Skip to main content
Security

cPanel patches critical flaw allowing authenticated users to execute SQL as database root

cPanel patches critical flaw allowing authenticated users to execute SQL as database root Image: Primary
cPanel has patched a flaw that let an authenticated hosting customer execute SQL in the database's root context. The database bug is tracked as CVE-2026-58048 with a CVSS 4.0 score of 9.4 and affects all supported versions of cPanel & WHM, along with WP Squared. Reaching it requires a valid cPanel account and access to the MySQL/MariaDB feature. From there, the vendor says the account holder could execute arbitrary database commands with full administrative privileges.
Sources
Published by Tech & Business, a media brand covering technology and business. This story was sourced from The Hacker News and reviewed by the T&B editorial agent team.
Back to Newswire
Keep reading
Full wire
AI
AI

Moonshot AI's Kimi K3 now available on Amazon Bedrock

AWS has made Kimi K3 from Moonshot AI available on Amazon Bedrock, describing it as the first open-weight model to reach 2.8 trillion parameters. The model combines native vision capabilities with a 1-million-token context window...

AI Infrastructure
AI Infrastructure

AWS launches GPU-aware SageMaker HyperPod Inference Gateway

AWS announced general availability of the SageMaker HyperPod Inference Gateway, a Kubernetes-native routing addon that places inference requests using real-time GPU signals such as KV cache utilization, queue depth, LoRA adapter r...

Security
Security

Cisco patches max-severity ISE zero-day under active exploitation

Cisco released security updates for a maximum-severity authentication bypass in Identity Services Engine and ISE Passive Identity Connector, tracked as CVE-2026-76460, and said its Product Security Incident Response Team is aware ...

Security
Security

Cisco warns of actively exploited ISE authentication bypass

Cisco warned that CVE-2026-76460, a maximum-severity flaw in Identity Services Engine and ISE Passive Identity Connector, is being actively exploited. The reported API authentication-control weakness can let an unauthenticated rem...

Security Infrastructure
Security Infrastructure

Port of Los Angeles reports 120 million cyberattack attempts

The Port of Los Angeles foiled more than 120 million cyberattack attempts in August, according to Bloomberg. The U.S.'s busiest container port for global trade faces a persistent operational threat while navigating shifting tariff...