Home > Control panel > Operations notices > CPanel vulnerability (CVE-2026-67401)

Related Links

Notice Links:

Notice

CPanel vulnerability (CVE-2026-67401)

PostedWed, 9 Sep 2026 01:30 AM UTC
Tue, 8 Sep 2026 21:30 PM EDT
Last UpdateWed, 9 Sep 2026 01:30 AM UTC (19 hours ago)
Tue, 8 Sep 2026 21:30 PM EDT
StatusClosed

Cpanel has asked all users to update servers running their hosting panel, due to a security issue CVE-2026-67401

ref: https://support.cpanel.net/hc/en-us/articles/43187903921559-Security-CVE-2026-67401-SQL-Injection-Vulnerability-in-cPanel-s-EmailTrack-Functionality-September-8-2026

This issue is fixed in the following releases:
110: v11.110.0.143
134: v11.134.0.55
136: v11.136.0.39
138: v11.138.0.4
wp138: v11.138.1.9

The vulnerability could allow a mail-enabled cPanel account to write a root-owned file at an arbitrary path on the server, compromising server integrity. We are not aware of any exploitation of these vulnerabilities, but we recommend treating this issue as urgent and updating without delay.

In most cases CPanel will have automatically updated itself. Anyone who requires addtional help to complete this update, please open a support ticket with us https://rimuhosting.com/ticket/enterticketdetails.jsp

#

Keep You Updated?

Log in to subscribe to changes to this notice.

Set your operation notice contact details for future notifications.