JeromeUG🇺🇬[verified]@jeromeug_Patch
The text advises shared cPanel hosts to verify patch status for CVE‑2026‑58048, CVE‑2026‑58047, and confirm the CVE‑2026‑41940 patch, noting it had been exploited in the wild, and to rotate credentials afterward.
ThaiCERT By NCSA[verified]@ThaiCERTByNCSAPatch
Thai CERT released a security advisory for CVE‑2026‑58048, detailing a critical privilege‑escalation flaw in cPanel/WHM and WP Squared, providing patch build information and mitigation steps.
Daily CyberSecurity@Daily_CyberSecDisclosure
The post announces two new cPanel vulnerabilities: CVE-2026-58048 permits root SQL execution with a CVSS score of 9.4, while CVE-2026-58047 enables request smuggling.
Infoflowcloud@infoflowcloudDisclosure
CVE-2026-58047 discloses an HTTP Smuggling flaw in cPanel that could leak credentials; no PoC, exploit code, patches, or active exploitation details are present.
CVE@CVEnewGeneral
A brief note references CVE‑2026‑58047, noting HTTP smuggling could leak credentials, with only a link to the CVE record and no further actionable details.
VulDB 🛡@vuldbActive Exploitation
The post indicates that attackers are increasingly targeting WebPros cPanel and WP Squared via CVE-2026-58047, suggesting active exploitation in the wild, but provides no mitigation or technical details.