cPanel and WHM Release Patches for Three Critical Vulnerabilities
cPanel has issued urgent security updates for its cPanel and Web Host Manager (WHM) software to address three newly discovered vulnerabilities. These flaws pose significant risks, including privilege escalation, arbitrary code execution, and denial-of-service attacks. The most severe issues, CVE-2026-29202 and CVE-2026-29203, both carry a CVSS score of 8.8. The former involves insufficient input validation in the create_user API, allowing arbitrary Perl code execution, while the latter stems from unsafe symlink handling that could modify file permissions. A third vulnerability, CVE-2026-29201, allows arbitrary file reads due to poor input validation. Patches are available across multiple version branches, including 11.136.0.9 and higher. Although there is no current evidence of these specific vulnerabilities being exploited in the wild, the release follows closely after the weaponization of another critical flaw, CVE-2026-41940, by threat actors distributing Mirai botnet variants and ransomware. Administrators are strongly advised to update their systems immediately to ensure optimal protection against potential cyber threats.
Wire timeline
cPanel and WHM Release Patches for Three Critical Vulnerabilities
cPanel has issued urgent security updates for its cPanel and Web Host Manager (WHM) software to address three newly discovered vulnerabilities. These flaws pose significant risks, including privilege escalation, arbitrary code execution, and denial-of-service attacks. The most severe issues, CVE-2026-29202 and CVE-2026-29203, both carry a CVSS score of 8.8. The former involves insufficient input validation in the create_user API, allowing arbitrary Perl code execution, while the latter stems from unsafe symlink handling that could modify file permissions. A third vulnerability, CVE-2026-29201, allows arbitrary file reads due to poor input validation. Patches are available across multiple version branches, including 11.136.0.9 and higher. Although there is no current evidence of these specific vulnerabilities being exploited in the wild, the release follows closely after the weaponization of another critical flaw, CVE-2026-41940, by threat actors distributing Mirai botnet variants and ransomware. Administrators are strongly advised to update their systems immediately to ensure optimal protection against potential cyber threats.
The Hacker News