CVE-2026-67401: WebPros cPanel

Critical severity, CVSS 9.9. EPSS: 0.9% chance of exploitation in the next 30 days.

A vulnerability in cPanel allows a mail-enabled account to achieve remote code execution as root through SQLi in EmailTrack component

Affected products

  • WebPros cPanel: before 11.134.0.55 (fixed in 11.134.0.55); before 11.136.0.39 (fixed in 11.136.0.39); before 11.138.0.4 (fixed in 11.138.0.4); before 11.138.1.9 (fixed in 11.138.1.9); before 11.110.0.143 (fixed in 11.110.0.143)

Published 2026-09-09. Last modified 2026-09-10.