cPanel Patches Critical SQL Injection Flaw Allowing Database Root Access
cPanel has released a targeted security update to address a critical vulnerability that could allow authenticated hosting customers to execute SQL commands…
cPanel has released a targeted security update to address a critical vulnerability that could allow authenticated hosting customers to execute SQL commands…
CVE-2026-58047 is an HTTP request-smuggling vulnerability in cPanel's cpsrvd daemon. Under limited conditions, an unauthenticated remote attacker could manipulate responses delivered to…
cPanel & WHM is a widely used web hosting control panel. All supported versions are affected by CVE-2026-58048, a critical SQL injection…
WP Squared, a cPanel product for WordPress hosting, is also affected by CVE-2026-58048. The fix is included in build 138.1.6.
cPanel is a web hosting control panel that is being targeted in a campaign using compromised GitHub repositories and GitHub Actions runners.…
Cybersecurity researchers have uncovered a large-scale campaign that weaponizes compromised GitHub repositories to target cPanel and WebHost Manager (WHM) instances. The activity…
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a security flaw impacting LiteSpeed cPanel Plugin to its Known Exploited Vulnerabilities…
cPanel is a web hosting control panel provider. It recently released a security update addressing multiple vulnerabilities, including a critical SQL injection…
CVE-2026-41940 is an authentication bypass vulnerability in cPanel and WebHost Manager (WHM) that allows remote attackers to gain elevated control of the…