1
Information / Re: The impact of AI tools and our commitment to CWP
« Last post by Jamshed Datori on Today at 03:38:42 PM »Dear Community:
We would like to share an open update regarding the current security landscape we are managing.
Over the past few months, the hosting and control panel ecosystem has seen a dramatic rise in vulnerability reports and automated scanning activity. With the proliferation of AI-driven tools, cybersecurity firms, independent researchers, and malicious actors alike are leveraging AI to conduct massive audits and identify attack vectors at unprecedented speeds. This situation is not unique to CWP; it affects the entire industry.
In light of this new landscape, we want to reassure you about our ongoing efforts:
Rapid response and mitigation: We analyze every report we receive—whether from security firms or the community—and deploy patches as quickly as possible.
Continuous core development: The CWP development team works daily to reinforce the code and adapt our defenses to neutralize these modern, AI-powered automated scanning methods.
Gratitude to the community: Your role is vital. We want to thank all the users and administrators who remain vigilant and actively collaborate with us.
We remind you of the importance of keeping your servers and services updated to the latest available version. If you detect any anomalous behavior, bugs, or potential security flaws, please notify us immediately through official channels so we can assess the issue with the highest priority.
Thank you for your continued support and trust as we work to strengthen the platform every day.
Hello Jose. Can you please respond to my Ticket #637019? This has been pending since Feb 25, 2026, and you people don't bother to respond.
2
Backup / Re: Backup Manager Beta is not remembering password in destination
« Last post by Martins-phpbb on Today at 02:21:44 PM »It should be encrypted.
It looks like it's now fixed in 1.13 (tested twice and seems to be holding so far)
It looks like it's now fixed in 1.13 (tested twice and seems to be holding so far)
3
CSF Firewall / Re: Critical Vulnerability in CSF MESSENGER (CVE-2026-67402)-03/Sep/2026
« Last post by overseer on Today at 11:52:49 AM »Another very helpful post! Thanks much!
4
Backup / Re: Backup Manager Beta is not remembering password in destination
« Last post by xenios on Today at 11:40:31 AM »Anyone knows where destination pass is stored?
5
CSF Firewall / Re: Critical Vulnerability in CSF MESSENGER (CVE-2026-67402)-03/Sep/2026
« Last post by 6Sense on Today at 11:11:02 AM »Cheers mate
6
CSF Firewall / Critical Vulnerability in CSF MESSENGER (CVE-2026-67402)-03/Sep/2026
« Last post by Netino on Today at 04:59:10 AM »Check: <https://nvd.nist.gov/vuln/detail/CVE-2026-67402>
A critical vulnerability was found in the MESSENGER service in the ConfigServer Firewall (CSF) software which could allow for unauthorized code execution.
An insecure Apache configuration in ConfigServer Security & Firewall maps /usr/bin as CGI programs through the Messenger v3 HTTPS virtual host. A remote unauthenticated attacker whose address is blocked can request a mapped executable and run arbitrary commands as the Apache user. The vulnerability affects installations where CSF Messenger v3 and its HTTPS mode are enabled. WebPros (Cpanel team) addressed the vulnerability in version 16.31.
This has a public CVE record listed with further information: CVE-2026-67402
Note: By default, the MESSENGER service is disabled.
Affected Product versions:
Product: csf
Affected Versions: CSF 16.30-1 and older
Patched Versions: 16.31+
Impact:
Exploiting this could allow an attacker to execute code as the Apache user.
Mitigation:
It is highly recommended that you update the installed CSF version as soon as possible.
If this is not possible, you can disable the MESSENGERV3 setting in CSF.
Access the server as the root user via SSH, or the Terminal in WHM.
Edit the CSF configuration file:
Update the MESSENGERV3 option to be disabled:
Save and restart the CSF and LFD services:
Version from Aetherinox was not updated yet. Is recommmended you use mitigation above.
Do it as soon as possible, my self server already was attacked.
Regards,
Netino
A critical vulnerability was found in the MESSENGER service in the ConfigServer Firewall (CSF) software which could allow for unauthorized code execution.
An insecure Apache configuration in ConfigServer Security & Firewall maps /usr/bin as CGI programs through the Messenger v3 HTTPS virtual host. A remote unauthenticated attacker whose address is blocked can request a mapped executable and run arbitrary commands as the Apache user. The vulnerability affects installations where CSF Messenger v3 and its HTTPS mode are enabled. WebPros (Cpanel team) addressed the vulnerability in version 16.31.
This has a public CVE record listed with further information: CVE-2026-67402
Note: By default, the MESSENGER service is disabled.
Affected Product versions:
Product: csf
Affected Versions: CSF 16.30-1 and older
Patched Versions: 16.31+
Impact:
Exploiting this could allow an attacker to execute code as the Apache user.
Mitigation:
It is highly recommended that you update the installed CSF version as soon as possible.
If this is not possible, you can disable the MESSENGERV3 setting in CSF.
Access the server as the root user via SSH, or the Terminal in WHM.
Edit the CSF configuration file:
Code: [Select]
# nano /etc/csf/csf.confUpdate the MESSENGERV3 option to be disabled:
Code: [Select]
MESSENGERV3 = 0Save and restart the CSF and LFD services:
Code: [Select]
# csf -raVersion from Aetherinox was not updated yet. Is recommmended you use mitigation above.
Do it as soon as possible, my self server already was attacked.
Regards,
Netino
7
CentOS-WebPanel Bugs / Re: OWASP Modsecurity rules showing warnings and does not block anithing
« Last post by Starburst on Today at 01:25:59 AM »Hi Starburst
The panel just update rules automatically.
Happens to m, now, the OWASPrules are updated and file become .conf.example again and stop working.
I have to rename again!
Actually, No, it doesn't updated automatically. Even thought that's what it says in the panel.
8
CentOS-WebPanel Bugs / Re: OWASP Modsecurity rules showing warnings and does not block anithing
« Last post by overseer on September 12, 2026, 10:34:53 PM »He's making a subtle suggestion to switch to the latest OWASP CRS:
https://starburst.help/control-web-panel-cwp/modsecurity-running-with-control-web-panel/update-owasp-crs-ruleset-to-4-27-0-running-cwp-and-apache-on-almalinux-9/
https://starburst.help/control-web-panel-cwp/modsecurity-running-with-control-web-panel/update-modsecurity-to-2-9-14-running-cwp-and-apache-on-almalinux-8-9/
Then you don't have to keep looking over your shoulder (but do keep updating the rulesets from time to time).
https://starburst.help/control-web-panel-cwp/modsecurity-running-with-control-web-panel/update-owasp-crs-ruleset-to-4-27-0-running-cwp-and-apache-on-almalinux-9/
https://starburst.help/control-web-panel-cwp/modsecurity-running-with-control-web-panel/update-modsecurity-to-2-9-14-running-cwp-and-apache-on-almalinux-8-9/
Then you don't have to keep looking over your shoulder (but do keep updating the rulesets from time to time).
9
CentOS-WebPanel Bugs / Re: OWASP Modsecurity rules showing warnings and does not block anithing
« Last post by adrianofnatal on September 12, 2026, 08:32:26 PM »Hi Starburst
The panel just update rules automatically.
Happens to m, now, the OWASPrules are updated and file become .conf.example again and stop working.
I have to rename again!
The panel just update rules automatically.
Happens to m, now, the OWASPrules are updated and file become .conf.example again and stop working.
I have to rename again!
10
Information / Re: The impact of AI tools and our commitment to CWP
« Last post by geodim on September 12, 2026, 07:32:44 PM »Nice to see that you still "hold the line" on the security front
Recent Posts