These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
A security issue was found in WP Toolkit's handling of database-creation commands. Successful exploitation allows authenticated cPanel users to perform database modifications in other accounts. This issue requires immediate attention from cPanel administrators and users with database creation and modification permissions to assess exposure and update WP Toolkit to version 6.11.3 or later. The vulnerabilit [truncated]
CVE-2026-87899 is a privilege escalation vulnerability in cPanel's CalDAV and CardDAV functionality. An authenticated cPanel account holder can exploit this vulnerability to escalate their privileges, potentially leading to code execution as the root user. This gives an attacker full control of the server. The vulnerability affects cPanel/WHM versions v120 or later, and patched versions are available.
A permissions issue in cPanel's CalDAV/CardDAV functionality could allow a local user to access calendar and contact data belonging to other accounts on the same server. Successful exploitation allows reading of calendar events and contacts, but does not grant modification or root access. Update to the latest patched version to correct permissions and repair existing accounts.
CVE-2026-67401 debrief based on cPanel changelog RSS feed and CVE Program record. The vulnerability is a SQL injection issue in cPanel's EmailTrack functionality, allowing authenticated account holders with mail-related privileges to create arbitrary files, potentially leading to code execution as the root user. cPanel administrators and security teams should verify exposure, review mail-related privilege [truncated]
CVE-2026-65643 is a high-severity vulnerability in cPanel's Domain Parking functionality. An authenticated cPanel account holder can create arbitrary files on the server, potentially leading to code execution as the root user. This vulnerability allows an attacker to gain full control of the server and its accounts, websites, and databases. System administrators and security teams responsible for cPanel/W [truncated]
The CVE-2026-58047 vulnerability is an HTTP Request Smuggling issue in the cPanel web server. This vulnerability allows manipulation of cpsrvd responses under limited conditions, potentially enabling an unauthenticated remote attacker to manipulate responses delivered to other users on the same server. The vulnerability affects cPanel/WHM and has been patched in versions 11.110.0.137, 11.126.0.78, 11.134. [truncated]
cPanel’s EasyApache 4 25.52 maintenance release includes a security update for ea-nghttp2 and identifies CVE-2026-27135 as the fixed issue. The vendor advisory does not provide technical detail about the flaw in the supplied corpus, but it does make clear that this release is part of a broader EasyApache update cycle that also includes other package refreshes and compatibility fixes.
A security and maintenance update for EasyApache 4 (version 25.66) was released, addressing five CVEs, including four High-severity issues (CVE-2026-45447, CVE-2026-34180, CVE-2026-7383, CVE-2026-9076). The update patches ea-openssl11 to 1.1.1w-8 (for CentOS 7 only) with TuxCare/ELS backports and updates the Passenger ecosystem to v6.1.5. This release aims to enhance security and stability for users of cPanel/WHM.
A argument injection vulnerability in WP Toolkit before version 6.11.0, as bundled with cPanel & WHM, allows remote authenticated users to bypass cross-tenant authorization boundaries and execute arbitrary wp-toolkit CLI commands under the context of another account. The flaw exists in how WP Toolkit handles command-line arguments, permitting injection that subverts intended tenant isolation on multi-user [truncated]
cPanel released a security update for ea-nginx, moving the package to version 1.31.1 to address CVE-2026-9256. The vendor describes the issue as a security vulnerability tied to ea-nginx's ngx_http_rewrite_module and notes remote code execution risk through worker process memory pool handling ("nginx-poolslip"). Administrators running cPanel/WHM with ea-nginx installed should prioritize the update.
cPanel disclosed CVE-2026-32991 on 2026-05-13. According to the vendor advisory, a low-privilege team user with the default role could escalate to the owner account’s full capabilities through certain UAPI modules. The issue affects cPanel & WHM versions 110 and higher, and cPanel has released fixed builds across supported branches, plus a WP Squared fix. Because this is an authenticated privilege-escalat [truncated]
cPanel disclosed CVE-2026-29206 as a SQL injection issue in the sqloptimizer script affecting all cPanel & WHM versions. The vendor states patched releases are available for cPanel & WHM and WP Squared, and recommends extra upgrade-tier steps for customers still on CentOS 6 or CloudLinux 6.
CVE-2026-32993 is a vendor-reported vulnerability in cPanel’s cpsrvd service where an unauthenticated endpoint could allow arbitrary HTTP header insertion. cPanel says the issue affects cPanel & WHM versions 132 and higher and was patched in specific release lines published on 2026-05-13.
cPanel published a security update on 2026-05-13 for CVE-2026-32992. The vendor says SSL verification was not fully enforced in the DNS Cluster system, which could let a malicious server man-in-the-middle a request and capture credentials. cPanel released fixes in specific cPanel & WHM branches and in WP Squared, and states that later versions are also patched.
cPanel’s EasyApache 4 25.60 update addresses CVE-2026-42945, described by the vendor as a critical heap buffer overflow in ngx_http_rewrite_module affecting ea-nginx versions v1.30.0 through v1.31.0. The release also rebuilds ea-nginx-echo, ea-nginx-headers-more, ea-nginx-passenger, and ea-nginx-njs against the patched nginx build. For organizations using EasyApache 4 with ea-nginx, this is a high-priorit [truncated]
cPanel disclosed CVE-2026-29205 on 2026-05-13 and updated the advisory on 2026-05-14 with an additional fix. According to the vendor, incorrect privilege dropping combined with insufficient path filtering in certain cpdavd endpoints made it possible to read arbitrary files on affected cPanel & WHM systems. The issue affects cPanel & WHM version 120 and higher, and the vendor recommends moving to the patch [truncated]
CVE-2026-45185, also called Dead.Letter, is described as a use-after-free in Exim BDAT message body parsing when TLS is handled by GnuTLS. cPanel’s official advisory states its Exim build does not set USE_GNUTLS, depends on OpenSSL instead, and is not affected.
cPanel’s EasyApache 4 25.59 security release, published on 2026-05-12, explicitly includes a fix for CVE-2026-43515. In the supplied vendor material, cPanel does not describe the flaw’s root cause, affected component details, or exploitation impact for this CVE, so the safest interpretation is that it should be treated as a security-relevant update for EasyApache 4 users until exposure is ruled out in you [truncated]
CVE-2026-28387 is addressed in cPanel’s EasyApache 4 25.54 release, which delivers a security patch for ea-openssl11. The vendor advisory groups this issue with related OpenSSL package CVEs in the same update stream, so the practical response is to treat the EasyApache 4 package refresh as the fix path for affected cPanel/WHM systems.
cPanel’s EasyApache 4 25.58 security release, published on 2026-05-10, includes a fix for CVE-2026-6735 alongside several other CVEs. The vendor notice says updated packages were released for ea-php82, ea-php83, ea-php84, and ea-php85. The supplied advisory does not provide technical root-cause details for CVE-2026-6735, so the safest takeaway is operational: ensure the EasyApache 4 PHP packages are updat [truncated]
cPanel disclosed an unsafe symlink handling flaw in cPanel & WHM / WP Squared that could let a user chmod an arbitrary file. The vendor says this can cause denial of service and may enable privilege escalation, and it has released patched builds across supported branches.
On 2026-05-07, cPanel disclosed CVE-2026-29202, describing a Perl code injection issue in the create_user API call related to the plugin parameter. cPanel says fixed builds are available for affected cPanel & WHM branches, WP Squared 11.136.1.11 and later, and a direct 11.110.0.116 update for CentOS 6 or CloudLinux 6 systems. Administrators should prioritize upgrading any affected systems and verify that [truncated]
cPanel released a vendor security update for all supported cPanel & WHM versions that includes a fix for CVE-2026-29201, an arbitrary file read issue in the LOADFEATUREFILE adminbin call. The same update also addresses two additional vulnerabilities in cPanel & WHM, but this debrief focuses on the file-read issue tracked as CVE-2026-29201.
cPanel’s advisory groups CVE-2026-40684 through CVE-2026-40687 and says the underlying Exim issues affect versions prior to 4.99.2. cPanel has already released updated cpanel-exim 4.99.2 in patched cPanel/WHM builds, and administrators are advised to upgrade promptly. The source does not include exploit details, impact specifics, or a CVSS score for CVE-2026-40687.
cPanel’s advisory groups CVE-2026-40686 with three related Exim issues and says the fix is already available in updated cPanel/WHM builds. The vendor notes that Exim versions prior to 4.99.2 are affected and that upgrading cPanel/WHM to a patched release updates cpanel-exim to 4.99.2. The advisory does not provide separate technical details for CVE-2026-40686 by itself, so the most reliable defensive take [truncated]
cPanel’s advisory groups CVE-2026-40685 with three related Exim issues and states that versions of Exim prior to 4.99.2 are affected. For cPanel/WHM customers, the vendor says a patched Exim package is already available in specific builds, so the practical response is to move to the fixed cPanel/WHM release rather than waiting for a separate standalone remediation note.
cPanel’s advisory says Exim vulnerabilities affecting versions prior to 4.99.2 are fixed in updated cpanel-exim packages delivered through specific cPanel/WHM builds. Administrators running affected cPanel/WHM versions should upgrade to a patched release as soon as practical.
CVE-2026-24072 is a privilege-escalation issue in Apache HTTP Server that cPanel says affects version 2.4.66 and earlier. The vendor summary says local .htaccess authors may be able to read files with the privileges of the httpd user. Apache HTTP Server 2.4.67 is identified as the fixed release.
CVE-2026-23918 is a vendor-confirmed remote code execution issue called out in cPanel’s EasyApache 4 25.57 release notes. The advisory says ea-apache24 was updated to 2.4.67 to address 11 CVEs, including this one in mod_http2. For cPanel/WHM environments that use EasyApache 4, this is a high-priority security update because the affected component sits in the Apache package stack and the vendor characteriz [truncated]
cPanel’s EasyApache 4 25.53 release includes a security update for ea-ruby27-rubygem-rack that addresses CVE-2026-34830. The vendor notice does not provide additional vulnerability details in the supplied corpus, but it does confirm that affected EasyApache 4 package users should move to the updated release.