A critical security vulnerability affecting ConfigServer Firewall (CSF) has been identified. A patched version is now available.
Vulnerability in CSF's Messenger service - CVE-2026-67402
Situation:
An unauthenticated attacker can exploit CSF's Messenger service to execute code on the server.
Impact:
Exploitation can lead to increased access, allowing an attacker to execute code as the Apache user.
Affected Versions:
ConfigServer Firewall (CSF) versions 16.30-1 and older
Patched Versions:
ConfigServer Firewall (CSF) 16.31 or later
Support Link: Security: CSF Security Release - September 3rd, 2026 – cPanel
Action Required > Update CSF now
Servers configured for automatic updates will receive the patched build automatically. To apply it immediately, log in to the server as root and run:
# yum clean all
# /scripts/update-packages
If your server is running an end-of-life version of cPanel & WHM, upgrade to a supported version to continue receiving CSF updates.
Please reach out to your account manager or our support team if you have any questions or need further guidance.
Best regards,
Your cPanel Security Team
Vulnerability in CSF's Messenger service - CVE-2026-67402
Situation:
An unauthenticated attacker can exploit CSF's Messenger service to execute code on the server.
Impact:
Exploitation can lead to increased access, allowing an attacker to execute code as the Apache user.
Affected Versions:
ConfigServer Firewall (CSF) versions 16.30-1 and older
Patched Versions:
ConfigServer Firewall (CSF) 16.31 or later
Support Link: Security: CSF Security Release - September 3rd, 2026 – cPanel
Action Required > Update CSF now
Servers configured for automatic updates will receive the patched build automatically. To apply it immediately, log in to the server as root and run:
# yum clean all
# /scripts/update-packages
If your server is running an end-of-life version of cPanel & WHM, upgrade to a supported version to continue receiving CSF updates.
Please reach out to your account manager or our support team if you have any questions or need further guidance.
Best regards,
Your cPanel Security Team