This notice is to inform you of a critical security vulnerability recently identified in all cPanel servers:
Vulnerability Overview
CVE-2026-29203
An unsafe symlink handling error was found that allows a user to chmod an arbitrary file, allowing for denial of service and possible privilege escalation.
Action Taken
Our security team acted ...
Continue reading
This notice is to inform you of a critical security vulnerability recently identified in all cPanel servers:
Vulnerability Overview
CVE-2026-29202
A Perl code injection method was found in the create_user API call, relating to the plugin parameter.
Action Taken
Our security team acted immediately upon the disclosure. We are pleased to ...
Continue reading
This notice is to inform you of a critical security vulnerability recently identified in all cPanel servers:
Vulnerability Overview
CVE-2026-29201
An arbitrary file read found was found in the feature::LOADFEATUREFILE adminbin call where it does not adequately validate the feature file name. A relative path may be passed as the argument to ...
Continue reading
This notice is to inform you of a critical security vulnerability recently identified in all linux servers: Dirty Frag
Vulnerability Overview
The reported flaw allowed remote attackers to bypass authentication protocols, potentially granting unauthorised administrative (root) access to host systems. If left unpatched, this could have ...
Continue reading