cPanel, WHM Release Fixes for Three New Vulnerabilities — Patch Now
2026-05-09T19:24:06Z•abfc00b27ea0a6016011c2c8e1e27669d6ae01cc9d5ad0fb0bb1acf369b4ceab
active-exploitationandroidbanking-trojanbotnetcloud-infrastructurecredential-theftlinuxlocal-privilege-escalationmalwarepam-backdoorplay-store-fraudransomwareremote-code-executionsupply-chainvulnerabilitiesworm
What happened
A batch of security news from The Hacker News covering multiple high-impact vulnerabilities, active exploits, and malware campaigns. Notable vulnerability disclosures and active exploits include PAN-OS RCE (CVE-2026-0300, CVSS 9.3), Apache HTTP/2 double-free/RCE (CVE-2026-23918, CVSS 8.8), Ivanti EPMM RCE (CVE-2026-6973, CVSS 7.2), a new cPanel/WHM input-validation issue (CVE-2026-29201), and mention of the Linux "Dirty Frag" LPE (successor to CVE-2026-31431). Malware and attacker activity includes TCLBANKER banking trojan (REF3076), Quasar Linux RAT (QLNX), PamDOORa PAM-based backdoor, PCPJak
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- abfc00b27ea0a6016011c2c8e1e27669d6ae01cc9d5ad0fb0bb1acf369b4ceab
- Enrichment time
- 2026-05-09T19:24:06Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.