New cPanel Flaw Lets a Hosting Account With Mail Privileges Run Code as Root

cPanel has patched a flaw that it says lets a single hosting account take control of an entire server. An authenticated account holder with mail-related privileges can create files of their choosing on the server through EmailTrack and,…
Sourcing & attribution. Newseze provides AI-curated summaries, narrative framing, and editorial analysis. The underlying reporting was contributed by The Hacker News; tap “Open original source” above to read their full reporting and support the contributing newsroom directly.
Newseze's algorithm reads the story and answers your question — calmly, factually, with source attribution. No comments, no flame wars — just answers.
No questions yet. Be the first.
Answers reflect Newseze's editorial framework applied under fair use (17 U.S.C. § 107). Not financial, legal, medical, or tax advice. Hate speech and racial slurs are blocked.
Related stories

Why it mattersGoogle on Thursday released updates to patch 230 security vulnerabilities, including one that has come under active exploitation in the wild. The medium-severity vulnerability, assigned the CVE identifier CVE-2026-87491 …
Google on Thursday released updates to patch 230 security vulnerabilities, including one that has come under active exploitation in the wild. The medium-severit…

Why it mattersAttackers are actively exploiting two of the vulnerabilities and another 58 are more likely to be exploited, according to Microsoft.
Why it mattersThe scale of fixes underscores ongoing security demands on enterprise infrastructure, while zero-day disclosures signal persistent threats to unpatched systems across Windows and related products.
Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-days bleepingcomputer.com
Why it mattersThe guilty plea closes a major 2024 cybercrime case affecting hundreds of organizations and tens of millions of customers, while establishing accountability for one of the year's most damaging threat actors—signaling law…
A 26-year-old Canadian man once described as one of the most consequential cybercrime threat actors of 2024 has pleaded guilty to computer fraud and conspiracy …