Panel patched CVE-2026-67401, which lets a hosting account with mail privileges create files anywhere and run code as root.
A critical vulnerability affecting all but the latest versions of cPanel and the WebHost Manager (WHM) dashboard could be exploited to obtain access to the control panel without authentication. The ...