The latest cPanel and WHM vulnerabilities are a strong reminder that hosting control panels are high-value targets because they sit directly between users, websites, files, databases, mail, and server administration. The three patched flaws include arbitrary file read, authenticated arbitrary Perl code execution, and unsafe symlink handling that could lead to denial-of-service or possible privilege escalation. That is not exactly the kind of feature set anyone wants bundled with their hosting panel.

Hosting providers and administrators should update cPanel/WHM and WP Squared immediately, especially because another recent cPanel flaw was reportedly exploited as a zero-day to deliver Mirai variants and ransomware. Even where there is no evidence of active exploitation for these three issues, exposed hosting panels should be treated as sensitive infrastructure: enforce MFA, restrict admin access, review plugin/user activity, and monitor for unexpected file permission changes or suspicious Perl execution. Waiting for active exploitation before patching a control panel is basically leaving the master key under the welcome mat and admiring the mat.


cPanel has released updates to address three vulnerabilities in cPanel and Web Host Manager (WHM) that could be exploited to achieve privilege escalation, code execution, and denial-of-service. The list of vulnerabilities is as follows - CVE-2026-29201 (CVSS score: 4.3) - An insufficient input validation of the feature file name in the "feature::LOADFEATUREFILE" adminbin call that could result

Source: cPanel, WHM Release Fixes for Three New Vulnerabilities — Patch Now via The Hacker News — published 09 May 2026.