CSF Security Advisory Critical Vulnerability Patch

CSF Security Advisory September 2026: Critical Vulnerability and Patch Guide

Simplify Article With:
Share Article With: Link copied

A critical security vulnerability, CVE-2026-67402, has recently been identified in ConfigServer Firewall (CSF) and may pose a security risk to the servers. To address this vulnerability, cPanel advised updating CSF to the latest secure version.

ConfigServer Firewall vulnerabilities were found on CVE-2026-67402, and cPanel released a patch  MESSENGER service in the ConfigServer Firewall (CSF) software, which could allow for unauthorized code execution

CSF(ConfigServer Firewall) has officially been discontinued on August 31, 2025. It has ended all support and distribution. They released the software as open-source under the GPLv3 license.

On February 25, 2026, cPanel launched its own Fork of CSF and is maintaining security patches and stability for users.

If your CSF has auto-updates enabled, then cPanel should have applied the configuration change on your server at the time of the update.

On 06 August 2026, cPanel addressed multiple vulnerabilities in CSF version 16.20-1 and earlier. The impact of these vulnerabilities is it could allow an attacker to gain root access to the server. They provided a patch in version 16.30-1.

Shortly after, on 03 September 2026, cPanel released another patch and remediation steps for CSF vulnerabilities that have Critical severity.

CVE-2026-67402 –  Patch Information

An insecure Apache configuration in ConfigServer Security & Firewall maps /usr/bin as CGI programs through the Messenger v3 HTTPS virtual host. A remote unauthenticated attacker whose address is blocked can request a mapped executable and run arbitrary commands as the Apache user. The vulnerability affects installations where CSF Messenger v3 and its HTTPS mode are enabled. WebPros addressed the vulnerability in version 16.31.

This has a public CVE record listed with further information: CVE-2026-67402.

Impact: Exploiting this could allow an attacker to execute code as the Apache user.

Affected Versions: Servers with ConfigServer Firewall (CSF) installed running cpanel-csf 16.30-1 or older are affected. Servers without CSF installed are not affected.

Patched Versions: ConfigServer Firewall (CSF) 16.31 or later

Action needs to be taken

Servers configured for automatic updates will receive the patched build automatically.

To check your server’s cPanel CSF fork version, run the following command,

#csf -v

CSF version
If your version is 16.30-1 or older than this, you should update CSF immediately.

To manually update  the patch, log in to your server using root access and run the following command,

On CentOS 7/CloudLinux 7 Servers

#yum clean all
#/scripts/update-packages

On AlmaLinux/CloudLinux 8/9/10 Servers

#dnf clean all
#/scripts/update-packages

On Ubuntu Servers

#apt update
#/scripts/update-packages

If your server is running an end-of-life version of cPanel & WHM, upgrade to a supported version to continue receiving CSF updates.

For more information, please check the cPanel CSF Security Release – September 3rd, 2026.

 

More Security Information:

1. Data Encryption and How Does It Work?

2. Where Does a Proxy Firewall Filter At?

3. How to Enable Leech Protection in cPanel