cPanel fixes three serious vulnerabilities in cPanel and WHM

cPanel has released security updates for three vulnerabilities in cPanel and WHM. CVE-2026-29201 can let attackers read files, CVE-2026-29202 can allow code execution, and CVE-2026-29203 can allow privilege escalation on affected systems. No active exploitation has been reported.

What this means for your organisation

cPanel and WHM often administer many customer websites on the same server, so a flaw here rarely affects just one area at a time. Most Norwegian organisations are affected indirectly, through their hosting provider, and have no way to patch themselves. In that case, the question you put to the provider is the only control you actually hold.

Berigo recommends

  • Ask your hosting or managed service provider in writing when the update was applied.
  • Patch immediately yourself if you run cPanel or WHM in house.
  • Ensure the management interfaces are not openly reachable from the internet.
  • Verify that you hold backups of websites and databases stored outside that same server.

Source

Related services

Security that is understood, governed and works.

Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.

Get in touch