CVE-2026-67402
largeUnauthenticated RCE in ConfigServer Security & Firewall (CSF)
ConfigServer Security & Firewall (CSF) ships an insecure Apache configuration that maps the entire /usr/bin directory as CGI programs through the Messenger v3 HTTPS virtual host. A remote, unauthenticated attacker whose IP address is already blocked by CSF can request any mapped executable via that HTTPS vhost, causing Apache to treat it as a CGI script and execute it. Successful exploitation lets the attacker run arbitrary commands on the server with the privileges of the Apache user. Only installations with CSF Messenger v3 and its HTTPS mode enabled are affected; WebPros fixed the flaw in CSF version 16.31. No public proof-of-concept or in-the-wild exploitation is known, and EPSS currently estimates the 30-day exploitation probability at about 0.3%.
What to do: Upgrade CSF to version 16.31 or later. Until patched, disable Messenger v3 HTTPS mode (or the Messenger feature entirely) to remove the exposed virtual host, and confirm whether your configuration actually enables Messenger v3 with HTTPS. Review Apache access logs for requests to executables under /usr/bin arriving via the Messenger vhost as an indicator of probing or compromise.
| WebPros (ConfigServer) ConfigServer Security & Firewall (CSF) | All versions prior to 16.31 on installations where CSF Messenger v3 and its HTTPS mode are enabled |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
An insecure Apache configuration in ConfigServer Security & Firewall maps /usr/bin as CGI programs through the Messenger v3 HTTPS virtual host. A remote unauthenticated attacker whose address is blocked can request a mapped executable and run arbitrary commands as the Apache user. The vulnerability affects installations where CSF Messenger v3 and its HTTPS mode are enabled. WebPros addressed the vulnerability in version 16.31.
- Weakness
- CWE-552
- Vector
- CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.