Category: Security
78 articles
Security
cPanel Patches a Root Escalation That Starts From an Ordinary Hosting Account
An authenticated cPanel account holder could run code as root through CalDAV and CardDAV. Three builds carry the fix, dated September 22.
Security
WordPress 7.1.1 Fixes a Comment-Form XSS. The Payload Passes the Sanitizer.
WordPress 7.1.1 was planned as bug-fix only and shipped with 11 security fixes, one an anonymous comment XSS the sanitizer does not catch.
Security
A Critical libheif Bug Reachable Through WordPress Uploads Still Has No CVE
A CVSS 9.8 flaw sits under WordPress photo uploads, in a system library the host has to patch. Twenty days after the fix, it has no CVE number.
Security
Three LiteSpeed Security Builds in Six Days: Check Which One Your Servers Run
LiteSpeed Enterprise 6.3.7 shipped three security builds in six days, after a cPanel advisory on a root path from a hosting account. Build 2 is the one to run.
Security
Acronis cPanel Backup Plugin: Exploited Privilege-Escalation Flaw on CISA’s List
Acronis patched a privilege-escalation flaw in its cPanel backup plugin and reports limited attacks. CISA listed it with a September 19 deadline.
Security
Ten IP Addresses Sent at Least 94,000 Attempts to Exploit a WooCommerce Plugin.
Six months after disclosure, a WooCommerce extension is still drawing blocked exploit attempts. The largest spike came on August 30.
Security
EU Software Makers Now Have 24 Hours to Report an Exploited Flaw.
The EU now requires software makers to report actively exploited flaws within 24 hours, and a GPL plugin with a paid tier counts as a product.
Partners
Monarx Launches Dark Web Monitoring. One Domain Covers Every Address on It.
Monarx has launched a white-label dark web monitoring service for hosts. It starts from a domain and shows the categories of breached data, not the values.
Security
A cPanel Account With Mail Privileges Could Reach Root. Every Supported Version Was Affected.
cPanel has patched CVE-2026-67401, a flaw rated 9.9 out of 10 that let an authenticated account with mail privileges run code as root.
Security
A Magento Zero-Day Is Being Exploited Now. The First Known Victim Was Fully Patched.
An unpatched Magento flaw has been exploited since September 4. The first known victim had a clean patch status, and the backdoor installs outside the web root.
Reach hosting professionals
Sponsor webhosting.today and get in front of hosting buyers, founders and engineers.
50k+monthly readers
731articles