Find notable cyber news and cases, enriched with sources, timelines, and signals.

CPanel and WHM EmailTrack SQL injection root code execution SQL injection flaw (CVE-2026-67401)

Vulnerability
First reported
Last updated
Happening score
H score 26
1 unique sources, 1 articles

Summary

Hide ▲

CVE-2026-67401 in cPanel and WHM lets an authenticated account with mail privileges abuse EmailTrack to create files and reach root code execution, putting every supported version at risk. cPanel patched the flaw on September 8 and listed fixed builds for the affected release lines. The issue is described as an SQL injection weakness, and the advisory ties it to a path that can let one hosting account take over an entire server. No public exploit code was identified in the cited checks, but unpatched systems still face full-server compromise risk.

Related Happenings

CISA orders FCEB patching for CVE-2026-9082

Public Sector Action
H score70 First: 26.05.2026 11:46 Last: 26.05.2026 11:46 Sources 1

About this happening: CISA added CVE-2026-9082 to the KEV Catalog and ordered FCEB agencies to patch Drupal by May 27, turning an actively exploited flaw into a mandatory federa...

CPanel & WHM authentication-bypass exploitation wave (CVE-2026-41940)

Exploitation Wave
H score89 First: 04.05.2026 11:25 Last: 04.05.2026 11:25 Sources 1

About this happening: CVE-2026-41940 is being exploited in a large cPanel & WHM compromise wave, with attackers using compromised GitHub repositories as distributed attack infrastructure. T...

CPanel CVE-2026-41940 mitigation guidance

Advisory/Mitigation
H score89 First: 30.04.2026 14:40 Last: 30.04.2026 14:40 Sources 1

About this happening: cPanel issued mitigation guidance for CVE-2026-41940 after fixes became available for cPanel, WHM, and WP Squared, urging customers to restart cpsrvd to reduce exposur...

CISA KEV mitigation for BeyondTrust CVE-2026-1731

Advisory/Mitigation
H score46 First: 20.02.2026 19:02 Last: 20.02.2026 19:02 Sources 1

About this happening: CISA ordered urgent KEV mitigation for CVE-2026-1731 in BeyondTrust Remote Support and Privileged Remote Access, forcing affected federal deployments to apply th...

Timeline

  1. 09.09.2026 11:19 2 articles · 3h ago

    cPanel patches EmailTrack SQL injection that can yield root code execution

    Initial Disclosure

    cPanel patched CVE-2026-67401 on September 8 after an SQL injection flaw in EmailTrack let an authenticated hosting account with mail privileges create files on the server and execute code as root. cPanel said every supported version of cPanel and WHM was affected and listed fixed builds for the 110, 134, 136 and 138 release lines, including WP Squared 11.138.1.9.

    Show sources
  2. 09.09.2026 11:19 1 articles · 3h ago

    Checks find no public exploit code for CVE-2026-67401

    Technical Analysis Update

    Searches on September 9 found no public exploit code or exploitation reports for CVE-2026-67401, and the vulnerability was absent from CISA's Known Exploited Vulnerabilities catalog. cPanel had not yet published a CVE record for the flaw at that check, and the advisory did not assign a severity score.

    Show sources