Announcements

Security Notice: cPanel Security CVE-2026-29206

  • 14th May 2026
This notice is to inform you of a critical security vulnerability recently identified in all cPanel servers:   Vulnerability Overview CVE-2026-29206 It was found that, as part of the sqloptimizer script, it was possible that a created SQL query could be injected with arbitrary SQL queries. Action Taken Our security team acted immediately ...
Continue reading

Security Notice: cPanel Security CVE-2026-29205

  • 14th May 2026
This notice is to inform you of a critical security vulnerability recently identified in all cPanel servers:   Vulnerability Overview CVE-2026-29205 Through a combination of incorrect dropping of privileges and insufficient path filtering, it was possible to read arbitrary files via certain cpdavd endpoints. Action Taken Our security team ...
Continue reading

Security Notice: cPanel Security CVE-2026-29203

  • 9th May 2026
This notice is to inform you of a critical security vulnerability recently identified in all cPanel servers:   Vulnerability Overview CVE-2026-29203 An unsafe symlink handling error was found that allows a user to chmod an arbitrary file, allowing for denial of service and possible privilege escalation. Action Taken Our security team acted ...
Continue reading

Security Notice: cPanel Security CVE-2026-29202

  • 9th May 2026
This notice is to inform you of a critical security vulnerability recently identified in all cPanel servers:   Vulnerability Overview CVE-2026-29202 A Perl code injection method was found in the create_user API call, relating to the plugin parameter. Action Taken Our security team acted immediately upon the disclosure. We are pleased to ...
Continue reading