The Hacker News reported on September 9, 2026 that cPanel patched CVE-2026-67401, a vulnerability in cPanel's EmailTrack functionality. cPanel's own advisory, updated September 8, says an authenticated cPanel account holder with mail-related privileges can create arbitrary files on the server, and that successful exploitation can lead to code execution as the root user.
That matters because cPanel and WHM sit underneath many business websites. A company may never log in to WHM, know which release line its host runs, or control the server directly. The website may simply appear to be managed by a hosting company, web agency, freelancer, or MSP. But when the hosting control layer has a root-level issue, the risk is not limited to changing a page on one site.
The Business Risk Is Shared Infrastructure
For many small businesses, shared hosting is convenient and affordable. It also means the business is relying on the hosting provider to keep strong separation between accounts, patch the control panel quickly, and notice signs of abuse. A flaw that begins with one account holder but can reach root access turns server ownership into a practical accountability question.
The issue is not whether every business owner should become a Linux administrator. They should not. The real decision is whether to accept a broad assurance such as we are fully patched, or to ask for evidence that matches the exposure.
What Owners Should Ask
If your website, client portal, online form, ecommerce store, or marketing site depends on cPanel/WHM hosting, ask the provider or website vendor a few direct questions:
- Are our servers running one of the patched cPanel/WHM builds listed in the advisory?
- When was the update applied, and was it forced or automatic?
- Are we on shared hosting, reseller hosting, a VPS, or a dedicated server?
- Did anyone review for unexpected files, new accounts, cron jobs, database changes, or suspicious mail activity after the patch?
- If our site accepts form uploads, payments, logins, or customer records, what extra review was performed?
- Who is responsible for notifying us if the hosting provider later discovers signs of exploitation?
Patch Notes Are Not the Same as Proof
The cPanel advisory lists patched builds for supported release lines, including 11.110, 11.134, 11.136, 11.138, and WP Squared 11.138.1.9. That is useful, but a business still needs to know whether its own hosting environment actually reached a patched build and whether anything unusual happened before the update.
This is where web vendor management often gets fuzzy. The person who edits the website may not manage the server. The person who manages DNS may not manage cPanel. The host may patch WHM but not review application logs. The business owner sees one vendor relationship, but the risk may pass through several hands.
A Practical Next Step
Make a short website hosting inventory. List the host, DNS provider, web maintainer, CMS platform, whether cPanel/WHM is involved, whether the site stores or transmits customer data, and who is responsible for security updates at each layer.
Then ask for written confirmation of the current cPanel/WHM build and the date it was patched. If the site handles sensitive forms, ecommerce, patient inquiries, school information, donor records, or client portals, also ask whether the provider reviewed for suspicious files, accounts, mail activity, and database changes.
This does not require panic. It requires ownership. A hosted website is still a business system, and a root-level hosting panel issue deserves more than a shrug and a ticket closed with updated.
Sources and further reading