CVE-2026-32993Patch

LOWCVSS 8.3 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Improper sanitization of the `status` query parameter of the `/unprotected/nova_error` endpoint allows unauthenticated attacker to inject arbitrary HTTP header to the response.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-93

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 9 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 6 signals
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 4d ago at 4 mentions (2026-05-13); latest day: 1
  • 9 total mentions across 5 days

Deep dive

Activity timeline9 mentions / 5d
01234Mentions · 2026-05-13: 4Mentions · 2026-05-14: 2Mentions · 2026-05-15: 1Mentions · 2026-05-29: 1Mentions · 2026-06-24: 1Patch / Workaround · 2026-05-13: 3Patch / Workaround · 2026-05-14: 1Patch / Workaround · 2026-05-15: 1Patch / Workaround · 2026-06-24: 1Technical Details · 2026-05-13: 1Technical Details · 2026-05-14: 105-1305-1405-1505-2906-24
Signal classification3 categories
Patch
666.7%
Disclosure
222.2%
General
111.1%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-05-134
Disclosure1Patch3
2026-05-142
Disclosure1Patch1
2026-05-151
Patch1
2026-05-291
General1
2026-06-241
Patch1
Full discourse9 posts
  • Rıdvan Yağlı@ridvanyagli
    Patch

    cPanel / WHM'de yeni güvenlik açıkları duyuruldu. Henüz NVD'de görünmeyen bu açıklar için bugün TSİ 21:00 dan sonra patch çıkacak. İlgili saatten sonra /scripts/upcp --force yapmayı unutmayın. * CVE-2026-29205 * CVE-2026-29206 * CVE-2026-32991 * CVE-2026-32992 * CVE-2026-32993

    Post summary

    New, unlisted CVEs have been disclosed for cPanel/WHM with a patch set to be released after 21:00; users are advised to run /scripts/upcp --force once the patch is available.

    10050285
    1.2K followersView on X
  • kokumօtօ@__kokumoto
    Patch

    cPanel & WHMでまた深刻な脆弱性5件が修正。CVE-2026-29205、CVE-2026-32993、CVE-2026-32992、CVE-2026-29206、CVE-2026-32991。 https://securityonline.info/cpanel-whm-security-patches-cve-2026-29205-file-read-sql-injection/

    Post summary

    The post announces that cPanel and WHM have fixed five critical CVEs, providing a link to the patch details.

    00032886
    7.6K followersView on X
  • Lyrie.ai@lyrie_ai
    Patch

    cPanel & WHM is releasing an emergency security patch on May 13, 2026 at 1:00 PM EST addressing five HIGH-severity vulnerabilities (CVE-2026-29205, CVE-2026-29206, CVE-2026-32991, CVE-2026-32992, CVE-2026-32993) affecting versions 86 through 136. According to the vendor,…

    Post summary

    The announcement refers to an emergency patch for five high‑severity CVEs, without providing PoC details, exploit code, or evidence of active exploitation.

    1000031
    295 followersView on X
  • CERT-PY@CERTpy
    General

    ⚠️ Vulnerabilidades en productos cPanel ❗ CVE-2026-32993 ❗ CVE-2026-32992 ❗ CVE-2026-29205 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-cpanel-2/ https://t.co/XKmd99xRP0

    Post summary

    The post announces three CVEs for cPanel products and directs readers to a CERT page for more details, but provides no exploitation, patch, or technical information.

    00010124
    6.7K followersView on X
  • Factoría Digital Hosting@factoriadigital
    Patch

    Actualizados los servidores de clientes a la ultima version de cPanel que ha salido hace 2h. Vulnerabilidades corregidas de riesgo ALTO: CVE-2026-29205, CVE-2026-29206, CVE-2026-32991, CVE-2026-32992, CVE-2026-32993.  No es necesaria ninguna acción. #seguridad #cPanel

    Post summary

    The message announces that client servers were updated to the newest cPanel version, which resolves several high‑risk CVEs, and no additional action is required.

    00010116
    799 followersView on X
  • TropicalServer 🚀@tropicalserver
    Patch

    #cPanel Después de parchear ayer: CVE-2026-29205 CVE-2026-29206 CVE-2026-32991 CVE-2026-32992 CVE-2026-32993 Hoy cPanel nos da la buena nueva de parchear de nuevo todos los servidores con la misma vulnerabilidad: CVE-2026-29205 no es que sea una nueva, es que la de ayer CVE-2026-29205 no esta bien parcheada https://x.com/tropicalserver/status/2052768638764036417?s=20

    Post summary

    The tweet communicates that cPanel has re‑patched all servers for CVE‑2026‑29205 after discovering the prior patch was incomplete.

    00000113
    284 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-32993 Unauthenticated HTTP Header Injection in Unprotected Nova Error Endpoint https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-32993

    Post summary

    A new CVE (CVE‑2026‑32993) describes an unauthenticated HTTP header injection flaw in Nova’s error endpoint; no exploit code, patch, or active-use evidence is supplied.

    0000053
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-32993 Improper sanitization of the `status` query parameter of the `/unprotected/nova_error` endpoint allows unauthenticated attacker to inject arbitrary HTTP header to the… https://www.cve.org/CVERecord?id=CVE-2026-32993

    Post summary

    The statement discloses CVE-2026-32993, detailing an HTTP header injection vulnerability via an unauthenticated endpoint, with no evidence of PoC, exploit, patch, or active exploitation.

    0000086
    57.5K followersView on X
  • Ken Brubacher@KenBrubacher
    Patch

    PSA Patch your servers again! Landing tomorrow at 1pm EST This is getting tedious This release addresses •CVE-2026-29205 •CVE-2026-29206  •CVE-2026-32991  •CVE-2026-32992  •CVE-2026-32993

    Post summary

    The message advertises a patch release that addresses several CVEs and urges users to apply the update.

    00000105
    84 followersView on X

Explore more