Announcements

Security Notice: cPanel Security CVE-2026-29203

  • 9th May 2026
This notice is to inform you of a critical security vulnerability recently identified in all cPanel servers:   Vulnerability Overview CVE-2026-29203 An unsafe symlink handling error was found that allows a user to chmod an arbitrary file, allowing for denial of service and possible privilege escalation. Action Taken Our security team acted ...
Continue reading

Security Notice: cPanel Security CVE-2026-29202

  • 9th May 2026
This notice is to inform you of a critical security vulnerability recently identified in all cPanel servers:   Vulnerability Overview CVE-2026-29202 A Perl code injection method was found in the create_user API call, relating to the plugin parameter. Action Taken Our security team acted immediately upon the disclosure. We are pleased to ...
Continue reading

Security Notice: cPanel Security CVE-2026-29201

  • 9th May 2026
This notice is to inform you of a critical security vulnerability recently identified in all cPanel servers:   Vulnerability Overview CVE-2026-29201 An arbitrary file read found was found in the feature::LOADFEATUREFILE adminbin call where it does not adequately validate the feature file name. A relative path may be passed as the argument to ...
Continue reading

Urgent Security Notice: Dirty Frag: Universal Linux LPE

  • 8th May 2026
This notice is to inform you of a critical security vulnerability recently identified in all linux servers:  Dirty Frag Vulnerability Overview The reported flaw allowed remote attackers to bypass authentication protocols, potentially granting unauthorised administrative (root) access to host systems. If left unpatched, this could have ...
Continue reading