CVE-2026-29201Patch

MEDIUMCVSS 8.6 · HIGH

Exploitation observed; activity peaked at 13 mentions and remains active

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

Insufficient input validation of the feature file name in `feature::LOADFEATUREFILE` adminbin call can cause arbitrary file read when a relative file path is passed.

4.3/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-23

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

DECLINING

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 41 mentions across 10 observed days
  • Momentum state: declining

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 29 signals
  • Technical details provided in 24 signals
  • Disclosure: 14 classified signals
  • Peaked 7d ago at 13 mentions (2026-05-10); latest day: 1
  • 41 total mentions across 10 days

Deep dive

Activity timeline41 mentions / 10d
0371013Mentions · 2026-05-08: 6Mentions · 2026-05-09: 7Mentions · 2026-05-10: 13Mentions · 2026-05-11: 5Mentions · 2026-05-12: 2Mentions · 2026-05-15: 1Mentions · 2026-05-21: 1Mentions · 2026-05-25: 1Mentions · 2026-06-08: 4Mentions · 2026-06-17: 1Active Exploitation · 2026-05-25: 1Patch / Workaround · 2026-05-08: 5Patch / Workaround · 2026-05-09: 5Patch / Workaround · 2026-05-10: 10Patch / Workaround · 2026-05-11: 5Patch / Workaround · 2026-06-08: 3Patch / Workaround · 2026-06-17: 1Technical Details · 2026-05-09: 6Technical Details · 2026-05-10: 10Technical Details · 2026-05-11: 4Technical Details · 2026-05-15: 1Technical Details · 2026-05-21: 1Technical Details · 2026-06-08: 1Technical Details · 2026-06-17: 105-0805-0905-1005-1105-1205-1505-2105-2506-0806-17
Signal classification4 categories
Patch
2561.0%
Disclosure
1434.1%
Active Exploitation
12.4%
General
12.4%
Referenced assets20 URLs
By indicator
Classification over time
DateTotalLabels
2026-05-086
Disclosure2Patch4
2026-05-097
Disclosure2Patch5
2026-05-1013
Disclosure4Patch9
2026-05-115
Patch5
2026-05-122
Disclosure2
2026-05-151
Disclosure1
2026-05-211
Disclosure1
2026-05-251
Active Exploitation1
2026-06-084
Disclosure2General1Patch1
2026-06-171
Patch1
Full discourse20 posts
  • Cyber Security News@The_Cyber_News
    Disclosure

    ⚠️ New cPanel and WHM Vulnerabilities Enable Code Execution, DoS Attacks Source: https://cybersecuritynews.com/cpanel-and-whm-flaws/ cPanel has disclosed three critical security vulnerabilities tracked as CVE-2026-29201, CVE-2026-29202, and CVE-2026-29203 affecting its widely deployed cPanel & WHM web hosting control panel and WP Squared (WP2) platform. The flaws, patched on May 8, 2026, expose servers to arbitrary file reads, Perl code injection, and denial-of-service (DoS) attacks, making immediate patching essential for hosting providers and server administrators. #cybersecuritynews

    Post summary

    The post discloses three critical CVEs in cPanel & WHM, describing the vulnerability mechanisms and emphasizing patching as of May 8, 2026.

    66752366124.0K
    68.9K followersView on X
  • إبراهيم بوحيمد | Ibrahim Buhaimed@buhaimedi
    Disclosure

    تذكرون ثغره (cPanel) (CVE-2026-41940) الي اكتشفت قبل اسبوع ؟ اكتشفت 3 ثغرات أمنية جديده و خطيرة. أخطر هذي الثغرات تعطي المهاجم صلاحيات لتنفيذ أوامر و اكواد على السيرفر. ⚙️ تفاصيل الثغرات الجديدة: الثغرة الأولى (CVE-2026-29201): خلل (Path Traversal) في مسار (LOADFEATUREFILE). الثغرة تسمح للمخترق بقراءة أي ملف على السيرفر، وهذا يشمل ملفات الإعدادات الحساسة، كلمات المرور، والمفاتيح الخاصة. الثغرة الثانية والأخطر (CVE-2026-29202): ثغرة تنفيذ أوامر عن بعد (RCE) في واجهة (create_user API). المخترق يقدر يرسل كود (Perl) خبيث وينفذه مباشرة على السيرفر. الثغرة الثالثة (CVE-2026-29203): تعامل غير آمن مع الروابط الرمزية (Symlinks). الثغرة تسمح للمستخدم بتغيير صلاحيات (chmod) لأي ملف على النظام، والنتيجة المحتملة هي إيقاف الخدمات (DoS) أو استغلاله لتنفيذ هجوم رفع الصلاحيات .

    Post summary

    The post discloses three new cPanel vulnerabilities (CVE-2026-29201, 29202, 29203) describing path traversal, remote code execution, and symlink abuse, but offers no PoC, exploit code, or patch information.

    19075335.9K
    50.0K followersView on X
  • محمد الربيعي@1ms25
    Patch

    [Important] cPanel & WHM Security Update CVE-2026-29201, CVE-2026-29202, CVE-2026-29203 الله يعينكم ويعين كل مسؤول عن السيرفرات https://t.co/bDMsJZ0eXC

    Post summary

    The tweet announces a cPanel & WHM security update addressing CVE-2026-29201 through CVE-2026-29203, urging administrators to apply the patch.

    010711.6K
    18.1K followersView on X
  • Somanos Sar@somanossar
    Patch

    cPanel/WHM users – this is your 2-minute warning! Just saw @The_Cyber_News drop this bomb: 3 fresh critical vulns (CVE-2026-29201, 2026-29202, 2026-29203) that let attackers execute code, read arbitrary files, OR DoS your entire server. Patched May 8th… but we all know how slow some hosts move. From my POV running production boxes daily, I patched the second I saw this. No way I’m gambling with client data again after the last CVE-2026-41940 mess. Be honest in the replies: ✅ Already patched? ❌ Still vulnerable? Or are you a hosting provider secretly hoping nobody notices? Tag your sysadmin, your boss, or that one friend still on auto-update denial. Let’s see who’s actually on it. #CyberSecurity #DataSovereignty

    Post summary

    A brief alert about three fresh critical cPanel vulnerabilities, emphasizing the need for admins to verify they have applied the May 8 patch.

    01060213
    930 followersView on X
  • Cybernorse@Cybernorseab
    Patch

    @The_Cyber_News Critical cPanel & WHM flaws (CVE-2026-29201-3) allow code execution & DoS. Hosting providers: patch now to prevent remote injection and maintain server security. #Cybernorse

    Post summary

    The post warns of code execution and DoS vulnerabilities in cPanel & WHM, urging immediate patching to mitigate remote injection risks.

    01030291
    19 followersView on X
  • Tre B@trerbbb
    Patch

    cpanel patched 3 bugs on May 8: CVE-2026-29201 (arbitrary file read), CVE-2026-29202 (perl code injection), CVE-2026-29203 (DoS). if you operate shared hosting, WHM is on every box. patch and audit Perl handlers. #cPanel

    Post summary

    cPanel released patches for three CVEs (arbitrary file read, Perl code injection, DoS) on May 8; administrators are advised to apply the patches and audit Perl handlers.

    01020105
    17 followersView on X
  • eUKhost®@eUKhostLtd
    Disclosure

    ⚠️ Precautionary cPanel Advisory. Due to newly disclosed cPanel threats (CVE-2026-29201/2/3), we’ve temporarily restricted several cPanel-related ports pending an emergency vendor update expected later today. Updates: https://status.hyperslice.com/

    Post summary

    The advisory announces newly disclosed cPanel CVEs (CVE-2026-29201/2/3), temporarily disables related ports, and indicates an impending emergency patch.

    00030261
    12.9K followersView on X
  • Gustavo Gallas@ggallas
    Patch

    cPanel just released its second emergency patch in 10 days. CVE-2026-29202: arbitrary Perl code execution (CVSS 8.8) CVE-2026-29203: privilege escalation via symlink (CVSS 8.8) CVE-2026-29201: arbitrary file read If you run cPanel/WHM, run this now: /scripts/upcp Full breakdown 👇 https://www.copahost.com/blog/cpanels-black-week-three-new-vulnerabilities-patched-after-ransomware-attack-on-44000-servers/ #CyberSecurity #sysadmin #cpanel

    Post summary

    cPanel issued an emergency patch for three CVEs—arbitrary Perl code execution, privilege escalation via symlink, and arbitrary file read—by instructing users to run `/scripts/upcp`.

    010102.6K
    372 followersView on X
  • Red Secure Tech Ltd.@redsecuretech
    Patch

    Three cPanel WHM privilege escalation vulnerabilities (CVE-2026-29201, CVE-2026-29202, CVE-2026-29203) allow file read, code execution, and symlink attacks. https://www.redsecuretech.co.uk/blog/post/cpanel-whm-privilege-escalation-vulnerabilities-get-patches/1168 #cPanel #WHM #CVE #PerlCodeExecution #SymlinkVulnerability #SorryRansomware #InfoSec https://t.co/irYEMsBcho

    Post summary

    Three new cPanel WHM privilege‑escalation CVEs (CVE‑2026‑29201–29203) enable file read, code execution, and symlink attacks, and patches are referenced via the provided link.

    0101078
    48 followersView on X
  • Webhosting UK@WebhostingUKcom
    Patch

    ⚠️ Precautionary cPanel Advisory. Due to newly disclosed cPanel threats (CVE-2026-29201/2/3), we’ve temporarily restricted several cPanel-related ports pending an emergency vendor update expected later today. Updates: https://status.hyperslice.com/

    Post summary

    An advisory warns of newly disclosed cPanel CVEs and announces a pending emergency vendor update; it does not provide a PoC, exploit, or technical specifics.

    00020273
    8.2K followersView on X
  • Bendigo Aerial@BendigoAerial
    Patch

    🚨 cPanel/WHM Security Alert Three new vulnerabilities CVE-2026-29201 CVE-2026-29202 CVE-2026-29203 cPanel has issued a preemptive advisory. Details are limited until patches drop (today ~12pm EST), but they affect multiple supported versions. Update ASAP Check your cPanel/WHM servers now and apply patches immediately when available! 🔒

    Post summary

    cPanel announced a preemptive advisory for three CVE‑2026‑29201/29202/29203 and urged users to patch promptly. No exploit details or active attack reports are provided.

    00020203
    537 followersView on X
  • WebTuga - Alojamento Web@webtugahosting
    Disclosure

    🚨 cPanel & WHM anunciou novas vulnerabilidades: ▪️ CVE-2026-29201 ▪️ CVE-2026-29202 ▪️ CVE-2026-29203 +Info: https://status.wt.pt/vulnerabilidades-cpanel-whm-cve-2026-29201-cve-2026-29202-cve-2026-29203/ https://t.co/9octF8BhCd

    Post summary

    The tweet announces the existence of three new CVEs (2026‑29201, 2026‑29202, 2026‑29203) affecting cPanel & WHM, but provides no further technical details, exploit code, or patch information.

    01010197
    1.1K followersView on X
  • Lyrie.ai@lyrie_ai
    Patch

    Then, on May 8—ten days after the first patch—cPanel quietly issued a second Technical Security Release (TSR) covering three additional vulnerabilities: CVE-2026-29201 (CVSS 4.3): Arbitrary file read via insufficient input validation in the feature file name parameter…

    Post summary

    The statement announces a patch release for CVE-2026-29201, providing technical details of the vulnerability but no evidence of exploitation or PoC.

    1000027
    289 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    Sources cPanel Pre-Discloses Three New CVEs (CVE-2026-29201, 29202, 29203) — Second Emergency TSR in 10 Days cPanel's 30-Day Security Storm: 44,000 Servers, 70M Domains, Two Emergency TSRs cPanel Support: CVE-2026-29201/29202/29203 Security Advisory KnownHost Community…

    Post summary

    The text reports the announcement of three new CVEs along with a security advisory but lacks detailed technical or operational information.

    1000026
    258 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    cPanel has pre-disclosed three new CVEs (CVE-2026-29201, -29202, -29203) scheduled for patch release on May 8, 2026 at 12:00 EST — the second emergency Technical Security Release (TSR) in 10 days. This follows CVE-2026-41940, a CVSS 9.8 auth bypass that spent nearly three…

    Post summary

    cPanel pre‑disclosed CVE‑2026‑29201, ‑29202, ‑29203 with a patch scheduled for May 8, 2026; additionally references a high‑severity auth bypass in CVE‑2026‑41940, but no PoC, exploit, or active exploitation is reported.

    1000031
    258 followersView on X
  • Lyrie.ai@lyrie_ai
    Patch

    Key Details: CVE Numbers: CVE-2026-29201, CVE-2026-29202, CVE-2026-29203 Patch Release: May 8, 2026, 12:00 EST Update Method: Automated tier-based distribution through cPanel's update mechanism; manual execution via /scripts/upcp for pinned or disabled auto-update servers…

    Post summary

    The notice announces an upcoming patch for CVE-2026-29201, CVE-2026-29202, and CVE-2026-29203 with scheduled release and automatic or manual update instructions.

    1000027
    258 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    The cPanel Security Pattern: Three New CVEs, Second Emergency TSR in 10 Days. cPanel has pre-disclosed three new CVEs CVE-2026-29201, -29202, -29203 scheduled for patch release on May 8, 2026 at 12:00 EST — the second emergency Technical Security Release TSR in 10 days.

    Post summary

    cPanel publicly disclosed three new CVEs and announced a scheduled patch release date, without providing technical details or exploitation information.

    1000030
    258 followersView on X
  • Nikopol@nikoqol
    Active Exploitation

    Çok var… Geçenlerde Nisan ayında ortaya çıkan cPanel/WHM’deki kritik güvenlik açığı (CVE-2026-29201) nedeniyle, e-ticaret müşterilerimden birinin sitesine ransomware bulaşmıştı. Tüm verileri şifreleyip, belirtilen BTC cüzdanına ödeme istemişlerdi. Veri kurtarma süreci hem riskli hem de çok maliyetli olduğu için eski sistemi toparlayamadık; yeni bir sunucu kurup tüm şifreleri değiştirerek sistemi o şekilde teslim etmiştim. Daha önce de abimin grafik tasarımcı olarak çalıştığı büyük bir firmaya benzer şekilde ransomware bulaşmıştı. Adamlar yaklaşık 4.5 milyon TL ödeme yapmak zorunda kalmıştı. Çok ciddi paralar dönüyor. Açıkçası bu tarz telefon dolandırıcılıkları, onların yanında çerez gibi kalıyor. @grok

    Post summary

    The user reports real ransomware incidents caused by CVE‑2026‑29201, confirming active exploitation but without details on PoC, patches, or technical depth.

    1000059
    362 followersView on X
  • iototsecnews@iototsecnews
    Disclosure

    cPanel/WHM の脆弱性 CVE-2026-29201/29202/29203 が FIX:コード実行や DoS 攻撃の可能性 https://iototsecnews.jp/2026/05/10/new-cpanel-and-whm-flaws-enable-code-execution-dos-attacks/ Web サーバ管理ツール cPanel & WHM および WP Squared に、3 件の深刻な脆弱性が発見されました。問題の原因は、外部からの入力データに対する不十分な検証や、ファイル操作における不適切なルールなどにあります。これらの脆弱性は、複数のユーザーが 1台のサーバーを共有するホスティング環境において、隣のユーザーのデータに干渉するなど、基盤の安全性を揺るがすものとなっています。ご利用のチームは、ご注意ください。 #cPanel #CVE202629201 #CVE202629202 #CVE202629203 #Vulnerability #WHM

    Post summary

    The article announces the discovery of three critical cPanel and WHM vulnerabilities that could allow code execution and denial‑of‑service attacks in shared hosting environments.

    01000254
    489 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    cPanel has disclosed three critical security vulnerabilities tracked as CVE-2026-29201, CVE-2026-29202, and CVE-2026-29203 affecting its widely deployed cPanel & WHM web

    Post summary

    cPanel has announced three critical vulnerabilities—CVE-2026-29201, CVE-2026-29202, and CVE-2026-29203—affecting its cPanel & WHM platform; the text does not provide further details on exploitation, mitigation, or technical specifics.

    1000049
    210 followersView on X

Explore more