Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. Ugggh this one is going to suck.

Ugggh this one is going to suck.

Scheduled Pinned Locked Moved Uncategorized
5 Posts 5 Posters 0 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • mttaggart@infosec.exchangeM This user is from outside of this forum
    mttaggart@infosec.exchangeM This user is from outside of this forum
    mttaggart@infosec.exchange
    wrote last edited by
    #1

    Ugggh this one is going to suck. cPanel is everywhere and most are not patched frequently.

    https://www.bleepingcomputer.com/news/security/cpanel-whm-emergency-update-fixes-critical-auth-bypass-bug

    dec23k@mastodon.ieD nosirrahsec@infosec.exchangeN bersl2@furry.engineerB alesandroortiz@infosec.exchangeA 4 Replies Last reply
    0
    • mttaggart@infosec.exchangeM mttaggart@infosec.exchange

      Ugggh this one is going to suck. cPanel is everywhere and most are not patched frequently.

      https://www.bleepingcomputer.com/news/security/cpanel-whm-emergency-update-fixes-critical-auth-bypass-bug

      dec23k@mastodon.ieD This user is from outside of this forum
      dec23k@mastodon.ieD This user is from outside of this forum
      dec23k@mastodon.ie
      wrote last edited by
      #2

      @mttaggart
      Before the patches were released, the recommended emergency fix was to firewall off all the login ports: WHM, cPanel, and a few others (including Webmail).
      Those login services are independent of the main httpd that serves up the hosted websites, and they must share a similar code base, with the same vulnerabilities.

      1 Reply Last reply
      1
      0
      • mttaggart@infosec.exchangeM mttaggart@infosec.exchange shared this topic
      • mttaggart@infosec.exchangeM mttaggart@infosec.exchange

        Ugggh this one is going to suck. cPanel is everywhere and most are not patched frequently.

        https://www.bleepingcomputer.com/news/security/cpanel-whm-emergency-update-fixes-critical-auth-bypass-bug

        nosirrahsec@infosec.exchangeN This user is from outside of this forum
        nosirrahsec@infosec.exchangeN This user is from outside of this forum
        nosirrahsec@infosec.exchange
        wrote last edited by
        #3

        @mttaggart

        Link Preview Image
        1 Reply Last reply
        0
        • mttaggart@infosec.exchangeM mttaggart@infosec.exchange

          Ugggh this one is going to suck. cPanel is everywhere and most are not patched frequently.

          https://www.bleepingcomputer.com/news/security/cpanel-whm-emergency-update-fixes-critical-auth-bypass-bug

          bersl2@furry.engineerB This user is from outside of this forum
          bersl2@furry.engineerB This user is from outside of this forum
          bersl2@furry.engineer
          wrote last edited by
          #4

          @mttaggart cPanel has shipped with automatic updates enabled for a very long time. Typically, when systems don't update, either the administrator turned them off, or some piece of critical software supplied by the distro is so obsolete that the newer cPanel releases do not support it anymore.

          1 Reply Last reply
          0
          • mttaggart@infosec.exchangeM mttaggart@infosec.exchange

            Ugggh this one is going to suck. cPanel is everywhere and most are not patched frequently.

            https://www.bleepingcomputer.com/news/security/cpanel-whm-emergency-update-fixes-critical-auth-bypass-bug

            alesandroortiz@infosec.exchangeA This user is from outside of this forum
            alesandroortiz@infosec.exchangeA This user is from outside of this forum
            alesandroortiz@infosec.exchange
            wrote last edited by
            #5

            @mttaggart Detailed analysis by Watchtowr: https://labs.watchtowr.com/the-internet-is-falling-down-falling-down-falling-down-cpanel-whm-authentication-bypass-cve-2026-41940/

            1 Reply Last reply
            1
            0
            Reply
            • Reply as topic
            Log in to reply
            • Oldest to Newest
            • Newest to Oldest
            • Most Votes


            • Login

            • Login or register to search.
            • First post
              Last post
            0
            • Categories
            • Recent
            • Tags
            • Popular
            • World
            • Users
            • Groups