Cyber Resilience
← All news

[UPDATE] [hoch] cPanel cPanel/WHM: Mehrere Schwachstellen

Our takeCERT-Bund reports multiple high-severity flaws in cPanel/WHM, including arbitrary code execution. Update if you run it.
Sources (20)
What this means for you — Security leader:If you run cPanel/WHM, review CERT-Bund WID-SEC-2026-1880 and apply the vendor fixes; RCE, control bypass, DoS, and data exposure are in scope. Confirm patch status on any internet-facing hosting panels in your estate.
What this means for you — Lean IT orgs:If you administer your own cPanel/WHM server, apply the updates now. If a hosting provider runs cPanel for you, ask them to confirm they have patched.
What this means for you — MSP:Inventory client cPanel/WHM instances and roll the vendor updates, prioritizing internet-facing hosts. RCE and security-control bypass are listed—track completion per tenant.
What this means for you — Researcher:CERT-Bund flags multiple high-severity flaws in cPanel/WHM (WID-SEC-2026-1880), including potential RCE, control bypass, DoS, and data exposure. Use the advisory for version and fix mapping.