Report Incident
× Home DPO CyberHub Rw-CSIRT Website About Rw-CSIRT Alerts Advisories About NCSA Documentation News & Events Topics Contact us Opportunities Privacy Policy

Security Alert: Critical cPanel & WHM Vulnerability – CVE-2026-67401

A critical SQL injection vulnerability has been discovered in cPanel & WHM’s EmailTrack functionality. The vulnerability, identified as CVE-2026-67401, could be exploited by an attacker with valid cPanel credentials and mail‑related privileges to gain full control of the affected server.
 
Affected Systems:
 
  • cPanel and WHM: All supported versions prior to v11.110.0.143, v11.134.0.55, v11.136.0.39, v11.138.0.4
  • WP Squared (WP2): All supported versions prior to v11.138.1.9
 
Security Risks
 
Successful exploitation could allow an attacker with an authenticated cPanel account and mail‑related privileges to execute code with root‑level access, which may lead to complete server compromise and exposure of all hosted accounts, websites, and databases.
 
For more information on this vulnerability and related updates, please refer to official cPanel security advisory for CVE-2026-67401.
 
Recommended Actions
 
The National Cyber Security Authority (NCSA) recommends users and system administrators:
 
1. Upgrade cPanel and WHM to the latest supported versions to ensure continued access to security patches and technical support.
 
The recommended versions are:
 
  • cPanel and WHM: Upgrade to version v11.110.0.143 or above, v11.134.0.55 or above, v11.136.0.39 or above, v11.138.0.4 or above.
  • WP Squared (WP2): Upgrade to version 11.138.1.9 or above.
 
2. Review and restrict permissions for cPanel accounts that can add additional domain names, ensuring that access is granted only to authorized users.
 
3. Verify that the installed cPanel & WHM version meets one of the fixed versions specified by cPanel.
 
4. Ensure valid backups are available before applying updates.
 
For further information and support, please contact the National Cyber Security Authority (NCSA) by emailto rwcsirt@ncsa.gov.rw or call us on 9009.
 
References

10 September 2026

© 2026 National Cyber Security Authority