{
  "id": 7074117,
  "title": "cPanel presses CSF users to close critical flaw",
  "url": "https://urgent.news/2026/09/13/cpanel-presses-csf-users-to-close-critical-flaw",
  "topic": "world",
  "section": "World",
  "published": "2026-09-13T05:01:31.000Z",
  "source": {
    "name": "Arabian Post",
    "slug": "arabian-post",
    "url": "https://thearabianpost.com/cpanel-presses-csf-users-to-close-critical-flaw/"
  },
  "original_language": "en",
  "account": "cPanel has alerted server administrators to update ConfigServer Security & Firewall (CSF) due to a critical command-injection vulnerability. CVE-2026-65638 affects CSF versions 14.00 through 16.29 when the MESSENGER service is enabled and a reCAPTCHA secret is configured. Successful exploitation could allow unauthenticated remote attackers to execute arbitrary commands as the CSF service account, posing risks to confidentiality, integrity, and availability. cPanel recommends updating to version 16.30 or later, disabling the vulnerable MESSENGER service if an update cannot be applied immediately, or setting the MESSENGER option to zero in the CSF configuration file and restarting relevant services.",
  "summary": "cPanel has urged server administrators to update ConfigServer Security & Firewall after disclosure of a critical command-injection vulnerability that can let unauthenticated remote attackers run arbitrary commands on affected systems under specific service configurations. The flaw, tracked as CVE-2026-65638, affects cPanel’s WebPros-maintained CSF versions 14.00 through 16.29 and was addressed in…",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}