<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #cPanel</title><description>Cybersecurity articles tagged #cPanel on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>CVE-2026-58048: cPanel &amp; WHM Critical SQL Privilege Escalation</title><link>https://runtimerebel.com/blog/cve-2026-58048-cpanel-whm-critical-sql-privilege-escalation</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-58048-cpanel-whm-critical-sql-privilege-escalation</guid><description>A critical flaw in cPanel &amp; WHM (CVE-2026-58048) allows authenticated users to execute SQL as database root, potentially leading to OS-level compromise.</description><pubDate>Tue, 04 Aug 2026 11:21:13 GMT</pubDate><category>cPanel</category><category>SQL Injection</category><category>Privilege Escalation</category><category>Web Hosting</category><category>WHM</category></item><item><title>GitHub Actions Runners Weaponized to Attack cPanel and WHM Servers</title><link>https://runtimerebel.com/blog/github-actions-runners-weaponized-to-attack-cpanel-and-whm-servers</link><guid isPermaLink="true">https://runtimerebel.com/blog/github-actions-runners-weaponized-to-attack-cpanel-and-whm-servers</guid><description>Attackers are leveraging GitHub Actions runners and compromised Packagist packages to launch distributed attacks against cPanel and WHM server instances.</description><pubDate>Thu, 23 Jul 2026 14:05:01 GMT</pubDate><category>GitHub Actions</category><category>Packagist</category><category>cPanel</category><category>WHM</category><category>Supply Chain Attack</category><category>PHP</category></item><item><title>CVE-2026-54420: LiteSpeed cPanel Plugin Flaw Under Active Exploit</title><link>https://runtimerebel.com/blog/cve-2026-54420-litespeed-cpanel-plugin-flaw-under-active-exploit</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-54420-litespeed-cpanel-plugin-flaw-under-active-exploit</guid><description>CISA warns of active exploitation targeting CVE-2026-54420 in LiteSpeed cPanel user-end plugin, urging immediate patching for server security.</description><pubDate>Tue, 16 Jun 2026 13:58:29 GMT</pubDate><category>CVE-2026-54420</category><category>LiteSpeed</category><category>cPanel</category><category>Active Exploitation</category><category>CISA</category><category>Web Hosting</category></item><item><title>CVE-2024-50498: CISA Orders Patch for Exploited cPanel Plugin Flaw</title><link>https://runtimerebel.com/blog/cve-2024-50498-cisa-orders-patch-for-exploited-cpanel-plugin-flaw</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2024-50498-cisa-orders-patch-for-exploited-cpanel-plugin-flaw</guid><description>CISA mandates federal agencies patch CVE-2024-50498, an actively exploited LiteSpeed cPanel plugin vulnerability, to prevent unauthorized account access.</description><pubDate>Wed, 27 May 2026 13:21:58 GMT</pubDate><category>CVE-2024-50498</category><category>cPanel</category><category>LiteSpeed</category><category>CISA KEV</category><category>XSS</category></item><item><title>CVE-2024-50498: Patch Exploited LiteSpeed cPanel Plugin Zero-Day</title><link>https://runtimerebel.com/blog/cve-2024-50498-patch-exploited-litespeed-cpanel-plugin-zero-day</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2024-50498-patch-exploited-litespeed-cpanel-plugin-zero-day</guid><description>CISA warns of active exploitation of CVE-2024-50498 in LiteSpeed cPanel plugins, allowing attackers to execute scripts with root privileges. Patch now.</description><pubDate>Wed, 27 May 2026 09:17:56 GMT</pubDate><category>CVE-2024-50498</category><category>LiteSpeed</category><category>cPanel</category><category>CISA KEV</category><category>RCE</category><category>Privilege Escalation</category></item><item><title>CVE-2026-48172: LiteSpeed cPanel Plugin Privilege Escalation - Patch Now</title><link>https://runtimerebel.com/blog/cve-2026-48172-litespeed-cpanel-plugin-privilege-escalation-patch-now</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-48172-litespeed-cpanel-plugin-privilege-escalation-patch-now</guid><description>Exploitation of CVE-2026-48172 in the LiteSpeed cPanel plugin allows local users to gain root access. Organizations should update to version 1.2.2 immediately.</description><pubDate>Sat, 23 May 2026 08:47:28 GMT</pubDate><category>CVE-2026-48172</category><category>LiteSpeed</category><category>cPanel</category><category>Privilege Escalation</category><category>Exploitation</category></item><item><title>cPanel CVE-2026-41940 Exploited for Authentication Bypass, Backdoor</title><link>https://runtimerebel.com/blog/cpanel-cve-2026-41940-exploited-for-authentication-bypass-backdoor</link><guid isPermaLink="true">https://runtimerebel.com/blog/cpanel-cve-2026-41940-exploited-for-authentication-bypass-backdoor</guid><description>A critical authentication bypass vulnerability, CVE-2026-41940, in cPanel and WHM is under active exploitation to deploy the Filemanager backdoor.</description><pubDate>Mon, 11 May 2026 20:39:59 GMT</pubDate><category>CVE-2026-41940</category><category>cPanel</category><category>WebHost Manager</category><category>Mr Rot13</category><category>Filemanager Backdoor</category><category>Authentication Bypass</category><category>Active Exploitation</category></item><item><title>cPanel/WHM Security Update: Mitigating CVE-2026-29201 Risks</title><link>https://runtimerebel.com/blog/cpanel-whm-security-update-mitigating-cve-2026-29201-risks</link><guid isPermaLink="true">https://runtimerebel.com/blog/cpanel-whm-security-update-mitigating-cve-2026-29201-risks</guid><description>cPanel and WHM release patches for three vulnerabilities, including CVE-2026-29201, which allows for privilege escalation and remote code execution.</description><pubDate>Sat, 09 May 2026 08:38:00 GMT</pubDate><category>cPanel</category><category>WHM</category><category>CVE-2026-29201</category><category>Privilege Escalation</category><category>Web Hosting</category></item><item><title>CVE-2023-29489: How Attackers Exploit cPanel XSS for Auth Bypass</title><link>https://runtimerebel.com/blog/cve-2023-29489-how-attackers-exploit-cpanel-xss-for-auth-bypass</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2023-29489-how-attackers-exploit-cpanel-xss-for-auth-bypass</guid><description>A critical authentication bypass in cPanel via CVE-2023-29489 is under active exploitation. Discover technical details and essential mitigation steps.</description><pubDate>Mon, 04 May 2026 20:36:54 GMT</pubDate><category>cPanel</category><category>CVE-2023-29489</category><category>Authentication Bypass</category><category>XSS</category><category>Web Hosting</category></item><item><title>cPanel CVE-2026-41940 Exploitation: 40,000 Servers Compromised</title><link>https://runtimerebel.com/blog/cpanel-cve-2026-41940-exploitation-40000-servers-compromised</link><guid isPermaLink="true">https://runtimerebel.com/blog/cpanel-cve-2026-41940-exploitation-40000-servers-compromised</guid><description>Attackers leverage a zero-day vulnerability in cPanel, identified as CVE-2026-41940, to gain administrative access to over 40,000 hosting servers.</description><pubDate>Mon, 04 May 2026 08:56:30 GMT</pubDate><category>cPanel</category><category>CVE-2026-41940</category><category>Remote Code Execution</category><category>Server Security</category></item><item><title>CVE-2026-41940: Critical cPanel Vulnerability Exploited by Sorry Ransomware</title><link>https://runtimerebel.com/blog/cve-2026-41940-critical-cpanel-vulnerability-exploited-by-sorry-ransomware</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-41940-critical-cpanel-vulnerability-exploited-by-sorry-ransomware</guid><description>Attackers are mass-exploiting CVE-2026-41940 in cPanel to deploy Sorry ransomware. Learn how to detect CVE-2026-41940 exploit and protect your web servers.</description><pubDate>Sun, 03 May 2026 00:52:05 GMT</pubDate><category>cPanel</category><category>Sorry Ransomware</category><category>CVE-2026-41940</category><category>RCE</category><category>Web Hosting</category></item><item><title>CVE-2026-41940: Active Zero-Day Exploitation in cPanel and WHM</title><link>https://runtimerebel.com/blog/cve-2026-41940-active-zero-day-exploitation-in-cpanel-and-whm</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-41940-active-zero-day-exploitation-in-cpanel-and-whm</guid><description>Critical zero-day CVE-2026-41940 in cPanel and WHM allows for authentication bypass. Learn about active exploitation, public PoCs, and essential patch guidance.</description><pubDate>Thu, 30 Apr 2026 12:41:01 GMT</pubDate><category>cPanel</category><category>WHM</category><category>CVE-2026-41940</category><category>Authentication Bypass</category><category>Zero-Day</category></item><item><title>CVE-2020-27686: cPanel and WHM 2FA Authentication Bypass Mitigation</title><link>https://runtimerebel.com/blog/cve-2020-27686-cpanel-and-whm-2fa-authentication-bypass-mitigation</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2020-27686-cpanel-and-whm-2fa-authentication-bypass-mitigation</guid><description>Administrators must patch cPanel and WHM immediately to address a critical 2FA bypass vulnerability that allows attackers to brute-force security codes.</description><pubDate>Wed, 29 Apr 2026 16:38:47 GMT</pubDate><category>cPanel</category><category>WHM</category><category>CVE-2020-27686</category><category>2FA Bypass</category><category>Auth Bypass</category><category>Brute Force</category></item><item><title>cPanel Authentication Bypass: Patch Guidance for Versions 11.132.0.29</title><link>https://runtimerebel.com/blog/cpanel-authentication-bypass-patch-guidance-for-versions-11-132-0-29</link><guid isPermaLink="true">https://runtimerebel.com/blog/cpanel-authentication-bypass-patch-guidance-for-versions-11-132-0-29</guid><description>cPanel releases critical updates to address an authentication bypass vulnerability affecting all supported versions. Administrators should patch immediately.</description><pubDate>Wed, 29 Apr 2026 12:41:17 GMT</pubDate><category>cPanel</category><category>Authentication Bypass</category><category>Server Security</category><category>Web Hosting</category><category>Patch Management</category></item><item><title>Compromised Site Management Panels: A Commoditized Cybercrime Threat</title><link>https://runtimerebel.com/blog/compromised-site-management-panels-a-commoditized-cybercrime-threat</link><guid isPermaLink="true">https://runtimerebel.com/blog/compromised-site-management-panels-a-commoditized-cybercrime-threat</guid><description>Underground markets commoditize compromised cPanel and other site management panels, fueling phishing and scam infrastructure. Learn to secure web admin interfaces.</description><pubDate>Tue, 03 Mar 2026 16:23:08 GMT</pubDate><category>cPanel</category><category>Web Hosting</category><category>Phishing</category><category>Scams</category><category>Credential Theft</category><category>Cybercrime Markets</category><category>Web Security</category></item></channel></rss>