#cPanel
7 stories taggedcPanel.

Critical cPanel Bug Lets a Single Hosting Customer Seize an Entire Server
A flaw in domain parking, tracked as CVE-2026-65643, could hand root control of a shared hosting server to any customer with an account on it.

cPanel patches critical database flaw that let hosting customers run SQL as root
A newly disclosed bug, CVE-2026-58048, crossed the line between a single hosting account and the server's master database identity. cPanel has shipped a targeted fix.

Hijacked GitHub Repos Turned Into Attack Machines Hunting cPanel Servers
Researchers found booby-trapped PHP packages using GitHub's own automation to scan the internet for web hosting control panels.

CISA Sets Three-Day Patch Deadline for Actively Exploited LiteSpeed cPanel Plugin Flaw
CVE-2026-54420 lands on the KEV catalog, triggering a BOD 22-01 remediation clock for federal civilian agencies.

CISA Adds LiteSpeed cPanel Plugin Bug to KEV After In-the-Wild Exploitation
CVE-2026-54420 (CVSS 8.5) lets attackers escalate to root on hosts running the LiteSpeed cPanel plugin. Federal agencies have until June 18, 2026 to patch.

CISA Gives Federal Agencies Four Days to Kill a cPanel Plugin Bug Already Being Exploited
The LiteSpeed plugin sits on millions of shared hosting accounts. CISA's compressed timeline says the quiet part loud: someone's already inside.

LiteSpeed cPanel Plugin Flaw Hands Root to Any Logged-In User, and the Vendor Won't Say How Many Hosts Are Hit
CVE-2026-48172 carries a CVSS of 10.0, is already being exploited, and LiteSpeed has not answered three questions about exploitation telemetry.