Threat reportVulnerabilityTL-2026-2912

Multiple cPanel & WHM Vulnerabilities (CVE-2026-93698, CVE-2026-93029, CVE-2026-93697) Enable Root Code Execution and Admin Session Hijacking

criticalPATCHED

Multiple cPanel & WHM Vulnerabilities (CVE-2026-93698 (TL-2026-2912) is a critical-severity software vulnerability scored CVSS 9.9, first published 2026-10-04. It has no confirmed attribution, affects cPanel cPanel & WHM, references 3 CVEs (CVE-2026-93698, CVE-2026-93029, CVE-2026-93697), maps to 5 MITRE ATT&CK techniques (T1059.004, T1059.007, T1078), and is covered by 9 detection rules and 10 indicators of compromise.

CVSS
9.9/10Critical
CVEs
3Referenced vulnerabilities
Techniques
5MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
10Indicators of compromise

Key facts for TL-2026-2912

Threat ID
TL-2026-2912
Severity
CRITICAL
CVSS
9.9 (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H)
Status
PATCHED
Category
VULNERABILITY
First published
Last reviewed
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
web hosting, technology, small and medium business, government administration
Target regions
Global
Detection rules
9
Indicators of compromise
10

How Multiple cPanel & WHM Vulnerabilities (CVE-2026-93698 works

cPanel patched three vulnerabilities in cPanel & WHM on 2026-09-29: CVE-2026-93698, an OS command injection in the Multilang adminbin that permits code execution as root (CVSS 9.9), and two stored XSS flaws in WHM's Manage SSL Hosts (CVE-2026-93029) and Mass Modify Accounts (CVE-2026-93697) interfaces that allow script execution in administrator sessions. No in-the-wild exploitation or public PoC is reported.

On 2026-09-29 cPanel published three security advisories and fixed builds for cPanel & WHM and WP Squared. The fixes ship in cPanel & WHM 11.110.0.148, 11.134.0.61, 11.136.0.45 and 11.138.0.11, and in WP Squared 11.138.1.13. All supported versions before those builds are affected. NVD published the CVE records on 2026-10-02.

CVE-2026-93698 is an insufficient-validation flaw (CWE-78) in the Multilang adminbin, the privileged helper through which cPanel account-level callers reach root-run functionality. Per the NVD record it allows arbitrary commands to be executed via that adminbin. The CVSS 3.0 vector is AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H (9.9): it is network-reachable, needs only low privileges (an authenticated cPanel account) and no user interaction, and scope changes. Trade press describes the impact as code execution as root, the highest-privileged account on the Linux server, so a low-privileged hosted account could take over the whole host and every other tenant on it. The same component had earlier root-execution and feature-list-bypass issues (CVE-2017-18434 via SET_VHOST_LANG_PACKAGE, CVE-2016-10772), so it is a recurring hardening target.

CVE-2026-93029 (WHM Manage SSL Hosts interface) and CVE-2026-93697 (WHM Mass Modify Accounts / account modification interfaces) are stored cross-site scripting flaws (CWE-79). An unprivileged or low-privileged user can store script that runs when an administrator views the page, so the attacker can perform any administrative action available to that administrator, including session hijacking. NVD scores both 9.0 (CVSS 3.0 AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H); the vendor and press describe them as moderate, so scoring differs between sources.

The source reports no evidence of active exploitation, no public PoC, no IOCs and no named threat actor. Context for prioritization: cPanel was heavily targeted earlier in 2026. CVE-2026-41940, an authentication bypass, was reported exploited as a zero-day, with Mirai and the Sorry ransomware deployed. Three further cPanel flaws (CVE-2026-29201, CVE-2026-29202, CVE-2026-29203) were patched in May 2026 with no exploitation reported. This is unrelated to the present flaws but shows attacker interest in the platform. Defenders should treat this as a patch-priority advisory for all internet-exposed WHM/cPanel hosts and shared-hosting providers.

MITRE ATT&CK techniques used in TL-2026-2912

Execution

T1059.004 Command and Scripting Interpreter: Unix Shell; T1059.007 Command and Scripting Interpreter: JavaScript

Initial Access

T1078 Valid Accounts; T1190 Exploit Public-Facing Application

Credential Access

T1539 Steal Web Session Cookie

Affected products and versions in Multiple cPanel & WHM Vulnerabilities (CVE-2026-93698

  • cPanel — cPanel & WHM
    Vulnerable versions: All supported versions before 11.110.0.148, 11.134.0.61, 11.136.0.45 and 11.138.0.11
    Fixed in: 11.110.0.148; 11.134.0.61; 11.136.0.45; 11.138.0.11
  • cPanel — WP Squared
    Vulnerable versions: Versions before 11.138.1.13
    Fixed in: 11.138.1.13

Remediation for Multiple cPanel & WHM Vulnerabilities (CVE-2026-93698

Patches

  • cPanel & WHM 11.110.0.148
  • cPanel & WHM 11.134.0.61
  • cPanel & WHM 11.136.0.45
  • cPanel & WHM 11.138.0.11
  • WP Squared 11.138.1.13

Immediate actions

  • Update cPanel & WHM to 11.110.0.148, 11.134.0.61, 11.136.0.45, 11.138.0.11 or later (WP Squared 11.138.1.13 or later)
  • Review WHM access logs and privileged session activity
  • Review recently stored values in Manage SSL Hosts and account modification fields for script content

Longer-term hardening

  • Restrict WHM administrative access to trusted IP addresses
  • Enforce multi-factor authentication for WHM administrators
  • Minimize the number of privileged WHM user accounts

CVEs associated with Multiple cPanel & WHM Vulnerabilities (CVE-2026-93698

CVE-2026-93698, CVE-2026-93029, CVE-2026-93697

Weaknesses (CWE) in Multiple cPanel & WHM Vulnerabilities (CVE-2026-93698

CWE-78, CWE-79

Timeline of Multiple cPanel & WHM Vulnerabilities (CVE-2026-93698

  • Earlier, unrelated cPanel flaw CVE-2026-41940 (auth bypass) is reported exploited in the wild since at least this date, showing attacker interest in the platform
  • cPanel patches three earlier flaws (CVE-2026-29201, CVE-2026-29202, CVE-2026-29203) with no exploitation reported; press coverage of CVE-2026-41940 exploitation (Mirai, Sorry ransomware) in the same period
  • cPanel publishes advisories and releases fixed builds 11.110.0.148, 11.134.0.61, 11.136.0.45, 11.138.0.11 and WP Squared 11.138.1.13 for CVE-2026-93698, CVE-2026-93029 and CVE-2026-93697
  • GBHackers reports the three flaws, with no evidence of active exploitation, no IOCs and no named threat actor
  • NVD record for CVE-2026-93698 links the cPanel changelogs for the 110, 134, 136 and 138 tiers, the WP Squared changelog and HackerOne report 4054291; records show Last Modified equal to Published (2026-10-02)
  • NVD publishes CVE-2026-93698 (CVSS 9.9, CWE-78) and the two stored XSS CVEs (CVSS 9.0, CWE-79)
  • Platform review of all cited sources finds no exploitation reports, public PoC, IOCs or attribution for the three CVEs; recommended mitigations remain: patch, restrict WHM admin access by IP, enforce MFA, reduce privileged WHM users, review WHM access logs

Sources cited for Multiple cPanel & WHM Vulnerabilities (CVE-2026-93698

Detection coverage for TL-2026-2912

As of 2026-10-04, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2912 across Splunk SPL, Microsoft KQL and Sigma, covering 10 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
10 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats