Security — Web Hosting News

Latest Security news, updates and analysis from the web hosting industry — 79 articles.

Other
Automattic Is Not an Owner of the WordPress Marks It Asserted in Court, a Judge Rules
Natalia Nowak · 29 Sep 2026 · 6 min read
#automattic#web-hosting#wordpress
The September 24 order brings back four antitrust claims the same judge had dismissed in an earlier ruling. It also holds that Automattic and Mullenweg are neither owners nor registrants of the WordPress marks, so they cannot assert them in their own right.
All Security articles
21–40 of 79
Security
Forminator’s 9.8 Flaw, and Eleven More Fixes in Nineteen Days
by Natalia Nowak · 20 Aug 2026 · 7 min read
Forminator's file upload flaw scores 9.8 and needs no authentication, but it takes a form with both an upload and a select field, and the default .htaccess meant to stop execution does nothing on NGINX. The changelog records twelve security releases in nineteen days.
Security
The Hypervisor Escape Comes to VMware: CVE-2026-47876 May Let a Guest VM Run Code on the ESX Host
by Natalia Nowak · 14 Aug 2026 · 8 min read
CVE-2026-47876, rated 9.3, may let a guest VM with a VMXNET3 adapter escape to the VMware ESX host. Two vCenter flaws rated 9.8 shipped in the same advisory, and one is already being exploited in the wild.
Security
WordPress 7.0.4 Fixes a PNG That Runs Code. The Flaw Was Almost 10 Years Old.
by Natalia Nowak · 13 Aug 2026 · 6 min read
WordPress 7.0.4 closes CVE-2026-65640, present since version 4.7: a file named .png that hides PostScript could reach ImageMagick and Ghostscript and run code on the server. It needs an author account, but XML-RPC skips the upload check, so multi-author and membership sites should update first.
Security
Metabase Cloud Customers Were Patched Before They Knew. Self-Hosted Users Had to Do It Themselves.
by Natalia Nowak · 12 Aug 2026 · 5 min read
Metabase's cloud service was breached through a zero-day, and the vendor patched every hosted instance before most customers heard. Self-hosted operators had to find out, patch by hand and hunt for evidence. Five customers came forward in four days, and about 2,500 instances remain visible online.
Security
Cloudflare Reached FedRAMP High Without Building a Separate Government Cloud
by Natalia Nowak · 11 Aug 2026 · 7 min read
Cloudflare reached FedRAMP High without a separate gov cloud: one network, U.S.-only processing, 22 agencies on board. One catch: it brands the milestone Class D, a certification FedRAMP's roadmap only pilots next fiscal year. The Pentagon's IL4 is the next target.
Security
Zapscape Breaks the Linux KVM Boundary. A Server Without a Single VM Can Still Be in Range.
by Natalia Nowak · 10 Aug 2026 · 12 min read
Zapscape lets an attacker who controls a guest climb out and seize the Linux host as root. Wherever /dev/kvm is open to ordinary users, a plain shared-hosting box is in range too, because a local user can spin up their own guest. Exploit code is public; patched kernels are rolling out.
Security
Roundcube Shipped Eleven Security Fixes Without a Single CVE Number
by Natalia Nowak · 10 Aug 2026 · 5 min read
Roundcube shipped eleven security fixes across its current and LTS branches, including an IMAP command injection and a conditional code execution flaw. The notes name no CVE identifiers, so version-matching scanners stay quiet, and cPanel has historically taken five to nine days to follow.
Security
An AI Model Found the WordPress Flaw in Ten Hours for $25. Attackers Weaponized the Patch in Ninety Minutes.
by Natalia Nowak · 7 Aug 2026 · 8 min read
WordPress shipped its second security release in three weeks. Around the first one, both ends of the vulnerability lifecycle collapsed: an AI model found the critical chain in 10 hours for about $25, and exploitation began 90 minutes after the patch shipped. Hosting companies own the gap in between.
Security
N-able’s First Patch Left the Door Open, and Attackers Walked Back Through It
by Natalia Nowak · 3 Aug 2026 · 4 min read
A second CVE in N-able N-central exists because the first patch was incomplete, and it is being exploited to take over MSP consoles and reach every machine they manage. The August 2 hotfix closes the way in, but no vendor statement says it removes the attackers' persistence.
Security
Two of cPanel’s Three New Flaws Cross the Line Between Accounts
by Natalia Nowak · 29 Jul 2026 · 4 min read
cPanel patched three vulnerabilities on July 29, across every supported branch. Two matter most on shared servers: an unauthenticated request-smuggling bug that can alter other users' responses, and a database flaw that lets an ordinary account reach admin rights and possibly the host itself.
Security
A Model Found the Artifactory Zero-Day; Only Self-Hosted Users Had to Patch
by Natalia Nowak · 29 Jul 2026 · 5 min read
During a controlled OpenAI evaluation, a model found a real zero-day in self-hosted Artifactory, escaped its sandbox, and broke into Hugging Face to steal its own benchmark answers. For anyone running a registry, the real exposure is the gap between managed and self-hosted patching.
Security
Freenom Is Back, and No Longer Free. The Free-Domain Registry Behind Years of Phishing.
by Natalia Nowak · 27 Jul 2026 · 7 min read
Freenom gave away millions of domains and became the internet's biggest source of phishing, until Meta sued and it promised to quit. Now, per Domain Incite, it is back, running .tk, .cf and .gq again from €8.22 a year. What changed is what fueled the abuse: the domains are no longer free.
Security
A Malware Campaign Is Using GitHub Actions to Hunt Unpatched cPanel Servers
by Natalia Nowak · 24 Jul 2026 · 6 min read
Three months after cPanel's emergency patch, attackers have turned GitHub Actions into a distributed fleet that scans the internet for servers still exposed to CVE-2026-41940 and harvests their cloud keys, tokens and database logins. How it works, and what to check.
Security
A Once-a-Decade WordPress Core Flaw, and the Gap Between Patched and Safe
by Natalia Nowak · 21 Jul 2026 · 5 min read
A critical flaw in WordPress core, the first of its kind in nearly a decade, triggered a rare forced update to millions of sites. Within 72 hours it was mass exploitation, because forced updates never reach everyone. Why patched and safe are not the same thing.
Security
A 16-Year-Old KVM Escape, and OVHcloud’s Week-Long Patch Across a Million VMs
by Natalia Nowak · 21 Jul 2026 · 6 min read
A 16-year-old flaw in KVM let a customer with admin access escape their virtual server and seize the host on both Intel and AMD. OVHcloud built a fix and rebooted around a million VMs in a week to deploy it, and the campaign shows the quiet choice every host makes between your consent and your safety.
Security
A Critical Nginx Flaw and Who Is Actually Exposed
by Natalia Nowak · 20 Jul 2026 · 3 min read
F5 patched CVE-2026-42533, a heap-overflow flaw in Nginx rated 9.2 that has sat in the code since 2011. It is unauthenticated and remote, but only triggers under a specific regex-map configuration, so not every server is exposed. With a proof-of-concept exploit due in early August, here is who actually needs to patch.
Security
An Unauthenticated Path to Code Execution in WordPress Core, Already Being Exploited
by Łukasz Nowak · 18 Jul 2026 · 8 min read
A flaw in the heart of WordPress lets a complete stranger seize a site without ever logging in, and the attacks began the day it was disclosed. Millions of sites run the vulnerable code, and the only real protection is an update most owners assume already happened.
Security
Roundcube’s Zero-Click Webmail XSS, and How Fast It Reached cPanel
by Natalia Nowak · 15 Jul 2026 · 4 min read
A zero-click stored XSS in Roundcube webmail, scored CVSS 7.2, lets a crafted plain-text email run script in a victim's session on preview. Roundcube fixed it on July 5, cPanel shipped it in 134.0.45 on July 14, and standalone installs still need patching separately.
Security
A US Sanction, a Montenegrin Domain, and Why Every t.me Link Went Dark
by Natalia Nowak · 14 Jul 2026 · 4 min read
Telegram's t.me domain went offline worldwide, placed on serverHold by the .me registry. The likely trigger is a US OFAC sanction on a cybercrime group whose t.me address was listed, enforced through a Montenegrin ccTLD run by US firms Identity Digital and GoDaddy. One URL, a whole domain down.
Security
Januscape and Bad Epoll: Two Linux Flaws That Let One Customer Take Over the Whole Server
by Łukasz Nowak · 11 Jul 2026 · 9 min read
Januscape (CVE-2026-53359) lets a guest VM escape to the host and take over co-tenants; Bad Epoll (CVE-2026-46242) lets any unprivileged user reach root with a near-perfect exploit. Both are patched upstream and in AlmaLinux, and for both the only fix is a new kernel and a reboot.
🚀

Reach hosting professionals

Sponsor webhosting.today and get in front of hosting buyers, founders and engineers.

50k+monthly readers
742articles
Become a sponsor →
Page 2 of 4