CRITICAL
ConfigServer
CVE published 2026-09-10
CVE-2026-65638
A vulnerability in the MESSENGER service of ConfigServer Security & Firewall (CSF) allows unauthenticated remote attackers to execute arbitrary commands as the CSF service account. The MESSENGER service is disabled by default. Affected versions are CSF 14.00 through 16.29, with 16.30 and later being patched. Exploitation requires the MESSENGER service to be enabled and a reCAPTCHA secret configured.