๐Ÿ” CVE Alert

CVE-2026-65639

UNKNOWN 0.0
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

OS command injection in the advanced-rule parser of ConfigServer Security & Firewall allows a remote attacker who controls a configured allow/deny feed to execute arbitrary commands as root, due to insufficient validation of feed-supplied rule data. The vulnerability affects versions of the software originally distributed by ConfigServer, as well as versions of the WebPros-maintained fork that contain the vulnerable code. WebPros has addressed the vulnerability in version 16.30. Other forks or independently maintained versions of ConfigServer Security & Firewall (CSF) may also be affected and should be evaluated independently.

CWE CWE-78
Vendor webpros
Product configserver security & firewall
Published Sep 10, 2026
Last Updated Sep 10, 2026
Stay Ahead of the Next One

Get instant alerts for webpros configserver security & firewall

Be the first to know when new unknown vulnerabilities affecting webpros configserver security & firewall are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

WebPros / ConfigServer Security & Firewall
2.15 < 16.30
ConfigServer / ConfigServer Security & Firewall
2.15 < *

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
support.cpanel.net: https://support.cpanel.net/hc/en-us/articles/43387923160343-Security-CVE-2026-65639-CSF-Security-Release