ZeroHour

CVE-2026-67402

large

Unauthenticated RCE in ConfigServer Security & Firewall (CSF)

CVSS 4.0
9.2 critical
EPSS
<1%p25
Published
()
Modified
AI analysis

ConfigServer Security & Firewall (CSF) ships an insecure Apache configuration that maps the entire /usr/bin directory as CGI programs through the Messenger v3 HTTPS virtual host. A remote, unauthenticated attacker whose IP address is already blocked by CSF can request any mapped executable via that HTTPS vhost, causing Apache to treat it as a CGI script and execute it. Successful exploitation lets the attacker run arbitrary commands on the server with the privileges of the Apache user. Only installations with CSF Messenger v3 and its HTTPS mode enabled are affected; WebPros fixed the flaw in CSF version 16.31. No public proof-of-concept or in-the-wild exploitation is known, and EPSS currently estimates the 30-day exploitation probability at about 0.3%.

What to do: Upgrade CSF to version 16.31 or later. Until patched, disable Messenger v3 HTTPS mode (or the Messenger feature entirely) to remove the exposed virtual host, and confirm whether your configuration actually enables Messenger v3 with HTTPS. Review Apache access logs for requests to executables under /usr/bin arriving via the Messenger vhost as an indicator of probing or compromise.

Affected
WebPros (ConfigServer) ConfigServer Security & Firewall (CSF)All versions prior to 16.31 on installations where CSF Messenger v3 and its HTTPS mode are enabled
Estimated exposure
largetens of thousands of cPanel/WHM servers with Messenger v3 HTTPS enabled — CSF is one of the most widely deployed firewall add-ons across the global fleet of several hundred thousand cPanel/WHM servers, but only the opt-in Messenger v3 HTTPS configuration is vulnerable, so the plausibly affected population is one…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An insecure Apache configuration in ConfigServer Security & Firewall maps /usr/bin as CGI programs through the Messenger v3 HTTPS virtual host. A remote unauthenticated attacker whose address is blocked can request a mapped executable and run arbitrary commands as the Apache user. The vulnerability affects installations where CSF Messenger v3 and its HTTPS mode are enabled. WebPros addressed the vulnerability in version 16.31.

Weakness
CWE-552
Vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.