{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/configserver-security--firewall-14.00-16.29-2.15-16.29/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":9.9,"id":"CVE-2026-67401"},{"id":"CVE-2026-65638"},{"id":"CVE-2026-65639"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["cPanel \u0026 WebHost Manager (\u003c 11.110.0.143, \u003c 11.134.0.55, \u003c 11.136.0.39, \u003c 11.138.0.4, \u003c 11.138.1.9)","ConfigServer Security \u0026 Firewall (14.00-16.29, 2.15-16.29)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","web-application","cpanel","sql-injection"],"_cs_type":"advisory","_cs_vendors":["WebPros"],"content_html":"\u003cp\u003eWebPros has issued a security advisory (AV26-908) regarding multiple vulnerabilities impacting cPanel \u0026amp; WebHost Manager (WHM) and ConfigServer Security \u0026amp; Firewall (CSF). The most notable vulnerability, tracked as CVE-2026-67401, is a SQL injection flaw identified within the cPanel EmailTrack functionality. Additionally, two vulnerabilities, CVE-2026-65638 and CVE-2026-65639, have been identified in CSF, necessitating immediate patching. Organizations utilizing these products are at risk of unauthorized database access or potential security feature bypass if left unpatched. Defenders should prioritize updating cPanel \u0026amp; WHM to version 11.110.0.143, 11.134.0.55, 11.136.0.39, 11.138.0.4, or 11.138.1.9 (WP2) respectively, and updating CSF to the latest available version beyond 16.29.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-67401 could allow unauthenticated or authenticated attackers to perform SQL injection attacks against the cPanel EmailTrack module, potentially leading to unauthorized data exfiltration or manipulation of the backend database. CSF vulnerabilities CVE-2026-65638 and CVE-2026-65639 impact the security infrastructure of the hosting environment, potentially allowing for the circumvention of firewall rules. These flaws impact a broad range of web hosting environments globally.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePatch cPanel \u0026amp; WebHost Manager immediately to the specified versions (11.110.0.143, 11.134.0.55, 11.136.0.39, 11.138.0.4, or 11.138.1.9) as documented in the WebPros advisory.\u003c/li\u003e\n\u003cli\u003eUpdate ConfigServer Security \u0026amp; Firewall (CSF) to versions beyond 16.29 to remediate CVE-2026-65638 and CVE-2026-65639.\u003c/li\u003e\n\u003cli\u003eAudit logs for web requests targeting \u003ccode\u003e/scripts/emailtrack\u003c/code\u003e or similar endpoints associated with the vulnerable EmailTrack functionality.\u003c/li\u003e\n\u003cli\u003eMonitor for anomalous database queries or unusual error patterns in web server logs that may indicate SQL injection attempts.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-10T18:56:38Z","date_published":"2026-09-10T18:56:38Z","id":"https://feed.craftedsignal.io/briefs/2026-09-webpros-advisory/","summary":"WebPros has released patches for multiple critical vulnerabilities in cPanel \u0026 WebHost Manager and ConfigServer Security \u0026 Firewall, including an SQL injection flaw in the EmailTrack component.","title":"Security Advisories for cPanel WHM and ConfigServer Security \u0026 Firewall","url":"https://feed.craftedsignal.io/briefs/2026-09-webpros-advisory/"}],"language":"en","title":"CraftedSignal Threat Feed - ConfigServer Security \u0026 Firewall (14.00-16.29, 2.15-16.29)","version":"https://jsonfeed.org/version/1.1"}