Security NEXT•October 5, 2026•🇯🇵Translated from Japanese

WebPros Releases Critical Patches for Three Vulnerabilities in cPanel & WHM

WebPros International has released security updates that remediate three Critical vulnerabilities in the cPanel & WHM hosting management platform.

The company disclosed the fixes on September 29, 2026, addressing the identifiers CVE-2026-93698, CVE-2026-93697, and CVE-2026-93029. All three issues were rated Critical under the four-tier severity scale.

CVE-2026-93698 – Remote Command Execution via Multilang adminbin

CVE-2026-93698 is an input validation flaw in the Multilang adminbin component. An attacker with a low-privileged account can supply crafted input that results in arbitrary operating system commands being executed with root privileges. Successful exploitation could grant full control over managed accounts, websites, and databases. The vulnerability received a CVSS v3.0 base score of 9.9.

Stored XSS Vulnerabilities in WHM Interfaces

The remaining two issues are stored cross-site scripting (XSS) flaws. CVE-2026-93697 resides in the WHM Mass Modify Accounts interface. A user without administrative rights can store malicious scripts that later execute within an authenticated WHM administrator session, enabling actions to be performed with full administrative privileges.

The third identifier, CVE-2026-93029, is also classified as a stored XSS vulnerability, though fewer technical details were provided in the initial advisory.

Administrators are strongly encouraged to apply the September 29, 2026 security release immediately to eliminate the risk of remote code execution and session hijacking.

Related articles

Security NEXT•Vulnerabilities & Exploits

Critical Sandbox Bypass Flaw in GitLab AI Gateway Enables Remote Command Execution

GitLab has released patches for a critical vulnerability in its GitLab AI Gateway component that allows authenticated users to bypass sandbox restrictions and execute arbitrary commands. The flaw, tracked as CVE-2026-90970, resides in the custom flow prompt template processing of the Duo Agent Platform and carries a CVSS v3.1 base score of 9.9. Self-hosted deployments are affected, while GitLab’s own hosted AI Gateway service has already been updated. The company urges immediate upgrades to versions 19.4.1, 19.3.2, or 19.2.4. The vulnerability can be triggered under specific conditions by users with access to the Duo Agent Platform through crafted flow configurations.

Security NEXT•Vulnerabilities & Exploits

Top Cybersecurity Stories: SharePoint Exploits Warned by US Authorities, Citrix and WordPress Flaws Lead Weekly Rankings

Security NEXT has published its weekly ranking of the most viewed articles from September 27 to October 3, 2026, highlighting critical vulnerability disclosures and confirmed exploitation cases. US authorities issued warnings about active exploitation of five vulnerabilities affecting SharePoint and WordPress. Citrix NetScaler received multiple vulnerability advisories with two flaws already confirmed as exploited in the wild. Apple released iOS 26.7.1 to address vulnerabilities potentially used in targeted attacks against specific individuals. Other notable incidents include a personal data breach at Times Car car-sharing service and a ransomware attack impacting Keio Electric Railway operations.

Security NEXT•Vulnerabilities & Exploits

Google Releases Chrome Update Fixing 11 Vulnerabilities Including Critical WebGL Flaw

Google has issued an update for its Chrome browser that addresses 11 security vulnerabilities across Windows, macOS, and Linux platforms. The release includes Chrome 154.0.8037.98 and 154.0.8037.97 for Windows and macOS, along with version 154.0.8037.97 for Linux. One vulnerability, CVE-2026-103628, received a Critical rating due to an out-of-bounds memory write in WebGL that was originally reported in August. Nine additional issues rated High severity affect components such as FileSystem, Compositing, Skia, FedCM, SVG, MediaStream, and WebRTC, including a buffer overflow tracked as CVE-2026-103631. The update also resolves a type confusion flaw in the V8 scripting engine and one Medium-severity issue. Google plans a gradual rollout over the coming days and weeks.

Habr•Vulnerabilities & Exploits

Browser Built on Mistakes: How Real-World Attacks Shaped Modern Browser Defenses

Browser security features such as process isolation, sandboxing, and restrictions on code execution were not designed in isolation but evolved directly in response to concrete attacks over more than a decade. Early threats like malicious Flash advertisements in 2015 demonstrated how a single compromised banner could compromise an entire system, prompting the industry to phase out plugins entirely. Later discoveries, including the Spectre vulnerability, forced browsers to implement stricter site isolation and timing-attack mitigations that remain in place today. Session hijacking and malicious browser extensions further drove the adoption of stronger cookie protections and permission models. BI.ZONE analysts trace this history through specific incidents to show why current architectures prioritize separation of sites into distinct processes. The resulting design reduces the blast radius of any single exploit and continues to adapt as new attack classes emerge.