vulnerability Critical cPanel Flaw Could Let One Hosting Customer Take Root Control of a Whole Server A critical security vulnerability in cPanel and WebHost Manager (WHM) allows an authenticated user adding parked or addon domains to execute code as the root user, potentially leading to full server control. While the vulnerability has not yet been confirmed exploited, it's present in end-of-life versions and requires… The Hacker News · 2d ago Critical CVE-2026-65643CVE-2026-58048CVE-2026-58047cpanelvulnerabilityroot
threat-intel In Other News: Zombie Card Attack, T-Mobile Cut Cable to Stop Hackers, GitHub Denies AI Caused Bug This week’s cybersecurity news highlights a range of active threats and vulnerabilities. A severe code injection flaw in Ray-Project Ray is being actively exploited by a Mirai-based botnet, while T-Mobile took drastic ac… SecurityWeek · Aug 21, 2026 High CVE-2025-62593JACAvulnerabilityddosransomware
vulnerability New cPanel Critical Flaw Could Let Hosting Customers Run SQL as Database Root A critical vulnerability (CVE-2026-58048) in cPanel allows authenticated hosting customers to execute arbitrary database commands with administrative privileges, potentially leading to system-wide compromise. This flaw s… The Hacker News · Aug 4, 2026 Critical CVE-2026-58048CVE-2026-58047cvesql injectionprivilege escalation
threat-intel Attackers Weaponize GitHub Actions Runners to Target cPanel and WHM Servers A sophisticated campaign leveraging compromised GitHub repositories is targeting cPanel and WHM servers. Attackers are using malicious GitHub Actions workflows to launch GitHub-hosted runners that scan for vulnerable ser… The Hacker News · Jul 23, 2026 High CVE-2026-41940githubmalwarecpanel
vulnerability CISA warns of another cPanel plugin flaw exploited in attacks The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning about a critical vulnerability (CVE-2026-48172) in the LiteSpeed cPanel user-end plugin, which is currently being actively exploited.… BleepingComputer · Jun 16, 2026 Critical CVE-2026-54420CVE-2026-48172cpanelvulnerabilityprivilege escalation