5 min
cPanel TSR-2026-09-29: patch three WHM security vulnerabilities
cPanel TSR-2026-09-29 fixes two stored XSS flaws in WHM and a Multilang Adminbin authorization bypass that may permit command execution. Check your full build number and update now.
2026-09-30
5 min
CVE-2026-68492: patch the Plesk REST API root RCE
CVE-2026-68492 lets a remote authenticated user execute arbitrary code as root when affected Plesk for Linux and RESTful API extension versions are installed together.
2026-09-23
7 min
CVE-2026-67401: the cPanel EmailTrack flaw that turns mail access into root
A SQL injection in cPanel's EmailTrack feature lets any account with mail privileges write files as root. Fixed builds, affected versions, and how to check your fleet.
2026-09-15
5 min
EasyApache 4 25.82: cPanel patches ea-libxml2, ea-nginx, ea-ruby27-ruby
EasyApache 4 build 25.82 patches eight libxml2 CVEs, two Ruby resolv CVEs, and bumps ea-nginx to 1.31.5. Here's what's affected and how to update.
2026-09-13
4 min
CVE-2026-84761: the LiteSpeed Cache for WordPress SSRF fix
An unauthenticated SSRF in LiteSpeed Cache for WordPress below v7.9.1 hits sites behind QUIC.cloud with client-IP restoration off. Patch and exposure check.
2026-09-11
5 min
bridge-stp-uaf (CVE-2026-72389): the CloudLinux kernel advisory
A use-after-free in the kernel bridge STP timer code lets a local user who can configure a network bridge become root. CloudLinux 7h and 8 need the modprobe mitigation now.
2026-09-11
4 min
Plesk CVE-2026-68487 and 68488: patch Backup Manager now
Two critical Plesk Backup Manager flaws let an authenticated customer or reseller write root-owned files and take over the server. Hotfixes ship in 18.0.79.11 and 18.0.80.7.
2026-09-10
4 min
cPanel TSR-2026-09-08: prepare for the critical WHM patch
cPanel pre-announced a Targeted Security Release for 8 September 2026 fixing a critical cPanel & WHM vulnerability. Here is how to identify affected servers and apply the fix.
2026-09-08
3 min
CVE-2026-67394: patch the Plesk root privilege-escalation flaw
CVE-2026-67394 can let a Plesk customer or reseller with shell access gain root control of a Linux server. Update to 18.0.79.9, 18.0.80.5, or later.
2026-08-27
3 min
CVE-2026-65643: patch the cPanel domain parking root vulnerability
CVE-2026-65643 lets an authenticated cPanel user with parked or addon-domain access create arbitrary server files and potentially execute code as root. Check the fixed builds and update now.
2026-08-27
3 min
Plesk CVE-2026-65646, 65642, and 65647: patch your server
Three critical Plesk flaws expose server files, customer databases, and root access. Check the affected builds and update Plesk plus both extensions.
2026-08-25
5 min
RtabRace (CVE-2026-68138): mitigating the kernel race on CloudLinux
A traffic-control race in the Linux kernel lets any shell user panic a shared server on demand. CloudLinux 8 and 7 Hybrid need the sysctl mitigation today — here's the command and the patch status.
2026-08-18
7 min
CVE-2026-33278: the cpanel-unbound DNSSEC RCE, and how to check for it
A critical Unbound DNSSEC validator bug shipped as cpanel-unbound puts remote code execution one malicious signed zone away, no login required. Patched builds and how to check exposure.
2026-08-17
5 min
EasyApache 4 25.69: cPanel patches six Tomcat CVEs in ea-tomcat101
EasyApache 4 25.69 ships Apache Tomcat 10.1.56 in ea-tomcat101, closing six CVEs — an auth-bypass on default servlet constraints among them. Here's what's fixed and how to update.
2026-07-31
7 min
CVE-2026-41940: the cPanel & WHM auth bypass, and how to check for it
A CRLF injection in cpsrvd session handling let unauthenticated attackers write user=root into their own session file. Patched versions, IOCs, and how to check if you were hit.
2026-07-23
8 min
KernelCare live patching on cPanel: zero-reboot kernel CVEs
How to install KernelCare on a cPanel server so kernel CVEs patch live without a reboot — verification commands, rollback steps, and the userspace caveat.
2026-05-16
3 min
NGINX Rift (CVE-2026-42945) — what hosting operators need to do
An 18-year-old heap overflow in NGINX's rewrite module — CVSS 9.2, unauthenticated, exploitable from the internet. Here's the patched versions, the config workaround, and how it affects Plesk and cPanel stacks.
2026-05-15