HomeSecurityCritical authentication vulnerability in cPanel - Update now

Critical authentication vulnerability in cPanel – Update now

cPanel has released security updates to address an issue affecting various authentication paths . The vulnerability could allow an attacker to gain access to the control panel software .

cPanel

cPanel: Fixes

The issue affects all currently supported versions and has been addressed in the most recent:

  • 11.110.0.97
  • 11.118.0.63
  • 11.126.0.54
  • 11.132.0.29
  • 11.136.0.5
  • 11.134.0.20

The company recommends that users update servers as soon as possible, as they may also be affected.

See also: Chrome: Emergency update fixes 30 security vulnerabilities

Although cPanel did not share specific details about the vulnerability, Namecheap revealed that it is related to an authentication login exploit that could allow unauthorized access to the control panel.

Critical authentication vulnerability in cPanel - Update now

As a precautionary measure, the company has implemented a firewall rule to block access to TCP ports 2083 and 2087.This will temporarily limit customer access to the cPanel and WHM interfaces (until a full fix is ​​implemented).

Namecheap stated: “Our team is actively monitoring the situation and will apply the official fix to all supported servers as soon as it becomes available. Access to your control panels will be restored immediately once the fix is ​​successfully applied.”

See also: CISA: ConnectWise and Windows vulnerabilities in the KEV Catalog

So far, the fix has been applied to Reseller, Stellar Business, and other, according to Namecheap's Support Team.

This vulnerability highlights the need for constant vigilance and immediate response to security issues that may arise in critical infrastructures such as cPanel. System administrators and security managers must always be ready to deal with such situations with speed and accuracyin order to protect their customers' data and services.

See also: LiteLLM: Vulnerability exploited 36 hours after disclosure

Critical authentication vulnerability in cPanel - Update now

cPanel, as one of the most popular platforms in its industry, is a target for attacks, which makes security updates critical to maintaining the integrity and security of systems. Users should monitor security announcements and apply updates as soon as possible to ensure that their servers remain secure.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS