CVE-2026-32991Patch

MEDIUMCVSS 7.1 · HIGH

Exploitation observed; activity peaked at 4 mentions and remains active

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

Improper authorization checks of team members privileges allow a team member to escalate privileges to the team owner account.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-863

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 8 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 6 signals
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • Peaked 3d ago at 4 mentions (2026-05-13); latest day: 1
  • 8 total mentions across 4 days

Deep dive

Activity timeline8 mentions / 4d
01234Mentions · 2026-05-13: 4Mentions · 2026-05-14: 2Mentions · 2026-05-15: 1Mentions · 2026-06-24: 1Active Exploitation · 2026-05-14: 1Patch / Workaround · 2026-05-13: 3Patch / Workaround · 2026-05-14: 1Patch / Workaround · 2026-05-15: 1Patch / Workaround · 2026-06-24: 1Technical Details · 2026-05-13: 1Technical Details · 2026-05-14: 105-1305-1405-1506-24
Signal classification3 categories
Patch
675.0%
Disclosure
112.5%
Active Exploitation
112.5%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-05-134
Disclosure1Patch3
2026-05-142
Active Exploitation1Patch1
2026-05-151
Patch1
2026-06-241
Patch1
Full discourse8 posts
  • Rıdvan Yağlı@ridvanyagli
    Patch

    cPanel / WHM'de yeni güvenlik açıkları duyuruldu. Henüz NVD'de görünmeyen bu açıklar için bugün TSİ 21:00 dan sonra patch çıkacak. İlgili saatten sonra /scripts/upcp --force yapmayı unutmayın. * CVE-2026-29205 * CVE-2026-29206 * CVE-2026-32991 * CVE-2026-32992 * CVE-2026-32993

    Post summary

    The text announces new cPanel/WHM vulnerabilities identified by CVE numbers and announces a scheduled patch after 21:00, urging users to run /scripts/upcp --force.

    10050285
    1.2K followersView on X
  • kokumօtօ@__kokumoto
    Patch

    cPanel & WHMでまた深刻な脆弱性5件が修正。CVE-2026-29205、CVE-2026-32993、CVE-2026-32992、CVE-2026-29206、CVE-2026-32991。 https://securityonline.info/cpanel-whm-security-patches-cve-2026-29205-file-read-sql-injection/

    Post summary

    The post announces that five CVE-2026 vulnerabilities in cPanel & WHM have been patched, providing a link to further details.

    00032886
    7.6K followersView on X
  • Lyrie.ai@lyrie_ai
    Patch

    cPanel & WHM is releasing an emergency security patch on May 13, 2026 at 1:00 PM EST addressing five HIGH-severity vulnerabilities (CVE-2026-29205, CVE-2026-29206, CVE-2026-32991, CVE-2026-32992, CVE-2026-32993) affecting versions 86 through 136. According to the vendor,…

    Post summary

    cPanel & WHM is issuing an emergency patch for five HIGH‑severity CVEs without reference to PoC, exploit code, or active exploitation.

    1000031
    295 followersView on X
  • NerdieNews@NewsNerdie
    Active Exploitation

    Apache Team's CVE-2026-32991 is being exploited, allowing attackers to escalate privileges to team owner accounts. 🔴 Revoke access today to prevent unauthorized control. #NerdieNews #CyberSecurity #InfoSec #Vulnerability https://t.co/Uj4Ou16WFL

    Post summary

    The tweet asserts that CVE‑2026‑32991 is currently being exploited to gain team‑owner privileges, urging immediate revocation of access to prevent unauthorized control.

    0001051
    63 followersView on X
  • Factoría Digital Hosting@factoriadigital
    Patch

    Actualizados los servidores de clientes a la ultima version de cPanel que ha salido hace 2h. Vulnerabilidades corregidas de riesgo ALTO: CVE-2026-29205, CVE-2026-29206, CVE-2026-32991, CVE-2026-32992, CVE-2026-32993.  No es necesaria ninguna acción. #seguridad #cPanel

    Post summary

    The message confirms that recent cPanel updates have fixed several high‑risk CVEs, and no further action is required.

    00010116
    799 followersView on X
  • TropicalServer 🚀@tropicalserver
    Patch

    #cPanel Después de parchear ayer: CVE-2026-29205 CVE-2026-29206 CVE-2026-32991 CVE-2026-32992 CVE-2026-32993 Hoy cPanel nos da la buena nueva de parchear de nuevo todos los servidores con la misma vulnerabilidad: CVE-2026-29205 no es que sea una nueva, es que la de ayer CVE-2026-29205 no esta bien parcheada https://x.com/tropicalserver/status/2052768638764036417?s=20

    Post summary

    cPanel announced a new patch for CVE‑2026‑29205 after an earlier update was insufficient, focusing on remedial action rather than technical exploitation details.

    00000113
    284 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-32991 Improper authorization checks of team members privileges allow a team member to escalate privileges to the team owner account. https://www.cve.org/CVERecord?id=CVE-2026-32991

    Post summary

    The post announces CVE-2026-32991, describing a privilege escalation flaw via improper authorization checks, with no evidence of exploits, patches, or ongoing attacks.

    0000060
    57.5K followersView on X
  • Ken Brubacher@KenBrubacher
    Patch

    PSA Patch your servers again! Landing tomorrow at 1pm EST This is getting tedious This release addresses •CVE-2026-29205 •CVE-2026-29206  •CVE-2026-32991  •CVE-2026-32992  •CVE-2026-32993

    Post summary

    The message is a public safety announcement urging administrators to apply a patch for CVE-2026-29205, CVE-2026-29206, and CVE-2026-32991 to 32993, with no evidence of active exploitation or PoC presented.

    00000105
    84 followersView on X

Explore more