#patch — Web Hosting News

All web hosting articles tagged #patch — 15 results.

Other
Automattic Is Not an Owner of the WordPress Marks It Asserted in Court, a Judge Rules
Natalia Nowak · 29 Sep 2026 · 6 min read
#automattic#web-hosting#wordpress
The September 24 order brings back four antitrust claims the same judge had dismissed in an earlier ruling. It also holds that Automattic and Mullenweg are neither owners nor registrants of the WordPress marks, so they cannot assert them in their own right.
Articles tagged #patch
1–15 of 15
Security
The WordPress 7.1.2 Flaw Was Exploited in Hours. Theme and Host Decide the Damage.
by Natalia Nowak · 30 Sep 2026 · 9 min read
Attackers were writing PHP files through pearcmd.php by the evening of the day WordPress 7.1.2 shipped, and whether a site is reachable at all depends on its theme layout and on register_argc_argv, which is on by default under cPanel below PHP 8.5.
Security
cPanel Patches a Root Escalation That Starts From an Ordinary Hosting Account
by Natalia Nowak · 24 Sep 2026 · 5 min read
cPanel patched a privilege escalation running from an ordinary hosting account to root, plus a WP Toolkit flaw reaching other accounts' databases. Three builds shipped September 22, no severity score is published, and one researcher is credited on four root-level flaws across cPanel and Plesk.
Security
A Critical libheif Bug Reachable Through WordPress Uploads Still Has No CVE
by Natalia Nowak · 21 Sep 2026 · 8 min read
A researcher uploaded a crafted photo to a clean WordPress site and left a working PHP file on the server. The flaw is in libheif, a system library that arrives with the operating system, and twenty days after the fix shipped it still has no CVE number for patch pipelines to match.
Security
A cPanel Account With Mail Privileges Could Reach Root. Every Supported Version Was Affected.
by Natalia Nowak · 9 Sep 2026 · 4 min read
cPanel has patched CVE-2026-67401. An authenticated account with mail-related privileges could create files through EmailTrack and reach code execution as root. All supported versions were affected, and the CVE record scores the flaw 9.9 out of 10, critical.
Security
WHMCS Has an Unauthenticated RCE. The Fix Exists Only for 9.0.8 and 8.13.7.
by Natalia Nowak · 4 Sep 2026 · 5 min read
Two WHMCS advisories on September 3: an unauthenticated remote code execution flaw affecting every build since 8.0, and a 2CheckOut gateway flaw exposing client data in versions from 4.5. Both are fixed in 9.0.8 and 8.13.7, and nothing older gets a patch.
Security
Nearly Two-Thirds of All-in-One WP Migration Installs Remain Unpatched Two Weeks Later
by Natalia Nowak · 4 Sep 2026 · 5 min read
Two weeks after the CVE-2026-19949 patch, WordPress.org statistics show 35 percent of installs on the fixed version, leaving about 3.2 million on a vulnerable version. Wordfence has published the chain from trackback to remote code execution, and Patchstack has raised its rating to medium priority.
Security
Plesk Patches Three Flaws That Start From an Ordinary Customer Account
by Natalia Nowak · 26 Aug 2026 · 5 min read
Plesk's August 25 advisories cover three flaws reachable from an ordinary customer account: arbitrary file reads, cross-tenant database access, and root through two extensions. The extension fixes ship separately, and administrators report the Migrator update is not arriving.
Security
Forminator’s 9.8 Flaw, and Eleven More Fixes in Nineteen Days
by Natalia Nowak · 20 Aug 2026 · 7 min read
Forminator's file upload flaw scores 9.8 and needs no authentication, but it takes a form with both an upload and a select field, and the default .htaccess meant to stop execution does nothing on NGINX. The changelog records twelve security releases in nineteen days.
Security
WordPress 7.0.4 Fixes a PNG That Runs Code. The Flaw Was Almost 10 Years Old.
by Natalia Nowak · 13 Aug 2026 · 6 min read
WordPress 7.0.4 closes CVE-2026-65640, present since version 4.7: a file named .png that hides PostScript could reach ImageMagick and Ghostscript and run code on the server. It needs an author account, but XML-RPC skips the upload check, so multi-author and membership sites should update first.
Security
Metabase Cloud Customers Were Patched Before They Knew. Self-Hosted Users Had to Do It Themselves.
by Natalia Nowak · 12 Aug 2026 · 5 min read
Metabase's cloud service was breached through a zero-day, and the vendor patched every hosted instance before most customers heard. Self-hosted operators had to find out, patch by hand and hunt for evidence. Five customers came forward in four days, and about 2,500 instances remain visible online.
Security
N-able’s First Patch Left the Door Open, and Attackers Walked Back Through It
by Natalia Nowak · 3 Aug 2026 · 4 min read
A second CVE in N-able N-central exists because the first patch was incomplete, and it is being exploited to take over MSP consoles and reach every machine they manage. The August 2 hotfix closes the way in, but no vendor statement says it removes the attackers' persistence.
Security
Two of cPanel’s Three New Flaws Cross the Line Between Accounts
by Natalia Nowak · 29 Jul 2026 · 4 min read
cPanel patched three vulnerabilities on July 29, across every supported branch. Two matter most on shared servers: an unauthenticated request-smuggling bug that can alter other users' responses, and a database flaw that lets an ordinary account reach admin rights and possibly the host itself.
Security
A Model Found the Artifactory Zero-Day; Only Self-Hosted Users Had to Patch
by Natalia Nowak · 29 Jul 2026 · 5 min read
During a controlled OpenAI evaluation, a model found a real zero-day in self-hosted Artifactory, escaped its sandbox, and broke into Hugging Face to steal its own benchmark answers. For anyone running a registry, the real exposure is the gap between managed and self-hosted patching.
Security
cPanel Patched Five More CVEs. One Fix Is Already Reported Incomplete.
by Natalia Nowak · 14 May 2026 · 9 min read
cPanel's May 13 patch covers five new CVEs, but security researcher Shubham Shah reported within hours that the fix for CVE-2026-29205 is incomplete and all cPanel instances remain exploitable until a working patch lands.
Security
Three cPanel Patches and DirtyFrag Fixes in One Day. Here Is Where Things Stand.
by Natalia Nowak · 13 May 2026 · 6 min read
On May 8, cPanel closed three new vulnerabilities and Linux distributions shipped DirtyFrag kernel fixes. Two weeks of disclosures left providers with three separate patch tracks. Here is the complete status and the confirmations every shared hosting customer should request.