Tuesday, 02 January 2024 12:17 GMT

Cpanel Presses CSF Users To Close Critical Flaw Arabian Post


(MENAFN- The Arabian Post) clearfix">cPanel has urged server administrators to update ConfigServer Security & Firewall after disclosure of a critical command-injection vulnerability that can let unauthenticated remote attackers run arbitrary commands on affected systems under specific service configurations.

The flaw, tracked as CVE-2026-65638, affects cPanel's WebPros-maintained CSF versions 14.00 through 16.29 and was addressed in version 16.30 and later. cPanel said administrators should move to the latest available release as soon as possible, while those unable to update should disable the vulnerable MESSENGER service.

The vulnerability carries a CVSS 4.0 score of 9.2 out of 10, placing it in the critical category. The published CVE record classifies the weakness as CWE-78, or operating system command injection, caused by improper escaping of a request URL before it reaches a shell command.

MENAFN13092026000152002308ID1111658696



The Arabian Post

Legal Disclaimer:
MENAFN provides the information “as is” without warranty of any kind. We do not accept any responsibility or liability for the accuracy, content, images, videos, licenses, completeness, legality, or reliability of the information contained in this article. If you have any complaints or copyright issues related to this article, kindly contact the provider above.



More Story