CVE-2026-32992: cPanel
High severity, CVSS 8.2. EPSS: 0.3% chance of exploitation in the next 30 days.
SSL verification is disabled in the DNS Cluster system. This could allow for a malicious server to man-in-the-middle the request and capture credentials.
Affected products
- cPanel cPanel: from 126.0.0, before 126.0.59 (fixed in 126.0.59); from 130.0.0, before 130.0.23 (fixed in 130.0.23); from 132.0.0, before 132.0.32 (fixed in 132.0.32); from 134.0.0, before 134.0.26 (fixed in 134.0.26); from 136.0.0, before 136.0.10 (fixed in 136.0.10)
- cPanel WHM: from 126.0.0, before 126.0.59 (fixed in 126.0.59); from 130.0.0, before 130.0.23 (fixed in 130.0.23); from 132.0.0, before 132.0.32 (fixed in 132.0.32); from 134.0.0, before 134.0.26 (fixed in 134.0.26); from 136.0.0, before 136.0.10 (fixed in 136.0.10)
- cPanel Wp Squared: from 126.1.0, before 136.1.12 (fixed in 136.1.12)
Published 2026-05-13. Last modified 2026-08-12.