A critical vulnerability in ConfigServer Security & Firewall (CSF), used on cPanel and WHM servers, could allow an unauthenticated remote attacker to execute arbitrary commands through the software’s MESSENGER service. The issue is tracked as CVE-2026-65638 and affects CSF versions 14.00 through 16.29.
CSF version 16.30 and later fixes the vulnerability. Administrators running affected installations should update the ConfigServer Firewall plugin immediately, especially where the MESSENGER feature has been manually enabled.
The flaw exists in the CSF MESSENGER service, a feature intended to display messages to blocked visitors. According to the security release, a remote attacker does not need to authenticate to exploit the vulnerable service.
Successful exploitation can result in arbitrary command execution under the CSF service account. This account is unprivileged, meaning the flaw does not automatically provide root-level access.
However, command execution on an internet-facing web server can still expose sensitive files, enable reconnaissance, create persistence, modify hosted content, or provide an initial foothold for further attacks.
The vulnerable functionality is not active by default. An attacker can reach the affected code only when both of these conditions are met:
Neither setting is enabled by default, reducing exposure for standard CSF deployments. However, organizations that enabled MESSENGER to manage blocked traffic or present custom visitor messages should treat the issue as urgent.
| Product | Affected versions | Patched versions |
|---|---|---|
| ConfigServer Security & Firewall | 14.00 through 16.29 | 16.30 and later |
CSF is widely deployed with cPanel and WHM environments to provide firewall management, login-failure detection, IP blocking, and related server-security controls.
Because it often runs on public hosting infrastructure, administrators should verify whether the vulnerable service is enabled even if they believe their installation uses default settings.
cPanel recommends updating the ConfigServer Firewall plugin to the latest available release. On supported CentOS 7, CloudLinux 7, AlmaLinux, CloudLinux 8, CloudLinux 9, CloudLinux 10, and Ubuntu systems, administrators can refresh packages and invoke the cPanel update process:
After updating, administrators should confirm that CSF version 16.30 or a newer release is installed. They should also review CSF configuration settings to ensure unnecessary internet-facing components remain disabled.
Organizations that can’t update immediately can reduce exposure by turning off the MESSENGER service. Administrators should connect to the server as root through SSH or the WHM Terminal and edit the CSF configuration file:
nano /etc/csf/csf.conf Set the following option: MESSENGER = 0
Then save the configuration and restart both CSF and the Login Failure Daemon service:
systemctl restart csf lfd Disabling MESSENGER removes the vulnerable attack path, but it should be considered a temporary safeguard. Installing CSF 16.30 or later remains the recommended remediation for CVE-2026-65638.
Learn 7 Metric-Gated AI SOC Deployment Phases – Download Free AI SOC Deployment Playbook 2026.
Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…
The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…
CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers…
Apple has released one of its largest coordinated security rollouts, addressing 273 distinct critical vulnerabilities…
You can’t detect today's attacks with yesterday’s threat intelligence; that’s how you could briefly formulate…
Microsoft has published a draft Humanist AI Code of Conduct that would prohibit its in-house…