cPanel has released critical security updates for three new vulnerabilities discovered in cPanel and Web Host Manager (WHM) systems . These vulnerabilities could be exploited by attackers to escalate privileges, execute code , and cause denial-of-service attacks . The importance of these fixes is critical, as cPanel systems are used by millions of websites worldwide, including banking and healthcare organizations.

The three new vulnerabilities addressed are:
- CVE-2026-29201 with CVSS score of 4.3: This is an “insufficient input validation” on the feature file name in the “feature::LOADFEATUREFILE” adminbin call. This vulnerability could lead to arbitrary file reading from the system, allowing malicious users to gain access to sensitive configuration data.
- CVE-2026-29202 with CVSS score 8.8: Resulting from “insufficient input validation” of the “plugin” parameter in the “create_user API” call, which could allow Perl code execution on behalf of the already authenticated account system user. This vulnerability is particularly dangerous as it could lead to a complete compromise of the hosting system.
- CVE-2026-29203 with CVSS score of 8.8: Insecure symlink handling allows a user to modify the access permissions of an arbitrary file using the chmod. This could lead to a denial-of-service or even privilege escalation on the system. This vulnerability is particularly problematic in shared hosting environments where multiple users share the same system resources.
See also: CISA: cPanel & WHM Vulnerability in the KEV Catalog
cPanel: New releases and fixes
The vulnerabilities have been fixed in the following cPanel and WHM versions:
- 11.136.0.9 and newer
- 11.134.0.25 and newer
- 11.132.0.31 and newer
- 11.130.0.22 and newer
- 11.126.0.58 and newer
- 11.124.0.37 and newer
- 11.118.0.66 and newer
- 11.110.0.116 and newer
- 11.110.0.117 and newer
- 11.102.0.41 and newer
- 11.94.0.30 and newer
- 11.86.0.43 and newer
Regarding WP Squared:
- 11.136.1.10 and newer
cPanel has also released version 110.0.114 as an immediate update for customers still using CentOS 6 or CloudLinux 6.System administrators are advised to update to the latest versions immediately for optimal protection.
See also: Critical authentication vulnerability in cPanel – Update now

The disclosure of these vulnerabilities comes just days after another critical vulnerability in the product, CVE-2026-41940, which has already been exploited by threat actors as a zero-day to deliver variants of the Mirai botnet and a ransomware called Sorry. This underscores the criticality of applying security fixes immediately. The previous vulnerability, with a CVSS score of 9.8, affected all supported versions after 11.40 and was related to CRLF injection in the login and session management processes.
Security experts emphasize that the cPanel breach differs from typical website attacks, as WHM provides root access, which allows reading all accounts, installing malware, stealing credentials, and lateral movement across networks.
See also: Chrome: Emergency update fixes 30 security vulnerabilities
Administrators should restrict access to the API, monitor WHM logs for abnormal activity, and conduct regular checks to detect backdoors or modified files after a potential exploit.
