Home > Control panel > Operations notices

Related Links

Notice Links:

Notices

CPanel vulnerability (CVE-2026-67402)

PostedThu, 3 Sep 2026 22:56 PM UTC
Thu, 3 Sep 2026 18:56 PM EDT
Last UpdateThu, 3 Sep 2026 22:56 PM UTC (83 hours ago)
Thu, 3 Sep 2026 18:56 PM EDT
StatusClosed

Cpanel has asked all users to update servers running their hosting panel, due to a security issue CVE-2026-67402

ref: https://support.cpanel.net/hc/en-us/articles/43171958716439-Security-CSF-Security-Release-September-3rd-2026

This issue is fixed in the following: ConfigServer Firewall (CSF) 16.31 or later. A vulnerability was found in the MESSENGER service in the ConfigServer Firewall (CSF) software which could allow for unauthorized code execution under the apache user. By default, the MESSENGER service is disabled.

In most cases CPanel will have automatically updated itself. Anyone who requires addtional help to complete this update, please open a support ticket with us https://rimuhosting.com/ticket/enterticketdetails.jsp

#

Plesk panel critical vulnerability (CVE-2026-67397)

PostedThu, 3 Sep 2026 22:44 PM UTC
Thu, 3 Sep 2026 18:44 PM EDT
Last UpdateThu, 3 Sep 2026 22:45 PM UTC (83 hours ago)
Thu, 3 Sep 2026 18:45 PM EDT
StatusClosed

Users of Plesk are recommended to update to the latest version as soon as possible. This is due to CVE-2026-67397

Affected Versions:
Plesk for Linux 18.0.79.9 or earlier
Plesk for Linux 18.0.80 - 18.0.80.5
Patched Versions:
Plesk for Linux - 18.0.79.10
Plesk for Linux - 18.0.80.6

The CVE may allow an attacker with access to a normal, logged-in user account to escalate to the root user. Details on https://support.plesk.com/hc/en-us/articles/43070000520855-Vulnerability-CVE-2026-67397-Arbitrary-code-execution-as-root-in-Plesk

If anyone needs extra help with updates, please open a support ticket at https://rimuhosting.com/ticket/enterticketdetails.jsp

#