Security — Web Hosting News

Latest Security news, updates and analysis from the web hosting industry — 79 articles.

Other
Automattic Is Not an Owner of the WordPress Marks It Asserted in Court, a Judge Rules
Natalia Nowak · 29 Sep 2026 · 6 min read
#automattic#web-hosting#wordpress
The September 24 order brings back four antitrust claims the same judge had dismissed in an earlier ruling. It also holds that Automattic and Mullenweg are neither owners nor registrants of the WordPress marks, so they cannot assert them in their own right.
All Security articles
1–20 of 79
Security
The WordPress 7.1.2 Flaw Was Exploited in Hours. Theme and Host Decide the Damage.
by Natalia Nowak · 30 Sep 2026 · 9 min read
Attackers were writing PHP files through pearcmd.php by the evening of the day WordPress 7.1.2 shipped, and whether a site is reachable at all depends on its theme layout and on register_argc_argv, which is on by default under cPanel below PHP 8.5.
Security
cPanel Patches a Root Escalation That Starts From an Ordinary Hosting Account
by Natalia Nowak · 24 Sep 2026 · 5 min read
cPanel patched a privilege escalation running from an ordinary hosting account to root, plus a WP Toolkit flaw reaching other accounts' databases. Three builds shipped September 22, no severity score is published, and one researcher is credited on four root-level flaws across cPanel and Plesk.
Security
WordPress 7.1.1 Fixes a Comment-Form XSS. The Payload Passes the Sanitizer.
by Natalia Nowak · 22 Sep 2026 · 10 min read
WordPress 7.1.1 fixes CVE-2026-93485, a stored XSS delivered through the ordinary comment form by an anonymous visitor and missed by wp_kses. Two of the other ten fixes came from Anthropic, and three in ten sites run a version 6 branch reached only by a backport.
Security
A Critical libheif Bug Reachable Through WordPress Uploads Still Has No CVE
by Natalia Nowak · 21 Sep 2026 · 8 min read
A researcher uploaded a crafted photo to a clean WordPress site and left a working PHP file on the server. The flaw is in libheif, a system library that arrives with the operating system, and twenty days after the fix shipped it still has no CVE number for patch pipelines to match.
Security
Three LiteSpeed Security Builds in Six Days: Check Which One Your Servers Run
by Natalia Nowak · 18 Sep 2026 · 7 min read
A cPanel advisory of September 14 covers a LiteSpeed Enterprise flaw that lets a hosting account past CageFS to root. LiteSpeed has since shipped 6.3.7 three times in six days, each build with a security change, and a server patched on the day of the advisory is no longer on the latest one.
Security
Acronis cPanel Backup Plugin: Exploited Privilege-Escalation Flaw on CISA’s List
by Natalia Nowak · 17 Sep 2026 · 5 min read
Acronis has patched CVE-2026-87886 in its backup plugin for cPanel and WHM and says it has been used in limited, targeted attacks, based on one customer report. CISA added it to its Known Exploited Vulnerabilities catalog on September 16 with a three-day deadline for US federal civilian agencies.
Security
Ten IP Addresses Sent at Least 94,000 Attempts to Exploit a WooCommerce Plugin.
by Natalia Nowak · 15 Sep 2026 · 5 min read
A critical file-upload flaw in a paid WooCommerce extension was disclosed in February, and Wordfence has since blocked more than 100,000 attempts to exploit it. The largest published spike came on August 30, and ten source addresses account for at least 94,490 of the blocked requests.
Security
EU Software Makers Now Have 24 Hours to Report an Exploited Flaw.
by Natalia Nowak · 14 Sep 2026 · 5 min read
Article 14 of the Cyber Resilience Act took effect on September 11, giving manufacturers 24 hours to file an early warning on an actively exploited flaw. License is not the test, monetization is, and the equivalent duty for open-source stewards does not begin until December 2027.
Partners
Monarx Launches Dark Web Monitoring. One Domain Covers Every Address on It.
by Natalia Nowak · 10 Sep 2026 · 6 min read
Monarx Dark Web Monitoring begins with a domain rather than a list of mailboxes, sells white-label at a suggested $1.99 to $9.99 a month on a 50/50 revenue share, and today shows customers which categories of their data were breached rather than the data itself.
Security
A cPanel Account With Mail Privileges Could Reach Root. Every Supported Version Was Affected.
by Natalia Nowak · 9 Sep 2026 · 4 min read
cPanel has patched CVE-2026-67401. An authenticated account with mail-related privileges could create files through EmailTrack and reach code execution as root. All supported versions were affected, and the CVE record scores the flaw 9.9 out of 10, critical.
Security
A Magento Zero-Day Is Being Exploited Now. The First Known Victim Was Fully Patched.
by Natalia Nowak · 7 Sep 2026 · 7 min read
Attackers are running code on Magento and Adobe Commerce stores through an unpatched flaw Sansec calls StyleSmuggler. There is no patch and no CVE, the first known victim had a clean patch status, and the backdoor installs in the site user's home directory rather than the web root.
Security
WHMCS Has an Unauthenticated RCE. The Fix Exists Only for 9.0.8 and 8.13.7.
by Natalia Nowak · 4 Sep 2026 · 5 min read
Two WHMCS advisories on September 3: an unauthenticated remote code execution flaw affecting every build since 8.0, and a 2CheckOut gateway flaw exposing client data in versions from 4.5. Both are fixed in 9.0.8 and 8.13.7, and nothing older gets a patch.
Security
Nearly Two-Thirds of All-in-One WP Migration Installs Remain Unpatched Two Weeks Later
by Natalia Nowak · 4 Sep 2026 · 5 min read
Two weeks after the CVE-2026-19949 patch, WordPress.org statistics show 35 percent of installs on the fixed version, leaving about 3.2 million on a vulnerable version. Wordfence has published the chain from trackback to remote code execution, and Patchstack has raised its rating to medium priority.
Security
Attacks on the Elementor Pro Flaw Began the Day It Was Disclosed
by Natalia Nowak · 3 Sep 2026 · 6 min read
A critical Elementor Pro flaw was disclosed on August 19 and attacked the same day, with one firewall vendor blocking more than 190,000 attempts. The fix had already shipped, only sites with a published upload form were reachable, and the check for compromise takes one look at a single directory.
Security
A High-Severity Patch for Five Million WordPress Sites Was Labeled as a Text Fix
by Natalia Nowak · 2 Sep 2026 · 7 min read
Two unauthenticated flaws in plugins on millions of WordPress sites were patched the same day, days before the CVE records went public. The changelogs gave no severity signal, and for anyone running a fleet, that gap is the real story.
Security
An Attacker Hijacked Hetzner IP Space and Poisoned a Virtualizor Update
by Natalia Nowak · 1 Sep 2026 · 6 min read
A BGP hijack of Hetzner address space sent Softaculous traffic to an attacker for two nights. A valid Let's Encrypt certificate hid the diversion, update packages were not cryptographically verified, one malicious Virtualizor update got through, and the countermeasure took about 12 hours to arrive.
Security
cPanel Patches a Root-Level Flaw in Domain Parking: One Customer Account With Domain Permissions Was Enough
by Natalia Nowak · 28 Aug 2026 · 3 min read
cPanel patched CVE-2026-65643: an account holder able to add parked or addon domains could create arbitrary files and reach root, taking every site on the server. All supported versions were affected. No CVE record, no CVSS and no exploitation status published so far.
Security
InMotion Rolls Out Monarx ThreatShield Inside the PHP Engine Across Its Fleet
by Natalia Nowak · 26 Aug 2026 · 7 min read
InMotion is switching on Monarx ThreatShield fleet-wide, blocking attacks inside the PHP runtime rather than filtering requests in front of it. Its own July incident report, with two sites taken over in under half a minute each, documents the problem this product class targets.
Security
Plesk Patches Three Flaws That Start From an Ordinary Customer Account
by Natalia Nowak · 26 Aug 2026 · 5 min read
Plesk's August 25 advisories cover three flaws reachable from an ordinary customer account: arbitrary file reads, cross-tenant database access, and root through two extensions. The extension fixes ship separately, and administrators report the Migrator update is not arriving.
Security
Researchers Found Six Major CDNs Vulnerable to New HTTP/3 Attacks. Two Deployed Mitigations.
by Natalia Nowak · 21 Aug 2026 · 7 min read
New research turns a CDN against the site behind it by exploiting the gap between HTTP/3 at the front and HTTP/1.1 at the back. All six CDNs tested were vulnerable, only Baidu and Tencent have deployed mitigations, and every proposed fix sits at the CDN rather than at the site.
📬

Stay in the loop

Weekly digest of the best hosting news, reviews and industry moves.

Page 1 of 4