CVE-2026-65643High· 8.8▾ MidnightPoC availableEval injection in cPanel 11.138.0.0 and earlier allows remote authenticated users to execute arbitrary code as root.
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 48.4 · likelihood 0.2 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 1 source. Availability, not in-the-wild use.
Exploit-prediction probability, daily snapshots since Sep 5.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.8%
0.8% → 0.9%
2 GitHub repos
Last analysed / modified upstream
Eval injection in cPanel 11.138.0.0 and earlier allows remote authenticated users to execute arbitrary code as root.
cpanel < 110.0.141cpanel >= 112.0.0, < 134.0.53cpanel >= 136.0.0, < 136.0.37cpanel >= 138.0.0, < 138.0.2cpanel >= 138.1.0, < 138.1.7Upgrade past the affected range:
cpanel 138.1.7Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-67401Critical· 9.9A vulnerability in cPanel allows a mail-enabled account to achieve remote code execution as root through SQLi in EmailTrack component
CVE-2026-48962High· 7.3IO::Compress versions before 2.220 for Perl can execute arbitrary code in File::GlobMapper via an attacker-controlled output glob. _parseOutputGlob() wraps the caller-supplied output glob string in double quotes and stores it in the par…
CVE-2026-47103Critical· 9.8python-statemachine SCXML <data expr> Eval Injection
CVE-2026-76974Medium· 5.3SAP Fiori Launchpad does not sufficiently validate certain user-controlled input
CVE-2026-72904NoneFirecrawl turns entire websites into LLM-ready markdown or structured data
CVE-2025-53837Critical· 9.9XWiki Rendering is a generic rendering system that converts textual input in a given syntax (wiki syntax, HTML, etc) into another syntax (XHTML, etc)