← Back to feed
Vulnerabilities & PatchesEmerging1 sourceSep 11, 2026 · 11:28via Cyber Security News

cPanel ConfigServer Security & Firewall Vulnerability Allows Remote Attacker to Execute Arbitrary Commands

Brief

A critical vulnerability in ConfigServer Security & Firewall (CSF), used on cPanel and WHM servers , could allow an unauthenticated remote attacker to execute arbitrary commands through the software’s MESSENGER service. The issue is tracked as CVE-2026-65638 and affects CSF versions 14. 00 through 16.

  • CSF version 16. 30 and later fixes the vulnerability. Administrators running affected installations should update the ConfigServer Firewall plugin immediately, especially where the MESSENGER feature has been manually enabled.

The flaw exists in the CSF MESSENGER service, a feature intended to display messages to blocked visitors. According to the security release, a remote attacker does not need to authenticate to exploit the vulnerable service.

Successful exploitation can result in arbitrary command execution under the CSF service account.

Read more on Cyber Security News→