As cited
Copy frozen at (site build).
vulnerabilities
WebPros security advisory (AV26-908)
WebPros issued security advisory AV26-908 on September 10, 2026, identifying vulnerabilities in cPanel & WebHost Manager (WHM) and ConfigServer Security & Firewall (CSF) software across multiple versions. The advisory references CVE-2026-67401 (SQL Injection in cPanel's EmailTrack functionality), CVE-2026-65638, and CVE-2026-65639, with affected version ranges specified for each product. Users and administrators are encouraged to apply updates as they become available.
Why it matters: Hosting administrators and cPanel users must patch these vulnerabilities immediately to prevent SQL injection attacks and other exploits affecting their web hosting control panels and firewall security.
- Source published
- First seen by Cybersecurity Tracker