<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>CPanel &amp; WebHost Manager (&lt; 11.110.0.143, &lt; 11.134.0.55, &lt; 11.136.0.39, &lt; 11.138.0.4, &lt; 11.138.1.9) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/cpanel--webhost-manager--11.110.0.143--11.134.0.55--11.136.0.39--11.138.0.4--11.138.1.9/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Thu, 10 Sep 2026 18:56:38 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/cpanel--webhost-manager--11.110.0.143--11.134.0.55--11.136.0.39--11.138.0.4--11.138.1.9/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Security Advisories for cPanel WHM and ConfigServer Security &amp; Firewall</title><link>https://feed.craftedsignal.io/briefs/2026-09-webpros-advisory/</link><pubDate>Thu, 10 Sep 2026 18:56:38 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-webpros-advisory/</guid><description>WebPros has released patches for multiple critical vulnerabilities in cPanel &amp; WebHost Manager and ConfigServer Security &amp; Firewall, including an SQL injection flaw in the EmailTrack component.</description><content:encoded><![CDATA[<p>WebPros has issued a security advisory (AV26-908) regarding multiple vulnerabilities impacting cPanel &amp; WebHost Manager (WHM) and ConfigServer Security &amp; Firewall (CSF). The most notable vulnerability, tracked as CVE-2026-67401, is a SQL injection flaw identified within the cPanel EmailTrack functionality. Additionally, two vulnerabilities, CVE-2026-65638 and CVE-2026-65639, have been identified in CSF, necessitating immediate patching. Organizations utilizing these products are at risk of unauthorized database access or potential security feature bypass if left unpatched. Defenders should prioritize updating cPanel &amp; WHM to version 11.110.0.143, 11.134.0.55, 11.136.0.39, 11.138.0.4, or 11.138.1.9 (WP2) respectively, and updating CSF to the latest available version beyond 16.29.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of CVE-2026-67401 could allow unauthenticated or authenticated attackers to perform SQL injection attacks against the cPanel EmailTrack module, potentially leading to unauthorized data exfiltration or manipulation of the backend database. CSF vulnerabilities CVE-2026-65638 and CVE-2026-65639 impact the security infrastructure of the hosting environment, potentially allowing for the circumvention of firewall rules. These flaws impact a broad range of web hosting environments globally.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Patch cPanel &amp; WebHost Manager immediately to the specified versions (11.110.0.143, 11.134.0.55, 11.136.0.39, 11.138.0.4, or 11.138.1.9) as documented in the WebPros advisory.</li>
<li>Update ConfigServer Security &amp; Firewall (CSF) to versions beyond 16.29 to remediate CVE-2026-65638 and CVE-2026-65639.</li>
<li>Audit logs for web requests targeting <code>/scripts/emailtrack</code> or similar endpoints associated with the vulnerable EmailTrack functionality.</li>
<li>Monitor for anomalous database queries or unusual error patterns in web server logs that may indicate SQL injection attempts.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>vulnerability</category><category>web-application</category><category>cpanel</category><category>sql-injection</category></item></channel></rss>