Urgent.News

What's breaking now, across thousands of outlets.

World

cPanel presses CSF users to close critical flaw

cPanel has urged server administrators to update ConfigServer Security & Firewall after disclosure of a critical command-injection vulnerability that can let unauthenticated remote attackers run arbitrary commands on affected systems under specific service configurations. The flaw, tracked as CVE-2026-65638, affects cPanel’s WebPros-maintained CSF versions 14.00 through 16.29 and was addressed in…

cPanel has alerted server administrators to update ConfigServer Security & Firewall (CSF) due to a critical command-injection vulnerability. CVE-2026-65638 affects CSF versions 14.00 through 16.29 when the MESSENGER service is enabled and a reCAPTCHA secret is configured. Successful exploitation could allow unauthenticated remote attackers to execute arbitrary commands as the CSF service account, posing risks to confidentiality, integrity, and availability. cPanel recommends updating to version 16.30 or later, disabling the vulnerable MESSENGER service if an update cannot be applied immediately, or setting the MESSENGER option to zero in the CSF configuration file and restarting relevant services.

Written by urgent.news from Arabian Post's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at thearabianpost.com →

More in World

More from Sunday 13 September →