Home > Control panel > Operations notices > CPanel vulnerability (CVE-2026-67402)

Related Links

Notice Links:

Notice

CPanel vulnerability (CVE-2026-67402)

PostedThu, 3 Sep 2026 22:56 PM UTC
Thu, 3 Sep 2026 18:56 PM EDT
Last UpdateThu, 3 Sep 2026 22:56 PM UTC (12 hours ago)
Thu, 3 Sep 2026 18:56 PM EDT
StatusClosed

Cpanel has asked all users to update servers running their hosting panel, due to a security issue CVE-2026-67402

ref: https://support.cpanel.net/hc/en-us/articles/43171958716439-Security-CSF-Security-Release-September-3rd-2026

This issue is fixed in the following: ConfigServer Firewall (CSF) 16.31 or later. A vulnerability was found in the MESSENGER service in the ConfigServer Firewall (CSF) software which could allow for unauthorized code execution under the apache user. By default, the MESSENGER service is disabled.

In most cases CPanel will have automatically updated itself. Anyone who requires addtional help to complete this update, please open a support ticket with us https://rimuhosting.com/ticket/enterticketdetails.jsp

#

Keep You Updated?

Log in to subscribe to changes to this notice.

Set your operation notice contact details for future notifications.