60
55
30
30
cPanel ConfigServer Security & Firewall Vulnerability Allows Remote Attacker to Execute Arbitrary Commands
CSF 14.00–16.29 (CVE-2026-65638) lets unauthenticated attackers execute arbitrary commands via the MESSENGER service on cPanel/WHM servers; version 16.30 fixes it.
CVE-2026-65638 affects ConfigServer Security & Firewall (CSF) versions 14.00 through 16.29 and allows unauthenticated remote attackers to execute arbitrary commands through the MESSENGER service, running under the unprivileged CSF service account rather than root. Exploitation requires the non-default MESSENGER service to be enabled and a reCAPTCHA secret configured, reducing exposure for standard deployments. CSF 16.30 and later fix the flaw; administrators who cannot update immediately can set MESSENGER = 0 in /etc/csf/csf.conf as a temporary mitigation.
55
30
30
55
30
55
30
60
60
30
30
30
55
55
55
60
30
30
55
30
Week in review: Attackers trying to access Check Point VPNs, NIST CSF 2.0 security metrics evolution
60
55
42
42
57
30
42
30
55
30
55
30
55
55
55
42