cPanel, WHM Release Fixes for Three New Vulnerabilities — Patch Now
2026-05-09T13:24:04Z•34e416a268f8aadcccdb00dd715cfd64a568c1cffb63f442b4726f2adc8400e8
Apache-HTTP2IvantiPAN-OSactive-exploitationandroidbackdoorbanking-trojancPanelcredential-theftincident-responseiot-botnetlinux-kernelmalwarenodejsplay-storeprivilege-escalationpyPIremote-code-executionsupply-chainvulnerability
What happened
The Hacker News digest highlights multiple high-impact vulnerabilities and active-exploitation incidents alongside a wave of malware and supply-chain abuse. Notable vulnerabilities include PAN-OS CVE-2026-0300 (critical RCE under active exploitation), Apache HTTP/2 CVE-2026-23918 (double-free, DoS and potential RCE), Ivanti EPMM CVE-2026-6973 (RCE exploited in the wild), cPanel/WHM fixes including CVE-2026-29201, and an unpatched Linux local privilege escalation dubbed "Dirty Frag" (successor to CVE-2026-31431). The feed also reports on multiple malware campaigns and supply-chain compromises —
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- 34e416a268f8aadcccdb00dd715cfd64a568c1cffb63f442b4726f2adc8400e8
- Enrichment time
- 2026-05-09T13:24:04Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.