CVE-2026-93698: WebPros cPanel

Critical severity, CVSS 9.9. EPSS: 0.6% chance of exploitation in the next 30 days.

Insufficient validation allows arbitrary commands to be executed via the Multilang adminbin.

Affected products

  • WebPros cPanel: before 11.138.0.11 (fixed in 11.138.0.11); before 11.136.0.45 (fixed in 11.136.0.45); before 11.134.0.61 (fixed in 11.134.0.61); before 11.110.0.148 (fixed in 11.110.0.148)
  • WebPros Wp Squared: before 11.138.1.13 (fixed in 11.138.1.13)

Published 2026-10-02. Last modified 2026-10-02.