cPanel, WHM Release Fixes for Three New Vulnerabilities — Patch Now

2026-05-09T19:24:06Zabfc00b27ea0a6016011c2c8e1e27669d6ae01cc9d5ad0fb0bb1acf369b4ceab
active-exploitationandroidbanking-trojanbotnetcloud-infrastructurecredential-theftlinuxlocal-privilege-escalationmalwarepam-backdoorplay-store-fraudransomwareremote-code-executionsupply-chainvulnerabilitiesworm

What happened

A batch of security news from The Hacker News covering multiple high-impact vulnerabilities, active exploits, and malware campaigns. Notable vulnerability disclosures and active exploits include PAN-OS RCE (CVE-2026-0300, CVSS 9.3), Apache HTTP/2 double-free/RCE (CVE-2026-23918, CVSS 8.8), Ivanti EPMM RCE (CVE-2026-6973, CVSS 7.2), a new cPanel/WHM input-validation issue (CVE-2026-29201), and mention of the Linux "Dirty Frag" LPE (successor to CVE-2026-31431). Malware and attacker activity includes TCLBANKER banking trojan (REF3076), Quasar Linux RAT (QLNX), PamDOORa PAM-based backdoor, PCPJak

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
abfc00b27ea0a6016011c2c8e1e27669d6ae01cc9d5ad0fb0bb1acf369b4ceab
Enrichment time
2026-05-09T19:24:06Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.