Cyber Security News

Critical Imunify360 AV Vulnerability Exposes 56 Million+ Linux-hosted Websites to RCE Attacks

A severe remote code execution (RCE) vulnerability has been discovered in Imunify360 AV, a widely used malware scanner protecting approximately 56 million websites.

The security flaw, recently patched by CloudLinux, allows attackers to execute arbitrary commands and potentially take complete control of hosting servers.

Patchstack researchers discovered a flaw in Imunify360 AV’s deobfuscation logic used to analyze malicious PHP code.

Imunify360 AV RCE Vulnerability

Attackers can create specially encoded PHP files that mislead the scanner into executing harmful functions, such as system(), exec(), or eval(), during analysis.

Because the scanner typically runs with root privileges, successful exploitation can result in a complete server takeover.

The Patchstack analysis highlights a concerning flaw: deobfuscation is automatically enabled in the default configuration of Imunify360 AV for all scan types.

AttributeDetails
Vulnerability TypeRemote Code Execution (RCE)
Product AffectedImunify360 AV (AI-Bolit)
Affected VersionsPrior to v32.7.4.0
Patched Versionv32.7.4.0 and later

Including background scans, on-demand scans, and rapid account scans. This means vulnerable systems are continuously at risk whenever the scanner operates. On shared hosting environments, this vulnerability poses exceptional danger.

Attackers who compromise a single website can escalate privileges to gain root access, compromising every website and customer on the same server.

This lateral movement capability makes the vulnerability especially severe for hosting providers serving multiple clients. CloudLinux released a patch on October 21, 2025, but has notably not issued a formal CVE assignment or security advisory.

Information about the vulnerability appeared on their Zendesk support page on November 4, 2025, even though exploitation details had been circulating since late October.

Patchstack experts recommend hosting companies not only patch immediately but also investigate whether their servers have already been compromised.

Hosting companies should upgrade to Imunify360 AV version 32.7.4.0 or later without delay and conduct forensic checks for signs of exploitation on their infrastructure.

Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

Abinaya

Abi is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

4 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

4 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

5 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

6 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

6 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

7 hours ago