{"id":213610,"date":"2026-05-14T02:50:05","date_gmt":"2026-05-14T06:50:05","guid":{"rendered":"https:\/\/testing.news-you-need.com\/index.php\/2026\/05\/14\/cpanel-whm-release-fixes-for-three-new-vulnerabilities-patch-now\/"},"modified":"2026-05-14T02:50:07","modified_gmt":"2026-05-14T06:50:07","slug":"cpanel-whm-release-fixes-for-three-new-vulnerabilities-patch-now","status":"publish","type":"post","link":"https:\/\/testing.news-you-need.com\/index.php\/2026\/05\/14\/cpanel-whm-release-fixes-for-three-new-vulnerabilities-patch-now\/","title":{"rendered":"cPanel, WHM Release Fixes for Three New Vulnerabilities \u2014 Patch Now"},"content":{"rendered":"<p><a href=\"https:\/\/thehackernews.com\/2026\/05\/cpanel-whm-patch-3-new-vulnerabilities.html\">cPanel, WHM Release Fixes for Three New Vulnerabilities \u2014 Patch Now<\/a><\/p>\n<p><a href=\"https:\/\/thehackernews.com\/2026\/05\/cpanel-whm-patch-3-new-vulnerabilities.html\">https:\/\/thehackernews.com\/2026\/05\/cpanel-whm-patch-3-new-vulnerabilities.html<\/a><\/p>\n<p>Publish Date: <a href=\"publish_date]\">2026-05-09 03:16:00<\/a><\/p>\n<p>Source Domain: <a href=\"thehackernews.com\">thehackernews.com<\/a><\/p>\n<p><strong>Summary:<\/strong><br \/>\ncPanel has issued updates to remedy three vulnerabilities in its cPanel and Web Host Manager (WHM) software. These vulnerabilities, marked CVE-2026-29201, CVE-2026-29202, and CVE-2026-29203, pose serious risks including privilege escalation, arbitrary Perl code execution, and denial-of-service attacks, among other threats. The vulnerability CVE-2026-29202 and CVE-2026-29203 both have critical CVSS scores of 8.8. The update patches these flaws in several specified versions, starting from 11.136.0.9. cPanel urges users to update to the latest versions to secure their systems, especially given the backdrop of another recent critical flaw being weaponized in the wild as a zero-day exploit. Although no evidence exists of these new vulnerabilities being publicly exploited, the urgency is heightened by the ongoing threat scenarios emerging from related flaws.<\/p>\n<p><strong>Key Points:<\/strong><\/p>\n<ul>\n<li>Three critical vulnerabilities were found in cPanel and WHM which could lead to privilege escalation, code execution, and denial-of-service attacks.<\/li>\n<li>The identified CVEs are CVE-2026-29201, CVE-2026-29202, and CVE-2026-29203, with the latter two sharing a high CVSS score of 8.8.<\/li>\n<li>Users are required to update to specific or newer versions for patch protection, including starting from version 11.136.0.9.<\/li>\n<li>Although no proof of these vulnerabilities being exploited exist, updates are urged immediately especially after another critical flaw exploited as a zero-day.<\/li>\n<li>Immediate attention is suggested since it\u2019s crucial to prevent exploitation and ensure system security.<\/li>\n<\/ul>\n<p><\/p>\n","protected":false},"excerpt":{"rendered":"<p>cPanel, WHM Release Fixes for Three New Vulnerabilities \u2014 Patch Now https:\/\/thehackernews.com\/2026\/05\/cpanel-whm-patch-3-new-vulnerabilities.html Publish Date: 2026-05-09&#8230;<\/p>\n","protected":false},"author":1,"featured_media":213612,"comment_status":"closed","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEj8HLwOMzo20kbZmflPvJJmY7su6wWOWgDLV-dJNx-k76m5ivbwVoCkFrnsLXkyO4PHAyLSkPXinjK71SDmWabyOcTlKb3juZgkXTzOVuMvZk6-LUFMhoJ-UGFvv0qEby7QmYcjTWn1m1L19VTKeB7CdmKvpvIP5ifniLO92ARSLjtf8rcXIbm8AFMZei-M\/s1700-e365\/cpanel-3.jpg","fifu_image_alt":"","footnotes":""},"categories":[15],"tags":[31,27],"class_list":["post-213610","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-exploit","tag-vulnerability"],"_links":{"self":[{"href":"https:\/\/testing.news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/213610"}],"collection":[{"href":"https:\/\/testing.news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/testing.news-you-need.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/testing.news-you-need.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/testing.news-you-need.com\/index.php\/wp-json\/wp\/v2\/comments?post=213610"}],"version-history":[{"count":1,"href":"https:\/\/testing.news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/213610\/revisions"}],"predecessor-version":[{"id":213613,"href":"https:\/\/testing.news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/213610\/revisions\/213613"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/testing.news-you-need.com\/index.php\/wp-json\/wp\/v2\/media\/213612"}],"wp:attachment":[{"href":"https:\/\/testing.news-you-need.com\/index.php\/wp-json\/wp\/v2\/media?parent=213610"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/testing.news-you-need.com\/index.php\/wp-json\/wp\/v2\/categories?post=213610"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/testing.news-you-need.com\/index.php\/wp-json\/wp\/v2\/tags?post=213610"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}