CVE-2026-67401
published 2026-09-09CVE-2026-67401: A vulnerability in cPanel allows a mail-enabled account to achieve remote code execution as root through SQLi in EmailTrack component
PriorityP270critical9.9CVSS 3.0
AVNACLPRLUINSCCHIHAH
EPSS
1.04%
62.5th percentile
A vulnerability in cPanel allows a mail-enabled account to achieve remote code execution as root through SQLi in EmailTrack component
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| webpros | cpanel | < 11.134.0.55 | 11.134.0.55 |
| webpros | cpanel | < 11.136.0.39 | 11.136.0.39 |
| webpros | cpanel | < 11.138.0.4 | 11.138.0.4 |
| webpros | cpanel | < 11.138.1.9 | 11.138.1.9 |
| webpros | cpanel | < 11.110.0.143 | 11.110.0.143 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Hackernews
⚡ Weekly Recap: Rogue AI Agents, WeChat Worm, PaperCut Attacks, AI Espionage, and Rootkits
blogs_hackernews·2026-09-14
CVE-2026-85046 ⚡ Weekly Recap: Rogue AI Agents, WeChat Worm, PaperCut Attacks, AI Espionage, and Rootkits
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## ⚡ Weekly Recap: Rogue AI Agents, WeChat Worm, PaperCut Attacks, AI Espionage, and Rootkits
AI keeps showing up in the wrong places. Attackers are using it to speed up exploits, test defenses, and automate more of the job. Some models are also crossing lines on their own. That is not a great combination.
The rest of the week is more familiar: old bugs still working, fresh exploit chains, exposed systems, weak defaults, and simple paths that should have been harder to abuse. A few of these stories are clever. Most are just easy.
Here’s what mattered this week.
## ⚡ Threat of the Week
OpenAI Agents Behind May 2026 Attack o
Hackernews
New cPanel Flaw Lets a Hosting Account With Mail Privileges Run Code as Root
blogs_hackernews·2026-09-09·CVSS 9.9
CVE-2026-67401 [CRITICAL] New cPanel Flaw Lets a Hosting Account With Mail Privileges Run Code as Root
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## New cPanel Flaw Lets a Hosting Account With Mail Privileges Run Code as Root
cPanel has patched a flaw that it says lets a single hosting account take control of an entire server. An authenticated account holder with mail-related privileges can create files of their choosing on the server through EmailTrack and, from there, run code as the root user.
cPanel published the advisory on September 8 and says every supported version of cPanel and WHM is affected.
The flaw is tracked as CVE-2026-67401 . cPanel's advisory calls it an SQL injection issue in EmailTrack, but does not say which cPanel feature or privilege an account ne
2026-09-09
Published