LowEndBox - Cheap VPS, Hosting and Dedicated Server Deals

Achtung! Critical cPanel Vulnerability: Take Action Now!

TcPanel Logohe world’s most popular (and expensive) web hosting panel is apparently vulnerable to anyone who decides to connect to your port 2087.

cPanel published a critical vulnerability on April 28th.

A security issue has been identified in the cPanel software affecting all currently supported versions relating to various authentication paths.

Disappointingly, that vulnerability alert used to have a lot more info.  Now it just says “update”.  Previously, it recommended blocking these ports if you can’t immediately update:

  • 2083/2087 – SSL connections
  • 2082/2086 – Non-SSL connections
  • 2095/2096 – Webmail
  • If webdisk is enabled, include 2077/2078

There’s no details on what the actual vulnerability, or any info in the cPanel forums’ security section.

But anyway…firewall those ports or upgrade!

No Comments

    Leave a Reply

    Some notes on commenting on LowEndBox:

    • Do not use LowEndBox for support issues. Go to your hosting provider and issue a ticket there. Coming here saying "my VPS is down, what do I do?!" will only have your comments removed.
    • Akismet is used for spam detection. Some comments may be held temporarily for manual approval.
    • Use <pre>...</pre> to quote the output from your terminal/console, or consider using a pastebin service.

    Your email address will not be published. Required fields are marked *