Tag

#cPanel

7 stories taggedcPanel.

A digital illustration showing a web browser with Adobe Acrobat and WhatsApp icons, symbolizing interconnected data flow
Vulnerabilities

Critical cPanel Bug Lets a Single Hosting Customer Seize an Entire Server

A flaw in domain parking, tracked as CVE-2026-65643, could hand root control of a shared hosting server to any customer with an account on it.

3 min read
A glowing red countdown timer overlaid on a rack of web hosting servers in a dark data center, lighting, shallow depth of field, sense of urgency
Vulnerabilities

cPanel patches critical database flaw that let hosting customers run SQL as root

A newly disclosed bug, CVE-2026-58048, crossed the line between a single hosting account and the server's master database identity. cPanel has shipped a targeted fix.

3 min read
Dim editorial photograph of a developer workstation at night, screen showing a code editor with a redacted extension manifest, faint overlay of blockchain trans
Threat Intelligence

Hijacked GitHub Repos Turned Into Attack Machines Hunting cPanel Servers

Researchers found booby-trapped PHP packages using GitHub's own automation to scan the internet for web hosting control panels.

4 min read
Policy & Regulation

CISA Sets Three-Day Patch Deadline for Actively Exploited LiteSpeed cPanel Plugin Flaw

CVE-2026-54420 lands on the KEV catalog, triggering a BOD 22-01 remediation clock for federal civilian agencies.

2 min read
Vulnerabilities

CISA Adds LiteSpeed cPanel Plugin Bug to KEV After In-the-Wild Exploitation

CVE-2026-54420 (CVSS 8.5) lets attackers escalate to root on hosts running the LiteSpeed cPanel plugin. Federal agencies have until June 18, 2026 to patch.

3 min read
Vulnerabilities

CISA Gives Federal Agencies Four Days to Kill a cPanel Plugin Bug Already Being Exploited

The LiteSpeed plugin sits on millions of shared hosting accounts. CISA's compressed timeline says the quiet part loud: someone's already inside.

2 min read
Vulnerabilities

LiteSpeed cPanel Plugin Flaw Hands Root to Any Logged-In User, and the Vendor Won't Say How Many Hosts Are Hit

CVE-2026-48172 carries a CVSS of 10.0, is already being exploited, and LiteSpeed has not answered three questions about exploitation telemetry.

2 min read
© 2026 Threat Vectr