WebPros security advisory (AV26-908)

Canadian Centre for Cyber Security Version 1 original current

Imported from official source

Serial number: AV26-908Date: September 10, 2026 As of September 10, 2026, WebPros is affected by vulnerabilities in the following products: cPanel & WebHost Manager (WHM) software Prior to 11.110.0.143 Prior to 11.134.0.55 Prior to 11.136.0.39 Prior to 11.138.0.4 Prior to WP2: 11.138.1.9 ConfigServer Security & Firewall (CSF) software Versions 14.00 to 16.29 (CVE-2026-65638) Versions 2.15 to 16.29 (CVE-2026-65639) The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. Security: CVE-2026-67401 SQL Injection Vulnerability in cPanel's EmailTrack Functionality - September 8, 2026 Security: CVE-2026-65638 CSF Security Release Security: CVE-2026-65639 CSF Security Release cPanel Security

This version

Version
1 of 1
Recorded
September 20, 2026 19:55
Change
Initial
Content hash
ed8eedbdc7bbba1ea844afee410bcb8f
All versions
Revision history

Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.