On the 15th of May, 2026, several of our services were interrupted due to a connectivity issue, leaving multiple servers on our network unreachable for several hours.
Servers themselves remained fully operational throughout the incident - the issue was not with the servers or any data stored on them, but with the ability to reach them from the ...
Continue reading
This notice is to inform you of a critical security vulnerability recently identified in all cPanel servers:
Vulnerability Overview
CVE-2026-32993
An unauthenticated endpoint in cpsrvd was found that could allow the insertion of arbitrary HTTP headers.
Action Taken
Our security team acted immediately upon the disclosure. We are pleased to ...
Continue reading
This notice is to inform you of a critical security vulnerability recently identified in all cPanel servers:
Vulnerability Overview
CVE-2026-32991
It was found that a low-privilege team user (role=default) can escalate to the owner account's full capabilities through the use of certain UAPI modules.
Action Taken
Our security team acted ...
Continue reading
This notice is to inform you of a critical security vulnerability recently identified in all cPanel servers:
Vulnerability Overview
CVE-2026-32992
It was found that SSL verification was not fully enforced in the DNS Cluster system, which could allow for a malicious server to man-in-the-middle the request and capture credentials.
Action ...
Continue reading