WebPros security advisory (AV26-908)
MediumCanadian Centre for Cyber Security · Canadian Centre for Cyber Security·
At a glance
- Severity
- Medium
- Used in attacks
- No flaws named
- Reported by
- 1 outlet
As of September 10, 2026, WebPros is affected by vulnerabilities in the following products:
- cPanel & WebHost Manager (WHM) software
- Prior to 11.110.0.143
- Prior to 11.134.0.55
- Prior to 11.136.0.39
- Prior to 11.138.0.4
- Prior to WP2: 11.138.1.9
- ConfigServer Security & Firewall (CSF) software
- Versions 14.00 to 16.29 (CVE-2026-65638)
- Versions 2.15 to 16.29 (CVE-2026-65639)
The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.
Reproduced in full under licence from Canadian Centre for Cyber Security. © Canadian Centre for Cyber Security. Written by Canadian Centre for Cyber Security.
Read at cyber.gc.ca ↗Official Source
Coverage
One outlet has carried this so far.
2026-09-10 17:38 UTC
Related stories
- Windows 11 KB5124008 update breaks domain trust for some users
BleepingComputer · 2026-09-16
- CISA decides weekly vulnerability bulletin isn't necessary anymore
The Register · 2026-09-16
- Malware bypasses browser checks to force install Chrome, Edge extensions
BleepingComputer · 2026-09-16
- Google Pixel phones pwned in zero-click attacks
The Register · 2026-09-16
- Attackers Exploit Issabel Framework Flaw Enabling Unauthenticated OS Command Execution
The Hacker News · 2026-09-16