cPanel Urges Users to Patch ConfigServer Firewall Remote Code Execution Flaw (CVE-2026-65638)
CVE-2026-65638 in ConfigServer Security & Firewall (CSF) 14.00-16.29 lets unauthenticated remote attackers execute arbitrary commands via the MESSENGER service on cPanel/WHM servers; updating to CSF 16.30 or later fixes the flaw.
CVE-2026-65638 affects ConfigServer Security & Firewall (CSF) versions 14.00 through 16.29 and allows unauthenticated remote attackers to execute arbitrary commands through the MESSENGER service. Exploitation is only possible when the non-default MESSENGER service is enabled and a reCAPTCHA secret has been configured, reducing exposure for standard deployments. Successful exploitation yields command execution under the unprivileged CSF service account (not root), providing a foothold for reconnaissance, data access, or lateral movement on internet-facing cPanel/WHM hosting infrastructure. CSF 16.30 and later fix the issue; administrators who cannot update immediately can set MESSENGER = 0 in /etc/csf/csf.conf and restart csf and lfd as a temporary mitigation. Both sources reporting on the flaw agree on the affected versions, exploitation prerequisites, and fix version.
- Vulnerability tracked as CVE-2026-65638
- Affects ConfigServer Security & Firewall (CSF) versions 14.00 through 16.29
- Allows unauthenticated remote attackers to execute arbitrary commands via the MESSENGER service
- Exploitation requires both MESSENGER enabled (a non-default setting) and a reCAPTCHA secret configured
- Command execution runs under the unprivileged CSF service account, not root by default
- Fixed in CSF 16.30 and later
- Temporary mitigation: set MESSENGER = 0 in /etc/csf/csf.conf and restart csf and lfd
- Impacts internet-facing cPanel/WHM hosting infrastructure
Coverage timelineoldest first · each row is one article
- · 15d agocPanel Urges Users to Patch ConfigServer Firewall Remote Code Execution Flaw
GBHackers· 55
cPanel urges administrators to patch CVE-2026-65638, a flaw letting unauthenticated attackers run commands through ConfigServer Firewall's MESSENGER service; update to CSF 16.30.
- · 15d agocPanel ConfigServer Security & Firewall Vulnerability Allows Remote Attacker to Execute Arbitrary Commands
Cyber Security News· 55
CSF 14.00–16.29 (CVE-2026-65638) lets unauthenticated attackers execute arbitrary commands via the MESSENGER service on cPanel/WHM servers; version 16.30 fixes it.
Vulnerabilities in this storyAll →
- CVE-2026-656389.2—Unauthenticated shell command injection in ConfigServer Security & Firewall (CSF)published · ConfigServer Security & Firewall (CSF)
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-65638 | Unauthenticated shell command injection in ConfigServer Security & Firewall (CSF) CVE-2026-65638 is an unauthenticated shell command injection flaw (CWE-78) in ConfigServer Security & Firewall (CSF), caused by improper escaping of a request URL. An attacker who sends a crafted request URL containing shell metacharacters to the affected web-facing component can have arbitrary commands executed under the CSF service account. Successful exploitation therefore yields command execution on the server in the context of the CSF service account, with a critical CVSS 4.0 score of 9.2 reflecting high confidentiality, integrity, and availability impact on the vulnerable system. The flaw affects versions originally distributed by ConfigServer as well as versions of the WebPros-maintained fork that contain the vulnerable code; WebPros has fixed it in version 16.30, and other independently maintained CSF forks should be evaluated separately. There is no public proof of concept, the issue is not in CISA's Known Exploited Vulnerabilities catalog, and no exploitation has been reported to date. |