cPanel, WHM Release Fixes for Three New Vulnerabilities — Patch Now

2026-05-10T01:24:05Z1d3d711590753401b879a34e187638ccaafb83a83416730c1a8c16d8835f64c4
IoTLinux backdoorPAM moduleactive exploitationbanking trojanbotnetcloud credential theftcredential theftlocal privilege escalationmalwarepatchingremote code executionsandbox escapesupply chain attackvulnerability

What happened

The collection of The Hacker News articles reports multiple high-impact vulnerabilities and active exploits alongside emerging malware and supply-chain incidents. Notable issues include a critical PAN-OS unauthenticated RCE (CVE-2026-0300) under active exploitation, Apache HTTP/2 double-free (CVE-2026-23918), Ivanti EPMM RCE (CVE-2026-6973), cPanel/WHM fixes (CVE-2026-29201), and a Linux LPE (Dirty Frag, successor to CVE-2026-31431). Additional coverage highlights critical vm2 sandbox-escape flaws, supply-chain compromises (DAEMON Tools, PyPI packages), new malware families (TCLBANKER banking‑

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
1d3d711590753401b879a34e187638ccaafb83a83416730c1a8c16d8835f64c4
Enrichment time
2026-05-10T01:24:05Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.