turn on passwords and multi-factor authentication for accounts that might be unsafe or are not needed anymore.

Administrators should look for strange files, unexpected changes to web folders, changed settings files, odd root processes, and unknown outgoing network connections. Checking cPanel, web-server, login, and system logs may help find signs of exploitation attempts.

Check Also

MikroTik

Hackers Exploiting MikroTik RouterOS Flaw Gaining Network Access

Attackers are misusing MikroTik routers through their Secure Shell (SSH) service, which can be accessed …