support.cpanel.net Multiple Vulnerabilities in cPanel & WHM Posed Security Risks
Article Content
- •cPanel & WHM released patches for three critical vulnerabilities on May 8, 2026.
- •CVE-2026-29201 allows arbitrary file reads, CVE-2026-29202 involves Perl code injection, and CVE-2026-29203 enables unsafe symlink handling.
- •Users are strongly advised to update their systems to the latest versions to mitigate risks.
On May 8, 2026, cPanel & WHM released patches for three critical vulnerabilities: CVE-2026-29201, CVE-2026-29202, and CVE-2026-29203. CVE-2026-29201 allows arbitrary file reads due to inadequate validation in the LOADFEATUREFILE call. CVE-2026-29202 involves a Perl code injection in the create_user API, while CVE-2026-29203 permits unsafe symlink handling, enabling users to change permissions on arbitrary files. These vulnerabilities affect all versions of cPanel & WHM, particularly impacting users on CentOS 6 or CloudLinux 6. The patches are available, and users are urged to update immediately to mitigate potential risks. The vulnerabilities could lead to denial of service, privilege escalation, and unauthorized access to sensitive files. All affected systems should verify their cPanel versions post-update to ensure security compliance.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track CloudLinux and CVE-2026-29201 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…
Critical Authentication Bypass in Rejetto HFS Exploited Within 24 Hours Anthropic's Mythos model identified a critical authentication bypass in Rejetto HTTP File Server (HFS), tracked as CVE-2026-61500, allowing remote code execution. Discovered by Horizon3 researcher Zach Hanley, the flaw was revealed on September 27, 2026, and exploitation began within 24 hours, with attacks traced to…