Cyber Security News

cPanel ConfigServer Security & Firewall Vulnerability Allows Remote Attacker to Execute Arbitrary Commands

A critical vulnerability in ConfigServer Security & Firewall (CSF), used on cPanel and WHM servers, could allow an unauthenticated remote attacker to execute arbitrary commands through the software’s MESSENGER service. The issue is tracked as CVE-2026-65638 and affects CSF versions 14.00 through 16.29.

CSF version 16.30 and later fixes the vulnerability. Administrators running affected installations should update the ConfigServer Firewall plugin immediately, especially where the MESSENGER feature has been manually enabled.

The flaw exists in the CSF MESSENGER service, a feature intended to display messages to blocked visitors. According to the security release, a remote attacker does not need to authenticate to exploit the vulnerable service.

Successful exploitation can result in arbitrary command execution under the CSF service account. This account is unprivileged, meaning the flaw does not automatically provide root-level access.

However, command execution on an internet-facing web server can still expose sensitive files, enable reconnaissance, create persistence, modify hosted content, or provide an initial foothold for further attacks.

cPanel ConfigServer Security & Firewall Vulnerability

The vulnerable functionality is not active by default. An attacker can reach the affected code only when both of these conditions are met:

  • The MESSENGER service is enabled in CSF.
  • A reCAPTCHA secret has been configured for the service.

Neither setting is enabled by default, reducing exposure for standard CSF deployments. However, organizations that enabled MESSENGER to manage blocked traffic or present custom visitor messages should treat the issue as urgent.

ProductAffected versionsPatched versions
ConfigServer Security & Firewall14.00 through 16.2916.30 and later

CSF is widely deployed with cPanel and WHM environments to provide firewall management, login-failure detection, IP blocking, and related server-security controls.

Because it often runs on public hosting infrastructure, administrators should verify whether the vulnerable service is enabled even if they believe their installation uses default settings.

cPanel recommends updating the ConfigServer Firewall plugin to the latest available release. On supported CentOS 7, CloudLinux 7, AlmaLinux, CloudLinux 8, CloudLinux 9, CloudLinux 10, and Ubuntu systems, administrators can refresh packages and invoke the cPanel update process:

After updating, administrators should confirm that CSF version 16.30 or a newer release is installed. They should also review CSF configuration settings to ensure unnecessary internet-facing components remain disabled.

Organizations that can’t update immediately can reduce exposure by turning off the MESSENGER service. Administrators should connect to the server as root through SSH or the WHM Terminal and edit the CSF configuration file:

nano /etc/csf/csf.conf

Set the following option: MESSENGER = 0

Then save the configuration and restart both CSF and the Login Failure Daemon service:

systemctl restart csf lfd

Disabling MESSENGER removes the vulnerable attack path, but it should be considered a temporary safeguard. Installing CSF 16.30 or later remains the recommended remediation for CVE-2026-65638.

Learn 7 Metric-Gated AI SOC Deployment Phases – Download Free AI SOC Deployment Playbook 2026.

Abinaya

Abi is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.

Recent Posts

Google Chrome 153 Update Fixes 42 Security Flaws, Including 3 Critical Ones

Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…

21 minutes ago

CISA and NIST Release Technical Checklist for Safeguarding Identity Tokens From Theft and Misuse

The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…

10 hours ago

CISA Shares 17 Techniques Used by Hackers to Compromise Active Directory Environments

CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers…

11 hours ago

Apple Rolls Out Massive Security Update Fixing 273 Vulnerabilities Across Its Devices

Apple has released one of its largest coordinated security rollouts, addressing 273 distinct critical vulnerabilities…

12 hours ago

How to Keep Malware’s Rotating Infrastructure From Becoming a Detection Gap

You can’t detect today's attacks with yesterday’s threat intelligence; that’s how you could briefly formulate…

12 hours ago

Microsoft Bans Its AI Models From Launching Cyberattacks or Escalating Their Own Access

Microsoft has published a draft Humanist AI Code of Conduct that would prohibit its in-house…

12 hours ago