CVE-2026-32992Patch(cpanel / cpanel)

LOWCVSS 8.2 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch cpanel cpanel systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

SSL verification is disabled in the DNS Cluster system. This could allow for a malicious server to man-in-the-middle the request and capture credentials.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-295

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • cpanel
  • whm
  • wp_squared

Threat summary

  • Patch or workaround signal is available
  • 9 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 6 signals
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 2 classified signals
  • Peaked 4d ago at 4 mentions (2026-05-13); latest day: 1
  • 9 total mentions across 5 days

Affected systems

Vendors
Products
cpanelwhmwp_squared

Deep dive

Activity timeline9 mentions / 5d
01234Mentions · 2026-05-13: 4Mentions · 2026-05-14: 2Mentions · 2026-05-15: 1Mentions · 2026-05-29: 1Mentions · 2026-06-24: 1Patch / Workaround · 2026-05-13: 3Patch / Workaround · 2026-05-14: 1Patch / Workaround · 2026-05-15: 1Patch / Workaround · 2026-06-24: 1Technical Details · 2026-05-13: 2Technical Details · 2026-05-14: 105-1305-1405-1505-2906-24
Signal classification3 categories
Patch
555.6%
Disclosure
222.2%
General
222.2%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-05-134
Disclosure1General1Patch2
2026-05-142
Disclosure1Patch1
2026-05-151
Patch1
2026-05-291
General1
2026-06-241
Patch1
Full discourse9 posts
  • Rıdvan Yağlı@ridvanyagli
    Disclosure

    cPanel / WHM'de yeni güvenlik açıkları duyuruldu. Henüz NVD'de görünmeyen bu açıklar için bugün TSİ 21:00 dan sonra patch çıkacak. İlgili saatten sonra /scripts/upcp --force yapmayı unutmayın. * CVE-2026-29205 * CVE-2026-29206 * CVE-2026-32991 * CVE-2026-32992 * CVE-2026-32993

    Post summary

    The post announces new cPanel/WHM CVEs not yet listed in NVD, indicates a forthcoming patch at 21:00 TSİ, and reminds users to run /scripts/upcp --force afterward.

    10050285
    1.2K followersView on X
  • kokumօtօ@__kokumoto
    Patch

    cPanel & WHMでまた深刻な脆弱性5件が修正。CVE-2026-29205、CVE-2026-32993、CVE-2026-32992、CVE-2026-29206、CVE-2026-32991。 https://securityonline.info/cpanel-whm-security-patches-cve-2026-29205-file-read-sql-injection/

    Post summary

    The post announces that five critical cPanel & WHM CVEs have been patched, linking to a security patch article.

    00032886
    7.6K followersView on X
  • Lyrie.ai@lyrie_ai
    Patch

    cPanel & WHM is releasing an emergency security patch on May 13, 2026 at 1:00 PM EST addressing five HIGH-severity vulnerabilities (CVE-2026-29205, CVE-2026-29206, CVE-2026-32991, CVE-2026-32992, CVE-2026-32993) affecting versions 86 through 136. According to the vendor,…

    Post summary

    cPanel & WHM has announced an emergency patch to address five high‑severity CVEs impacting versions 86‑136, scheduled for release on May 13, 2026.

    1000031
    295 followersView on X
  • CERT-PY@CERTpy
    General

    ⚠️ Vulnerabilidades en productos cPanel ❗ CVE-2026-32993 ❗ CVE-2026-32992 ❗ CVE-2026-29205 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-cpanel-2/ https://t.co/XKmd99xRP0

    Post summary

    The tweet lists three CVEs that affect cPanel products and provides a link for more information, but offers no technical details, PoC, or mitigation steps.

    00010124
    6.7K followersView on X
  • Factoría Digital Hosting@factoriadigital
    Patch

    Actualizados los servidores de clientes a la ultima version de cPanel que ha salido hace 2h. Vulnerabilidades corregidas de riesgo ALTO: CVE-2026-29205, CVE-2026-29206, CVE-2026-32991, CVE-2026-32992, CVE-2026-32993.  No es necesaria ninguna acción. #seguridad #cPanel

    Post summary

    An announcement that the latest cPanel update includes patches for five high‑risk CVEs, and no further action is required.

    00010116
    799 followersView on X
  • TropicalServer 🚀@tropicalserver
    Patch

    #cPanel Después de parchear ayer: CVE-2026-29205 CVE-2026-29206 CVE-2026-32991 CVE-2026-32992 CVE-2026-32993 Hoy cPanel nos da la buena nueva de parchear de nuevo todos los servidores con la misma vulnerabilidad: CVE-2026-29205 no es que sea una nueva, es que la de ayer CVE-2026-29205 no esta bien parcheada https://x.com/tropicalserver/status/2052768638764036417?s=20

    Post summary

    The tweet announces that cPanel has re‑patched servers for CVE‑2026‑29205 after discovering the earlier patch was incomplete, but no exploit details or technical information are provided.

    00000113
    284 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-32992 Man-in-the-Middle Attack via Disabled SSL Verification in DNS Cluster System https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-32992

    Post summary

    The post announces CVE-2026-32992, describing a disabled SSL verification enabling a man‑in‑the‑middle attack, but gives no PoC, exploit, or patch information.

    0000063
    4.0K followersView on X
  • CVE@CVEnew
    General

    CVE-2026-32992 SSL verification is disabled in the DNS Cluster system. This could allow for a malicious server to man-in-the-middle the request and capture credentials. https://www.cve.org/CVERecord?id=CVE-2026-32992

    Post summary

    The post points out that CVE‑2026‑32992 disables SSL verification in DNS Cluster, allowing MITM to capture credentials, but provides no PoC, exploit, or remediation details.

    0000068
    57.5K followersView on X
  • Ken Brubacher@KenBrubacher
    Patch

    PSA Patch your servers again! Landing tomorrow at 1pm EST This is getting tedious This release addresses •CVE-2026-29205 •CVE-2026-29206  •CVE-2026-32991  •CVE-2026-32992  •CVE-2026-32993

    Post summary

    The PSA urges administrators to apply a new patch addressing five CVE identifiers announced tomorrow, highlighting the need for timely updates.

    00000105
    84 followersView on X
CPE platform detail3 entries

3 of 3 entries

PartVendorProductVersionTarget SWTarget HW
Appcpanelcpanel---
Appcpanelwhm---
Appcpanelwp_squared-wordpress-

Explore more