๐Ÿ” CVE Alert

CVE-2026-67402

UNKNOWN 0.0
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

An insecure Apache configuration in ConfigServer Security & Firewall maps /usr/bin as CGI programs through the Messenger v3 HTTPS virtual host. A remote unauthenticated attacker whose address is blocked can request a mapped executable and run arbitrary commands as the Apache user. The vulnerability affects installations where CSF Messenger v3 and its HTTPS mode are enabled. WebPros addressed the vulnerability in version 16.31.

CWE CWE-552
Vendor webpros
Product configserver security & firewall
Published Sep 3, 2026
Stay Ahead of the Next One

Get instant alerts for webpros configserver security & firewall

Be the first to know when new unknown vulnerabilities affecting webpros configserver security & firewall are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

WebPros / ConfigServer Security & Firewall
14.02 < 16.31
ConfigServer / ConfigServer Security & Firewall
14.02 < *

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
support.cpanel.net: https://support.cpanel.net/hc/en-us/articles/43171958716439-Security-CSF-Security-Release-September-3rd-2026