Cpanel Presses CSF Users To Close Critical Flaw Arabian Post
The flaw, tracked as CVE-2026-65638, affects cPanel's WebPros-maintained CSF versions 14.00 through 16.29 and was addressed in version 16.30 and later. cPanel said administrators should move to the latest available release as soon as possible, while those unable to update should disable the vulnerable MESSENGER service.
The vulnerability carries a CVSS 4.0 score of 9.2 out of 10, placing it in the critical category. The published CVE record classifies the weakness as CWE-78, or operating system command injection, caused by improper escaping of a request URL before it reaches a shell command.
Legal Disclaimer:
MENAFN provides the
information “as is” without warranty of any kind. We do not accept any
responsibility or liability for the accuracy, content, images, videos,
licenses, completeness, legality, or reliability of the information
contained in this article. If you have any complaints or copyright issues
related to this article, kindly contact the provider above.

Comments
No comment