cPanel has patched CVE-2026-67401, an authenticated SQL-injection flaw in its EmailTrack functionality that lets a hosting user with mail-related privileges create arbitrary files and potentially execute code as root. All supported cPanel & WHM versions are affected, creating particular risk for shared-hosting and multi-tenant deployments where compromise of one eligible account could expose other customers and hosted assets.
Fixed builds are available for release lines 11.110, 11.134, 11.136, 11.138, and WP Squared. Administrators should upgrade immediately, review and minimize mail-related privileges, enforce strong authentication and MFA, and investigate eligible accounts and servers for compromise. cPanel has not disclosed the precise required privileges, exploitation chain, compensating controls, or detection guidance; no public exploit, confirmed active exploitation, CVE Program entry, or CISA KEV listing had been identified as of September 9.

See real exploitation activity before you spend the cycle.
5 events from the most recent confirmed update back to the earliest known activity.
The Canadian Centre for Cyber Security issued advisory AV26-908 identifying CVE-2026-65638 affecting ConfigServer Security & Firewall versions 14.00 through 16.29 and CVE-2026-65639 affecting versions 2.15 through 16.29. It urged users and administrators to review vendor information and apply available updates.
cPanel disclosed CVE-2026-67401, an authenticated SQL-injection vulnerability in EmailTrack affecting all supported cPanel and WHM versions. A hosting account with mail-related privileges could create arbitrary files and potentially execute code as root; cPanel released fixes for release lines 11.110, 11.134, 11.136, 11.138, and WP Squared.
cPanel disclosed a vulnerability in parked-domain functionality that could result in root-level code execution.
cPanel disclosed a database-related vulnerability that could allow a hosting user with database-function access to execute commands with full administrative privileges.
cPanel previously addressed an authentication-bypass vulnerability that required no user account and was confirmed to have been used in ransomware campaigns; the flaw was listed in CISA's Known Exploited Vulnerabilities catalog.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
9 references tracked. Mallory keeps watching after this page renders.
csirt.bj
Open sourcemalware.news
Open sourcecyber.gc.ca
Open sourcecvefeed.io
Open sourcethecybersecguru.com
Open sourcemkd-cirt.mk
Open sourcecryptika.com
Open sourcecybersecuritynews.com
Open sourcethehackernews.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.