{"id":7063635,"date":"2026-09-22T02:59:12","date_gmt":"2026-09-22T02:59:12","guid":{"rendered":"https:\/\/peraltafinancing.com\/business\/internet-business\/weekly-cybersecurity-summary-11-september-to-17-september-2026\/"},"modified":"2026-09-22T02:59:12","modified_gmt":"2026-09-22T02:59:12","slug":"weekly-cybersecurity-summary-11-september-to-17-september-2026","status":"publish","type":"post","link":"https:\/\/fivemor.com\/?p=7063635","title":{"rendered":"Weekly Cybersecurity Summary \u2013 11 September to 17 September 2026"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div id=\"fws_6ab1eeff8ac5a\" data-column-margin=\"default\" data-midnight=\"dark\" data-bottom-percent=\"2%\" class=\"wpb_row vc_row-fluid vc_row top-level\" style=\"padding-top: 0px;padding-bottom: calc(100vw * 0.02)\">\n<div class=\"row-bg-wrap\" data-bg-animation=\"none\" data-bg-animation-delay=\"\" data-bg-overlay=\"false\">\n<div class=\"inner-wrap row-bg-layer\">\n<div class=\"row-bg viewport-desktop\"><\/div>\n<\/div>\n<\/div>\n<div class=\"row_col_wrap_12 col span_12 dark left\">\n<div class=\"vc_col-sm-12 wpb_column column_container vc_column_container col no-extra-padding inherit_tablet inherit_phone \" data-padding-pos=\"all\" data-has-bg-color=\"false\" data-bg-color=\"\" data-bg-opacity=\"1\" data-animation=\"\" data-delay=\"0\">\n<div class=\"vc_column-inner\">\n<div class=\"wpb_wrapper\">\n<div id=\"fws_6ab1eeff8d597\" data-midnight=\"\" data-column-margin=\"default\" class=\"wpb_row vc_row-fluid vc_row inner_row\">\n<div class=\"row-bg-wrap\">\n<div class=\"row-bg\"><\/div>\n<\/p><\/div>\n<div class=\"row_col_wrap_12_inner col span_12  left\">\n<div class=\"vc_col-sm-12 wpb_column column_container vc_column_container col child_column no-extra-padding inherit_tablet inherit_phone \" data-padding-pos=\"all\" data-has-bg-color=\"false\" data-bg-color=\"\" data-bg-opacity=\"1\" data-animation=\"\" data-delay=\"0\">\n<div class=\"vc_column-inner\">\n<div class=\"wpb_wrapper\">\n<div class=\"wpb_text_column wpb_content_element \">\n<div class=\"wpb_wrapper\">\n<p>The Heart Internet Team are aware of several security issues affecting web hosting infrastructure this week, and we want to help customers understand what they mean, who may be affected, and what sensible steps to take. This week we&#8217;re covering four issues: two critical command injection flaws in a firewall tool used on a large share of cPanel\/WHM servers, an account-isolation bypass in LiteSpeed Web Server Enterprise, an actively exploited backup-plugin flaw affecting cPanel\/WHM and Plesk deployments, and a newly disclosed WordPress plugin vulnerability that allows unauthenticated administrator account takeover.<\/p>\n<\/p><\/div>\n<\/div><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/div>\n<\/div><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/div>\n<\/div>\n<div id=\"fws_6ab1eeff8de93\" data-column-margin=\"default\" data-midnight=\"dark\" data-bottom-percent=\"2%\" class=\"wpb_row vc_row-fluid vc_row\" style=\"padding-top: 0px;padding-bottom: calc(100vw * 0.02)\">\n<div class=\"row-bg-wrap\" data-bg-animation=\"none\" data-bg-animation-delay=\"\" data-bg-overlay=\"false\">\n<div class=\"inner-wrap row-bg-layer\">\n<div class=\"row-bg viewport-desktop\"><\/div>\n<\/div>\n<\/div>\n<div class=\"row_col_wrap_12 col span_12 dark left\">\n<div class=\"vc_col-sm-12 wpb_column column_container vc_column_container col no-extra-padding inherit_tablet inherit_phone \" data-padding-pos=\"all\" data-has-bg-color=\"false\" data-bg-color=\"\" data-bg-opacity=\"1\" data-animation=\"\" data-delay=\"0\">\n<div class=\"vc_column-inner\">\n<div class=\"wpb_wrapper\">\n<div id=\"fws_6ab1eeff8dfa3\" data-midnight=\"\" data-column-margin=\"default\" class=\"wpb_row vc_row-fluid vc_row inner_row\">\n<div class=\"row-bg-wrap\">\n<div class=\"row-bg\"><\/div>\n<\/p><\/div>\n<div class=\"row_col_wrap_12_inner col span_12  left\">\n<div class=\"vc_col-sm-12 wpb_column column_container vc_column_container col child_column no-extra-padding inherit_tablet inherit_phone \" data-padding-pos=\"all\" data-has-bg-color=\"false\" data-bg-color=\"\" data-bg-opacity=\"1\" data-animation=\"\" data-delay=\"0\">\n<div class=\"vc_column-inner\">\n<div class=\"wpb_wrapper\">\n<div class=\"nectar-split-heading \" data-align=\"default\" data-m-align=\"inherit\" data-text-effect=\"none\" data-animation-type=\"line-reveal-by-space\" data-animation-delay=\"0\" data-animation-offset=\"\" data-m-rm-animation=\"\" data-stagger=\"\" data-custom-font-size=\"false\">\n<h3>[Critical] ConfigServer Security &amp; Firewall Remote Command Injection Flaws (CVE-2026-65638, CVE-2026-65639)<\/h3>\n<\/div>\n<div class=\"divider-wrap\" data-alignment=\"default\">\n<div style=\"margin-top: 12.5px;height: 3px;margin-bottom: 12.5px\" data-width=\"100%\" data-animate=\"\" data-animation-delay=\"\" data-color=\"default\" class=\"divider-border\"><\/div>\n<\/div>\n<div class=\"wpb_text_column wpb_content_element \">\n<div class=\"wpb_wrapper\">\n<p>ConfigServer Security &amp; Firewall, commonly known as CSF, is a firewall and intrusion detection suite used on a large proportion of cPanel and WHM servers. On 10 September 2026, researchers disclosed two separate command injection vulnerabilities in CSF. The first, CVE-2026-65638, lies in CSF&#8217;s MESSENGER service, a feature that displays a message to visitors who have been blocked by the firewall; it fails to properly escape part of the request URL before passing it to a shell command, so an unauthenticated attacker can inject and run arbitrary commands. It only applies when MESSENGER and a reCAPTCHA secret are both configured, which is not the default setup. The second, CVE-2026-65639, sits in CSF&#8217;s advanced-rule parser: if an attacker can control a configured allow or deny feed, insufficient validation of the feed data lets them run arbitrary commands as root.<\/p>\n<\/p><\/div>\n<\/div><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/div>\n<\/div>\n<div id=\"fws_6ab1eeff8e87e\" data-midnight=\"\" data-column-margin=\"default\" class=\"wpb_row vc_row-fluid vc_row inner_row\">\n<div class=\"row-bg-wrap\">\n<div class=\"row-bg\"><\/div>\n<\/p><\/div>\n<div class=\"row_col_wrap_12_inner col span_12  left\">\n<div class=\"vc_col-sm-4 wpb_column column_container vc_column_container col child_column no-extra-padding inherit_tablet inherit_phone \" data-padding-pos=\"all\" data-has-bg-color=\"false\" data-bg-color=\"\" data-bg-opacity=\"1\" data-animation=\"\" data-delay=\"0\">\n<div class=\"vc_column-inner\">\n<div class=\"wpb_wrapper\">\n<div class=\"nectar-fancy-box  \" data-style=\"color_box_hover\" data-animation=\"\" data-hover-o=\"default\" data-border-radius=\"default\" data-border=\"true\" data-box-color-opacity=\"1\" data-delay=\"\" data-alignment=\"center\" data-color=\"accent-color\">\n<div class=\"box-inner-wrap\">\n<div class=\"box-bg\"><\/div>\n<div class=\"inner\" style=\"min-height: 120px\">\n<div class=\"inner-wrap\"><i class=\"icon-default-style fa fa-exclamation-triangle\" data-color=\"accent-color\" style=\"font-size: 20px!important;line-height: 20px!important\"><\/i><\/p>\n<h4><strong>Affected: <\/strong><\/h4>\n<p>CSF versions 14.00 to 16.29 (CVE-2026-65638) and versions 2.15 to 16.29 (CVE-2026-65639), including the WebPros-maintained fork.<\/p><\/div>\n<\/div><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"vc_col-sm-4 wpb_column column_container vc_column_container col child_column no-extra-padding inherit_tablet inherit_phone \" data-padding-pos=\"all\" data-has-bg-color=\"false\" data-bg-color=\"\" data-bg-opacity=\"1\" data-animation=\"\" data-delay=\"0\">\n<div class=\"vc_column-inner\">\n<div class=\"wpb_wrapper\">\n<div class=\"nectar-fancy-box  \" data-style=\"color_box_hover\" data-animation=\"\" data-hover-o=\"default\" data-border-radius=\"default\" data-border=\"true\" data-box-color-opacity=\"1\" data-delay=\"\" data-alignment=\"center\" data-color=\"accent-color\">\n<div class=\"box-inner-wrap\">\n<div class=\"box-bg\"><\/div>\n<div class=\"inner\" style=\"min-height: 120px\">\n<div class=\"inner-wrap\"><i class=\"icon-default-style fa fa-check\" data-color=\"accent-color\" style=\"font-size: 20px!important;line-height: 20px!important\"><\/i><\/p>\n<h4><strong>Fixed version: <\/strong><\/h4>\n<p>16.30 and later.<\/p><\/div>\n<\/div><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"vc_col-sm-4 wpb_column column_container vc_column_container col child_column no-extra-padding inherit_tablet inherit_phone \" data-padding-pos=\"all\" data-has-bg-color=\"false\" data-bg-color=\"\" data-bg-opacity=\"1\" data-animation=\"\" data-delay=\"0\">\n<div class=\"vc_column-inner\">\n<div class=\"wpb_wrapper\">\n<div class=\"nectar-fancy-box  \" data-style=\"color_box_hover\" data-animation=\"\" data-hover-o=\"default\" data-border-radius=\"default\" data-border=\"true\" data-box-color-opacity=\"1\" data-delay=\"\" data-alignment=\"center\" data-color=\"accent-color\">\n<div class=\"box-inner-wrap\">\n<div class=\"box-bg\"><\/div>\n<div class=\"inner\" style=\"min-height: 120px\">\n<div class=\"inner-wrap\"><i class=\"icon-default-style fa fa-star\" data-color=\"accent-color\" style=\"font-size: 20px!important;line-height: 20px!important\"><\/i><\/p>\n<h4><strong>CVSS: <\/strong><\/h4>\n<p>9.2 (CVE-2026-65638), 9.5 (CVE-2026-65639).<\/p><\/div>\n<\/div><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/div>\n<\/div>\n<div id=\"fws_6ab1eeff8f020\" data-midnight=\"\" data-column-margin=\"default\" class=\"wpb_row vc_row-fluid vc_row inner_row\">\n<div class=\"row-bg-wrap\">\n<div class=\"row-bg\"><\/div>\n<\/p><\/div>\n<div class=\"row_col_wrap_12_inner col span_12  left\">\n<div class=\"vc_col-sm-12 wpb_column column_container vc_column_container col child_column no-extra-padding inherit_tablet inherit_phone \" data-padding-pos=\"all\" data-has-bg-color=\"false\" data-bg-color=\"\" data-bg-opacity=\"1\" data-animation=\"\" data-delay=\"0\">\n<div class=\"vc_column-inner\">\n<div class=\"wpb_wrapper\">\n<div class=\"nectar-split-heading \" data-align=\"default\" data-m-align=\"inherit\" data-text-effect=\"none\" data-animation-type=\"line-reveal-by-space\" data-animation-delay=\"0\" data-animation-offset=\"\" data-m-rm-animation=\"\" data-stagger=\"\" data-custom-font-size=\"false\">\n<h3>What This Means For You:<\/h3>\n<\/div>\n<div class=\"wpb_text_column wpb_content_element \">\n<div class=\"wpb_wrapper\">\n<p>On shared hosting, a successful attack against a server-wide firewall tool like CSF could affect every website on that server, not just one account, since the compromise happens at root level. On VPS and dedicated servers, the practical risk is lower unless MESSENGER with reCAPTCHA is deliberately configured, or the server pulls IP block lists from a feed an attacker could influence, but the potential impact if either applies is severe.<\/p>\n<\/p><\/div>\n<\/div><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/div>\n<\/div>\n<div id=\"fws_6ab1eeff8f1d7\" data-midnight=\"\" data-column-margin=\"default\" class=\"wpb_row vc_row-fluid vc_row inner_row\">\n<div class=\"row-bg-wrap\">\n<div class=\"row-bg\"><\/div>\n<\/p><\/div>\n<div class=\"row_col_wrap_12_inner col span_12  left\">\n<div class=\"vc_col-sm-12 wpb_column column_container vc_column_container col child_column no-extra-padding inherit_tablet inherit_phone \" data-padding-pos=\"all\" data-has-bg-color=\"false\" data-bg-color=\"\" data-bg-opacity=\"1\" data-animation=\"\" data-delay=\"0\">\n<div class=\"vc_column-inner\">\n<div class=\"wpb_wrapper\">\n<div class=\"nectar-split-heading \" data-align=\"default\" data-m-align=\"inherit\" data-text-effect=\"none\" data-animation-type=\"line-reveal-by-space\" data-animation-delay=\"0\" data-animation-offset=\"\" data-m-rm-animation=\"\" data-stagger=\"\" data-custom-font-size=\"false\">\n<h3>Recommended Action:<\/h3>\n<\/div>\n<div class=\"wpb_text_column wpb_content_element \">\n<div class=\"wpb_wrapper\">\n<p>Update CSF to 16.30 or later on any server where it is installed. If MESSENGER is enabled, disable it until the update is confirmed applied.<\/p>\n<\/p><\/div>\n<\/div><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/div>\n<\/div><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/div>\n<\/div>\n<div id=\"fws_6ab1eeff8f4df\" data-column-margin=\"default\" data-midnight=\"dark\" data-bottom-percent=\"2%\" class=\"wpb_row vc_row-fluid vc_row\" style=\"padding-top: 0px;padding-bottom: calc(100vw * 0.02)\">\n<div class=\"row-bg-wrap\" data-bg-animation=\"none\" data-bg-animation-delay=\"\" data-bg-overlay=\"false\">\n<div class=\"inner-wrap row-bg-layer\">\n<div class=\"row-bg viewport-desktop\"><\/div>\n<\/div>\n<\/div>\n<div class=\"row_col_wrap_12 col span_12 dark left\">\n<div class=\"vc_col-sm-12 wpb_column column_container vc_column_container col no-extra-padding inherit_tablet inherit_phone \" data-padding-pos=\"all\" data-has-bg-color=\"false\" data-bg-color=\"\" data-bg-opacity=\"1\" data-animation=\"\" data-delay=\"0\">\n<div class=\"vc_column-inner\">\n<div class=\"wpb_wrapper\">\n<div id=\"fws_6ab1eeff8f5f5\" data-midnight=\"\" data-column-margin=\"default\" class=\"wpb_row vc_row-fluid vc_row inner_row\">\n<div class=\"row-bg-wrap\">\n<div class=\"row-bg\"><\/div>\n<\/p><\/div>\n<div class=\"row_col_wrap_12_inner col span_12  left\">\n<div class=\"vc_col-sm-12 wpb_column column_container vc_column_container col child_column no-extra-padding inherit_tablet inherit_phone \" data-padding-pos=\"all\" data-has-bg-color=\"false\" data-bg-color=\"\" data-bg-opacity=\"1\" data-animation=\"\" data-delay=\"0\">\n<div class=\"vc_column-inner\">\n<div class=\"wpb_wrapper\">\n<div class=\"nectar-split-heading \" data-align=\"default\" data-m-align=\"inherit\" data-text-effect=\"none\" data-animation-type=\"line-reveal-by-space\" data-animation-delay=\"0\" data-animation-offset=\"\" data-m-rm-animation=\"\" data-stagger=\"\" data-custom-font-size=\"false\">\n<h3>[High] LiteSpeed Web Server Enterprise Account-Isolation Bypass (no CVE assigned)<\/h3>\n<\/div>\n<div class=\"divider-wrap\" data-alignment=\"default\">\n<div style=\"margin-top: 12.5px;height: 3px;margin-bottom: 12.5px\" data-width=\"100%\" data-animate=\"\" data-animation-delay=\"\" data-color=\"default\" class=\"divider-border\"><\/div>\n<\/div>\n<div class=\"wpb_text_column wpb_content_element \">\n<div class=\"wpb_wrapper\">\n<p>cPanel published an advisory on 14 September 2026 warning that LiteSpeed Web Server Enterprise, widely used as a faster alternative to Apache on shared hosting, contains a flaw that lets a malicious low-privilege hosting account escape the isolation controls meant to keep customer accounts separate, including CageFS, and potentially reach root on the underlying server. Neither cPanel nor LiteSpeed have published technical detail on how the flaw works, and as of publication no CVE identifier has been assigned to it, which is unusual for an issue of this severity. This is reportedly the third LiteSpeed account-isolation flaw disclosed in four months.<\/p>\n<\/p><\/div>\n<\/div><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/div>\n<\/div>\n<div id=\"fws_6ab1eeff8f7fb\" data-midnight=\"\" data-column-margin=\"default\" class=\"wpb_row vc_row-fluid vc_row inner_row\">\n<div class=\"row-bg-wrap\">\n<div class=\"row-bg\"><\/div>\n<\/p><\/div>\n<div class=\"row_col_wrap_12_inner col span_12  left\">\n<div class=\"vc_col-sm-4 wpb_column column_container vc_column_container col child_column no-extra-padding inherit_tablet inherit_phone \" data-padding-pos=\"all\" data-has-bg-color=\"false\" data-bg-color=\"\" data-bg-opacity=\"1\" data-animation=\"\" data-delay=\"0\">\n<div class=\"vc_column-inner\">\n<div class=\"wpb_wrapper\">\n<div class=\"nectar-fancy-box  \" data-style=\"color_box_hover\" data-animation=\"\" data-hover-o=\"default\" data-border-radius=\"default\" data-border=\"true\" data-box-color-opacity=\"1\" data-delay=\"\" data-alignment=\"center\" data-color=\"accent-color\">\n<div class=\"box-inner-wrap\">\n<div class=\"box-bg\"><\/div>\n<div class=\"inner\" style=\"min-height: 120px\">\n<div class=\"inner-wrap\"><i class=\"icon-default-style fa fa-exclamation-triangle\" data-color=\"accent-color\" style=\"font-size: 20px!important;line-height: 20px!important\"><\/i><\/p>\n<h4><strong>Affected: <\/strong><\/h4>\n<p>LiteSpeed Web Server Enterprise before version 6.3.7.<\/p><\/div>\n<\/div><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"vc_col-sm-4 wpb_column column_container vc_column_container col child_column no-extra-padding inherit_tablet inherit_phone \" data-padding-pos=\"all\" data-has-bg-color=\"false\" data-bg-color=\"\" data-bg-opacity=\"1\" data-animation=\"\" data-delay=\"0\">\n<div class=\"vc_column-inner\">\n<div class=\"wpb_wrapper\">\n<div class=\"nectar-fancy-box  \" data-style=\"color_box_hover\" data-animation=\"\" data-hover-o=\"default\" data-border-radius=\"default\" data-border=\"true\" data-box-color-opacity=\"1\" data-delay=\"\" data-alignment=\"center\" data-color=\"accent-color\">\n<div class=\"box-inner-wrap\">\n<div class=\"box-bg\"><\/div>\n<div class=\"inner\" style=\"min-height: 120px\">\n<div class=\"inner-wrap\"><i class=\"icon-default-style fa fa-check\" data-color=\"accent-color\" style=\"font-size: 20px!important;line-height: 20px!important\"><\/i><\/p>\n<h4><strong>Fixed version: <\/strong><\/h4>\n<p>6.3.7.<\/p><\/div>\n<\/div><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"vc_col-sm-4 wpb_column column_container vc_column_container col child_column no-extra-padding inherit_tablet inherit_phone \" data-padding-pos=\"all\" data-has-bg-color=\"false\" data-bg-color=\"\" data-bg-opacity=\"1\" data-animation=\"\" data-delay=\"0\">\n<div class=\"vc_column-inner\">\n<div class=\"wpb_wrapper\">\n<div class=\"nectar-fancy-box  \" data-style=\"color_box_hover\" data-animation=\"\" data-hover-o=\"default\" data-border-radius=\"default\" data-border=\"true\" data-box-color-opacity=\"1\" data-delay=\"\" data-alignment=\"center\" data-color=\"accent-color\">\n<div class=\"box-inner-wrap\">\n<div class=\"box-bg\"><\/div>\n<div class=\"inner\" style=\"min-height: 120px\">\n<div class=\"inner-wrap\"><i class=\"icon-default-style fa fa-star\" data-color=\"accent-color\" style=\"font-size: 20px!important;line-height: 20px!important\"><\/i><\/p>\n<h4><strong>CVSS: <\/strong><\/h4>\n<p>Not assigned.<\/p><\/div>\n<\/div><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/div>\n<\/div>\n<div id=\"fws_6ab1eeff8fbf2\" data-midnight=\"\" data-column-margin=\"default\" class=\"wpb_row vc_row-fluid vc_row inner_row\">\n<div class=\"row-bg-wrap\">\n<div class=\"row-bg\"><\/div>\n<\/p><\/div>\n<div class=\"row_col_wrap_12_inner col span_12  left\">\n<div class=\"vc_col-sm-12 wpb_column column_container vc_column_container col child_column no-extra-padding inherit_tablet inherit_phone \" data-padding-pos=\"all\" data-has-bg-color=\"false\" data-bg-color=\"\" data-bg-opacity=\"1\" data-animation=\"\" data-delay=\"0\">\n<div class=\"vc_column-inner\">\n<div class=\"wpb_wrapper\">\n<div class=\"nectar-split-heading \" data-align=\"default\" data-m-align=\"inherit\" data-text-effect=\"none\" data-animation-type=\"line-reveal-by-space\" data-animation-delay=\"0\" data-animation-offset=\"\" data-m-rm-animation=\"\" data-stagger=\"\" data-custom-font-size=\"false\">\n<h3>What This Means For You:<\/h3>\n<\/div>\n<div class=\"wpb_text_column wpb_content_element \">\n<div class=\"wpb_wrapper\">\n<p>This is specifically a shared-hosting risk, since it depends on multiple customer accounts sharing one server, which is exactly the CageFS model. VPS and dedicated server users, where each customer already has their own isolated environment, are not affected by this particular flaw.<\/p>\n<\/p><\/div>\n<\/div><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/div>\n<\/div>\n<div id=\"fws_6ab1eeff8fdb1\" data-midnight=\"\" data-column-margin=\"default\" class=\"wpb_row vc_row-fluid vc_row inner_row\">\n<div class=\"row-bg-wrap\">\n<div class=\"row-bg\"><\/div>\n<\/p><\/div>\n<div class=\"row_col_wrap_12_inner col span_12  left\">\n<div class=\"vc_col-sm-12 wpb_column column_container vc_column_container col child_column no-extra-padding inherit_tablet inherit_phone \" data-padding-pos=\"all\" data-has-bg-color=\"false\" data-bg-color=\"\" data-bg-opacity=\"1\" data-animation=\"\" data-delay=\"0\">\n<div class=\"vc_column-inner\">\n<div class=\"wpb_wrapper\">\n<div class=\"nectar-split-heading \" data-align=\"default\" data-m-align=\"inherit\" data-text-effect=\"none\" data-animation-type=\"line-reveal-by-space\" data-animation-delay=\"0\" data-animation-offset=\"\" data-m-rm-animation=\"\" data-stagger=\"\" data-custom-font-size=\"false\">\n<h3>Recommended Action:<\/h3>\n<\/div>\n<div class=\"wpb_text_column wpb_content_element \">\n<div class=\"wpb_wrapper\">\n<p>Update LiteSpeed Web Server Enterprise to 6.3.7 or later on every affected server as a priority.<\/p>\n<\/p><\/div>\n<\/div><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/div>\n<\/div><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/div>\n<\/div>\n<div id=\"fws_6ab1eeff900bd\" data-column-margin=\"default\" data-midnight=\"dark\" data-bottom-percent=\"2%\" class=\"wpb_row vc_row-fluid vc_row\" style=\"padding-top: 0px;padding-bottom: calc(100vw * 0.02)\">\n<div class=\"row-bg-wrap\" data-bg-animation=\"none\" data-bg-animation-delay=\"\" data-bg-overlay=\"false\">\n<div class=\"inner-wrap row-bg-layer\">\n<div class=\"row-bg viewport-desktop\"><\/div>\n<\/div>\n<\/div>\n<div class=\"row_col_wrap_12 col span_12 dark left\">\n<div class=\"vc_col-sm-12 wpb_column column_container vc_column_container col no-extra-padding inherit_tablet inherit_phone \" data-padding-pos=\"all\" data-has-bg-color=\"false\" data-bg-color=\"\" data-bg-opacity=\"1\" data-animation=\"\" data-delay=\"0\">\n<div class=\"vc_column-inner\">\n<div class=\"wpb_wrapper\">\n<div id=\"fws_6ab1eeff901d5\" data-midnight=\"\" data-column-margin=\"default\" class=\"wpb_row vc_row-fluid vc_row inner_row\">\n<div class=\"row-bg-wrap\">\n<div class=\"row-bg\"><\/div>\n<\/p><\/div>\n<div class=\"row_col_wrap_12_inner col span_12  left\">\n<div class=\"vc_col-sm-12 wpb_column column_container vc_column_container col child_column no-extra-padding inherit_tablet inherit_phone \" data-padding-pos=\"all\" data-has-bg-color=\"false\" data-bg-color=\"\" data-bg-opacity=\"1\" data-animation=\"\" data-delay=\"0\">\n<div class=\"vc_column-inner\">\n<div class=\"wpb_wrapper\">\n<div class=\"nectar-split-heading \" data-align=\"default\" data-m-align=\"inherit\" data-text-effect=\"none\" data-animation-type=\"line-reveal-by-space\" data-animation-delay=\"0\" data-animation-offset=\"\" data-m-rm-animation=\"\" data-stagger=\"\" data-custom-font-size=\"false\">\n<h3>[High] Acronis Backup Plugin for cPanel &amp; WHM and Plesk Actively Exploited (CVE-2026-87886)<\/h3>\n<\/div>\n<div class=\"divider-wrap\" data-alignment=\"default\">\n<div style=\"margin-top: 12.5px;height: 3px;margin-bottom: 12.5px\" data-width=\"100%\" data-animate=\"\" data-animation-delay=\"\" data-color=\"default\" class=\"divider-border\"><\/div>\n<\/div>\n<div class=\"wpb_text_column wpb_content_element \">\n<div class=\"wpb_wrapper\">\n<p>Acronis disclosed on 15 September 2026 that its Backup plugin for cPanel &amp; WHM and its Backup extension for Plesk contain a local privilege escalation flaw caused by incorrect default file permissions. Acronis confirmed that exploitation has already been detected in the wild, in limited and targeted attacks against cPanel &amp; WHM deployments; no exploitation against Plesk deployments has been reported so far. CISA added the flaw to its Known Exploited Vulnerabilities catalogue on 16 September 2026.<\/p>\n<\/p><\/div>\n<\/div><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/div>\n<\/div>\n<div id=\"fws_6ab1eeff903d9\" data-midnight=\"\" data-column-margin=\"default\" class=\"wpb_row vc_row-fluid vc_row inner_row\">\n<div class=\"row-bg-wrap\">\n<div class=\"row-bg\"><\/div>\n<\/p><\/div>\n<div class=\"row_col_wrap_12_inner col span_12  left\">\n<div class=\"vc_col-sm-4 wpb_column column_container vc_column_container col child_column no-extra-padding inherit_tablet inherit_phone \" data-padding-pos=\"all\" data-has-bg-color=\"false\" data-bg-color=\"\" data-bg-opacity=\"1\" data-animation=\"\" data-delay=\"0\">\n<div class=\"vc_column-inner\">\n<div class=\"wpb_wrapper\">\n<div class=\"nectar-fancy-box  \" data-style=\"color_box_hover\" data-animation=\"\" data-hover-o=\"default\" data-border-radius=\"default\" data-border=\"true\" data-box-color-opacity=\"1\" data-delay=\"\" data-alignment=\"center\" data-color=\"accent-color\">\n<div class=\"box-inner-wrap\">\n<div class=\"box-bg\"><\/div>\n<div class=\"inner\" style=\"min-height: 120px\">\n<div class=\"inner-wrap\"><i class=\"icon-default-style fa fa-exclamation-triangle\" data-color=\"accent-color\" style=\"font-size: 20px!important;line-height: 20px!important\"><\/i><\/p>\n<h4><strong>Affected: <\/strong><\/h4>\n<p>Acronis Backup plugin for cPanel &amp; WHM before build 1.9.3.1021, and Backup extension for Plesk before build 1.8.11.638.<\/p><\/div>\n<\/div><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"vc_col-sm-4 wpb_column column_container vc_column_container col child_column no-extra-padding inherit_tablet inherit_phone \" data-padding-pos=\"all\" data-has-bg-color=\"false\" data-bg-color=\"\" data-bg-opacity=\"1\" data-animation=\"\" data-delay=\"0\">\n<div class=\"vc_column-inner\">\n<div class=\"wpb_wrapper\">\n<div class=\"nectar-fancy-box  \" data-style=\"color_box_hover\" data-animation=\"\" data-hover-o=\"default\" data-border-radius=\"default\" data-border=\"true\" data-box-color-opacity=\"1\" data-delay=\"\" data-alignment=\"center\" data-color=\"accent-color\">\n<div class=\"box-inner-wrap\">\n<div class=\"box-bg\"><\/div>\n<div class=\"inner\" style=\"min-height: 120px\">\n<div class=\"inner-wrap\"><i class=\"icon-default-style fa fa-check\" data-color=\"accent-color\" style=\"font-size: 20px!important;line-height: 20px!important\"><\/i><\/p>\n<h4><strong>Fixed version: <\/strong><\/h4>\n<p>1.9.3 HF3 (cPanel &amp; WHM), 1.8.11 (Plesk).<\/p><\/div>\n<\/div><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"vc_col-sm-4 wpb_column column_container vc_column_container col child_column no-extra-padding inherit_tablet inherit_phone \" data-padding-pos=\"all\" data-has-bg-color=\"false\" data-bg-color=\"\" data-bg-opacity=\"1\" data-animation=\"\" data-delay=\"0\">\n<div class=\"vc_column-inner\">\n<div class=\"wpb_wrapper\">\n<div class=\"nectar-fancy-box  \" data-style=\"color_box_hover\" data-animation=\"\" data-hover-o=\"default\" data-border-radius=\"default\" data-border=\"true\" data-box-color-opacity=\"1\" data-delay=\"\" data-alignment=\"center\" data-color=\"accent-color\">\n<div class=\"box-inner-wrap\">\n<div class=\"box-bg\"><\/div>\n<div class=\"inner\" style=\"min-height: 120px\">\n<div class=\"inner-wrap\"><i class=\"icon-default-style fa fa-star\" data-color=\"accent-color\" style=\"font-size: 20px!important;line-height: 20px!important\"><\/i><\/p>\n<h4><strong>CVSS: <\/strong><\/h4>\n<p>7.8.<\/p><\/div>\n<\/div><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/div>\n<\/div>\n<div id=\"fws_6ab1eeff907fc\" data-midnight=\"\" data-column-margin=\"default\" class=\"wpb_row vc_row-fluid vc_row inner_row\">\n<div class=\"row-bg-wrap\">\n<div class=\"row-bg\"><\/div>\n<\/p><\/div>\n<div class=\"row_col_wrap_12_inner col span_12  left\">\n<div class=\"vc_col-sm-12 wpb_column column_container vc_column_container col child_column no-extra-padding inherit_tablet inherit_phone \" data-padding-pos=\"all\" data-has-bg-color=\"false\" data-bg-color=\"\" data-bg-opacity=\"1\" data-animation=\"\" data-delay=\"0\">\n<div class=\"vc_column-inner\">\n<div class=\"wpb_wrapper\">\n<div class=\"nectar-split-heading \" data-align=\"default\" data-m-align=\"inherit\" data-text-effect=\"none\" data-animation-type=\"line-reveal-by-space\" data-animation-delay=\"0\" data-animation-offset=\"\" data-m-rm-animation=\"\" data-stagger=\"\" data-custom-font-size=\"false\">\n<h3>What This Means For You:<\/h3>\n<\/div>\n<div class=\"wpb_text_column wpb_content_element \">\n<div class=\"wpb_wrapper\">\n<p>Exploitation requires an attacker to already have some form of local, low-privilege access to the server, for example through a compromised hosting account, weak credentials, or a vulnerable web application. From there, this flaw could let them escalate to read backup data, system files, or other accounts on a shared server.<\/p>\n<\/p><\/div>\n<\/div><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/div>\n<\/div>\n<div id=\"fws_6ab1eeff909a5\" data-midnight=\"\" data-column-margin=\"default\" class=\"wpb_row vc_row-fluid vc_row inner_row\">\n<div class=\"row-bg-wrap\">\n<div class=\"row-bg\"><\/div>\n<\/p><\/div>\n<div class=\"row_col_wrap_12_inner col span_12  left\">\n<div class=\"vc_col-sm-12 wpb_column column_container vc_column_container col child_column no-extra-padding inherit_tablet inherit_phone \" data-padding-pos=\"all\" data-has-bg-color=\"false\" data-bg-color=\"\" data-bg-opacity=\"1\" data-animation=\"\" data-delay=\"0\">\n<div class=\"vc_column-inner\">\n<div class=\"wpb_wrapper\">\n<div class=\"nectar-split-heading \" data-align=\"default\" data-m-align=\"inherit\" data-text-effect=\"none\" data-animation-type=\"line-reveal-by-space\" data-animation-delay=\"0\" data-animation-offset=\"\" data-m-rm-animation=\"\" data-stagger=\"\" data-custom-font-size=\"false\">\n<h3>Recommended Action:<\/h3>\n<\/div>\n<div class=\"wpb_text_column wpb_content_element \">\n<div class=\"wpb_wrapper\">\n<p>Update the Acronis Backup plugin\/extension to the fixed build on any server where it is installed, and review access logs for signs of unexpected privilege changes.<\/p>\n<\/p><\/div>\n<\/div><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/div>\n<\/div><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/div>\n<\/div>\n<div id=\"fws_6ab1eeff90cb0\" data-column-margin=\"default\" data-midnight=\"dark\" data-bottom-percent=\"2%\" class=\"wpb_row vc_row-fluid vc_row\" style=\"padding-top: 0px;padding-bottom: calc(100vw * 0.02)\">\n<div class=\"row-bg-wrap\" data-bg-animation=\"none\" data-bg-animation-delay=\"\" data-bg-overlay=\"false\">\n<div class=\"inner-wrap row-bg-layer\">\n<div class=\"row-bg viewport-desktop\"><\/div>\n<\/div>\n<\/div>\n<div class=\"row_col_wrap_12 col span_12 dark left\">\n<div class=\"vc_col-sm-12 wpb_column column_container vc_column_container col no-extra-padding inherit_tablet inherit_phone \" data-padding-pos=\"all\" data-has-bg-color=\"false\" data-bg-color=\"\" data-bg-opacity=\"1\" data-animation=\"\" data-delay=\"0\">\n<div class=\"vc_column-inner\">\n<div class=\"wpb_wrapper\">\n<div id=\"fws_6ab1eeff90db0\" data-midnight=\"\" data-column-margin=\"default\" class=\"wpb_row vc_row-fluid vc_row inner_row\">\n<div class=\"row-bg-wrap\">\n<div class=\"row-bg\"><\/div>\n<\/p><\/div>\n<div class=\"row_col_wrap_12_inner col span_12  left\">\n<div class=\"vc_col-sm-12 wpb_column column_container vc_column_container col child_column no-extra-padding inherit_tablet inherit_phone \" data-padding-pos=\"all\" data-has-bg-color=\"false\" data-bg-color=\"\" data-bg-opacity=\"1\" data-animation=\"\" data-delay=\"0\">\n<div class=\"vc_column-inner\">\n<div class=\"wpb_wrapper\">\n<div class=\"nectar-split-heading \" data-align=\"default\" data-m-align=\"inherit\" data-text-effect=\"none\" data-animation-type=\"line-reveal-by-space\" data-animation-delay=\"0\" data-animation-offset=\"\" data-m-rm-animation=\"\" data-stagger=\"\" data-custom-font-size=\"false\">\n<h3>[Critical] WordPress &#8220;Login with QR&#8221; Plugin Unauthenticated Admin Takeover (CVE-2026-86710)<\/h3>\n<\/div>\n<div class=\"divider-wrap\" data-alignment=\"default\">\n<div style=\"margin-top: 12.5px;height: 3px;margin-bottom: 12.5px\" data-width=\"100%\" data-animate=\"\" data-animation-delay=\"\" data-color=\"default\" class=\"divider-border\"><\/div>\n<\/div>\n<div class=\"wpb_text_column wpb_content_element \">\n<div class=\"wpb_wrapper\">\n<p>A vulnerability disclosed on 17 September 2026 in the WordPress plugin &#8220;Login with QR&#8221; (versions up to and including 1.0.0) allows any unauthenticated visitor to log in as any user on the site, including administrators. The plugin is meant to let a user log in by scanning a QR code, but it fails to verify that the code presented is one it actually issued, instead accepting any code that matches a stored value, which an attacker can guess or generate themselves. No fixed version has been published yet.<\/p>\n<\/p><\/div>\n<\/div><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/div>\n<\/div>\n<div id=\"fws_6ab1eeff90fac\" data-midnight=\"\" data-column-margin=\"default\" class=\"wpb_row vc_row-fluid vc_row inner_row\">\n<div class=\"row-bg-wrap\">\n<div class=\"row-bg\"><\/div>\n<\/p><\/div>\n<div class=\"row_col_wrap_12_inner col span_12  left\">\n<div class=\"vc_col-sm-4 wpb_column column_container vc_column_container col child_column no-extra-padding inherit_tablet inherit_phone \" data-padding-pos=\"all\" data-has-bg-color=\"false\" data-bg-color=\"\" data-bg-opacity=\"1\" data-animation=\"\" data-delay=\"0\">\n<div class=\"vc_column-inner\">\n<div class=\"wpb_wrapper\">\n<div class=\"nectar-fancy-box  \" data-style=\"color_box_hover\" data-animation=\"\" data-hover-o=\"default\" data-border-radius=\"default\" data-border=\"true\" data-box-color-opacity=\"1\" data-delay=\"\" data-alignment=\"center\" data-color=\"accent-color\">\n<div class=\"box-inner-wrap\">\n<div class=\"box-bg\"><\/div>\n<div class=\"inner\" style=\"min-height: 120px\">\n<div class=\"inner-wrap\"><i class=\"icon-default-style fa fa-exclamation-triangle\" data-color=\"accent-color\" style=\"font-size: 20px!important;line-height: 20px!important\"><\/i><\/p>\n<h4><strong>Affected: <\/strong><\/h4>\n<p>Login with QR, all versions up to 1.0.0.<\/p><\/div>\n<\/div><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"vc_col-sm-4 wpb_column column_container vc_column_container col child_column no-extra-padding inherit_tablet inherit_phone \" data-padding-pos=\"all\" data-has-bg-color=\"false\" data-bg-color=\"\" data-bg-opacity=\"1\" data-animation=\"\" data-delay=\"0\">\n<div class=\"vc_column-inner\">\n<div class=\"wpb_wrapper\">\n<div class=\"nectar-fancy-box  \" data-style=\"color_box_hover\" data-animation=\"\" data-hover-o=\"default\" data-border-radius=\"default\" data-border=\"true\" data-box-color-opacity=\"1\" data-delay=\"\" data-alignment=\"center\" data-color=\"accent-color\">\n<div class=\"box-inner-wrap\">\n<div class=\"box-bg\"><\/div>\n<div class=\"inner\" style=\"min-height: 120px\">\n<div class=\"inner-wrap\"><i class=\"icon-default-style fa fa-check\" data-color=\"accent-color\" style=\"font-size: 20px!important;line-height: 20px!important\"><\/i><\/p>\n<h4><strong>Fixed version: <\/strong><\/h4>\n<p>None yet available.<\/p><\/div>\n<\/div><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"vc_col-sm-4 wpb_column column_container vc_column_container col child_column no-extra-padding inherit_tablet inherit_phone \" data-padding-pos=\"all\" data-has-bg-color=\"false\" data-bg-color=\"\" data-bg-opacity=\"1\" data-animation=\"\" data-delay=\"0\">\n<div class=\"vc_column-inner\">\n<div class=\"wpb_wrapper\">\n<div class=\"nectar-fancy-box  \" data-style=\"color_box_hover\" data-animation=\"\" data-hover-o=\"default\" data-border-radius=\"default\" data-border=\"true\" data-box-color-opacity=\"1\" data-delay=\"\" data-alignment=\"center\" data-color=\"accent-color\">\n<div class=\"box-inner-wrap\">\n<div class=\"box-bg\"><\/div>\n<div class=\"inner\" style=\"min-height: 120px\">\n<div class=\"inner-wrap\"><i class=\"icon-default-style fa fa-star\" data-color=\"accent-color\" style=\"font-size: 20px!important;line-height: 20px!important\"><\/i><\/p>\n<h4><strong>CVSS: <\/strong><\/h4>\n<p>Not yet scored by NVD.<\/p><\/div>\n<\/div><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/div>\n<\/div>\n<div id=\"fws_6ab1eeff913a5\" data-midnight=\"\" data-column-margin=\"default\" class=\"wpb_row vc_row-fluid vc_row inner_row\">\n<div class=\"row-bg-wrap\">\n<div class=\"row-bg\"><\/div>\n<\/p><\/div>\n<div class=\"row_col_wrap_12_inner col span_12  left\">\n<div class=\"vc_col-sm-12 wpb_column column_container vc_column_container col child_column no-extra-padding inherit_tablet inherit_phone \" data-padding-pos=\"all\" data-has-bg-color=\"false\" data-bg-color=\"\" data-bg-opacity=\"1\" data-animation=\"\" data-delay=\"0\">\n<div class=\"vc_column-inner\">\n<div class=\"wpb_wrapper\">\n<div class=\"nectar-split-heading \" data-align=\"default\" data-m-align=\"inherit\" data-text-effect=\"none\" data-animation-type=\"line-reveal-by-space\" data-animation-delay=\"0\" data-animation-offset=\"\" data-m-rm-animation=\"\" data-stagger=\"\" data-custom-font-size=\"false\">\n<h3>What This Means For You:<\/h3>\n<\/div>\n<div class=\"wpb_text_column wpb_content_element \">\n<div class=\"wpb_wrapper\">\n<p>If a website owner has this plugin installed and active, an attacker could gain full administrative control of that WordPress site without needing any credentials.<\/p>\n<\/p><\/div>\n<\/div><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/div>\n<\/div>\n<div id=\"fws_6ab1eeff9154a\" data-midnight=\"\" data-column-margin=\"default\" class=\"wpb_row vc_row-fluid vc_row inner_row\">\n<div class=\"row-bg-wrap\">\n<div class=\"row-bg\"><\/div>\n<\/p><\/div>\n<div class=\"row_col_wrap_12_inner col span_12  left\">\n<div class=\"vc_col-sm-12 wpb_column column_container vc_column_container col child_column no-extra-padding inherit_tablet inherit_phone \" data-padding-pos=\"all\" data-has-bg-color=\"false\" data-bg-color=\"\" data-bg-opacity=\"1\" data-animation=\"\" data-delay=\"0\">\n<div class=\"vc_column-inner\">\n<div class=\"wpb_wrapper\">\n<div class=\"nectar-split-heading \" data-align=\"default\" data-m-align=\"inherit\" data-text-effect=\"none\" data-animation-type=\"line-reveal-by-space\" data-animation-delay=\"0\" data-animation-offset=\"\" data-m-rm-animation=\"\" data-stagger=\"\" data-custom-font-size=\"false\">\n<h3>Recommended Action:<\/h3>\n<\/div>\n<div class=\"wpb_text_column wpb_content_element \">\n<div class=\"wpb_wrapper\">\n<p>Deactivate and remove the plugin immediately on any site where it is installed, until a fixed version is released.<\/p>\n<\/p><\/div>\n<\/div><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/div>\n<\/div><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/div>\n<\/div>\n<div id=\"fws_6ab1eeff91851\" data-column-margin=\"default\" data-midnight=\"dark\" data-bottom-percent=\"2%\" class=\"wpb_row vc_row-fluid vc_row\" style=\"padding-top: 0px;padding-bottom: calc(100vw * 0.02)\">\n<div class=\"row-bg-wrap\" data-bg-animation=\"none\" data-bg-animation-delay=\"\" data-bg-overlay=\"false\">\n<div class=\"inner-wrap row-bg-layer\">\n<div class=\"row-bg viewport-desktop\"><\/div>\n<\/div>\n<\/div>\n<div class=\"row_col_wrap_12 col span_12 dark left\">\n<div class=\"vc_col-sm-12 wpb_column column_container vc_column_container col no-extra-padding inherit_tablet inherit_phone \" data-padding-pos=\"all\" data-has-bg-color=\"false\" data-bg-color=\"\" data-bg-opacity=\"1\" data-animation=\"\" data-delay=\"0\">\n<div class=\"vc_column-inner\">\n<div class=\"wpb_wrapper\">\n<div id=\"fws_6ab1eeff9195a\" data-midnight=\"\" data-column-margin=\"default\" class=\"wpb_row vc_row-fluid vc_row inner_row\">\n<div class=\"row-bg-wrap\">\n<div class=\"row-bg\"><\/div>\n<\/p><\/div>\n<div class=\"row_col_wrap_12_inner col span_12  left\">\n<div class=\"vc_col-sm-12 wpb_column column_container vc_column_container col child_column no-extra-padding inherit_tablet inherit_phone \" data-padding-pos=\"all\" data-has-bg-color=\"false\" data-bg-color=\"\" data-bg-opacity=\"1\" data-animation=\"\" data-delay=\"0\">\n<div class=\"vc_column-inner\">\n<div class=\"wpb_wrapper\">\n<div class=\"nectar-split-heading \" data-align=\"default\" data-m-align=\"inherit\" data-text-effect=\"none\" data-animation-type=\"line-reveal-by-space\" data-animation-delay=\"0\" data-animation-offset=\"\" data-m-rm-animation=\"\" data-stagger=\"\" data-custom-font-size=\"false\">\n<h3>How to Check If Your Site Has Been Compromised<\/h3>\n<\/div>\n<div class=\"divider-wrap\" data-alignment=\"default\">\n<div style=\"margin-top: 12.5px;height: 3px;margin-bottom: 12.5px\" data-width=\"100%\" data-animate=\"\" data-animation-delay=\"\" data-color=\"default\" class=\"divider-border\"><\/div>\n<\/div>\n<div class=\"nectar-fancy-ul\" data-list-icon=\"icon-salient-thin-line\" data-animation=\"false\" data-animation-delay=\"0\" data-color=\"accent-color\" data-spacing=\"default\" data-alignment=\"left\">\n<ul>\n<li>Review the WordPress admin users list for accounts you don&#8217;t recognise, particularly any created or elevated to Administrator recently.<\/li>\n<li>Check for unexpected changes to plugin or theme files, or new files in the uploads directory.<\/li>\n<li>Review cPanel\/WHM account and server access logs around the affected dates for unusual privilege escalations or process activity.<\/li>\n<li>Check for unfamiliar cron jobs or scheduled tasks.<\/li>\n<li>Look for outbound connections to unfamiliar IP addresses or domains from the server.<\/li>\n<li>If you find anything suspicious, change all passwords and API keys, and consider taking the affected site offline while you investigate further.<\/li>\n<\/ul><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/div>\n<\/div><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/div>\n<\/div>\n<div id=\"fws_6ab1eeff91bd3\" data-column-margin=\"default\" data-midnight=\"dark\" data-bottom-percent=\"2%\" class=\"wpb_row vc_row-fluid vc_row\" style=\"padding-top: 0px;padding-bottom: calc(100vw * 0.02)\">\n<div class=\"row-bg-wrap\" data-bg-animation=\"none\" data-bg-animation-delay=\"\" data-bg-overlay=\"false\">\n<div class=\"inner-wrap row-bg-layer\">\n<div class=\"row-bg viewport-desktop\"><\/div>\n<\/div>\n<\/div>\n<div class=\"row_col_wrap_12 col span_12 dark left\">\n<div class=\"vc_col-sm-12 wpb_column column_container vc_column_container col no-extra-padding inherit_tablet inherit_phone \" data-padding-pos=\"all\" data-has-bg-color=\"false\" data-bg-color=\"\" data-bg-opacity=\"1\" data-animation=\"\" data-delay=\"0\">\n<div class=\"vc_column-inner\">\n<div class=\"wpb_wrapper\">\n<div id=\"fws_6ab1eeff91cda\" data-midnight=\"\" data-column-margin=\"default\" class=\"wpb_row vc_row-fluid vc_row inner_row\">\n<div class=\"row-bg-wrap\">\n<div class=\"row-bg\"><\/div>\n<\/p><\/div>\n<div class=\"row_col_wrap_12_inner col span_12  left\">\n<div class=\"vc_col-sm-12 wpb_column column_container vc_column_container col child_column no-extra-padding inherit_tablet inherit_phone \" data-padding-pos=\"all\" data-has-bg-color=\"false\" data-bg-color=\"\" data-bg-opacity=\"1\" data-animation=\"\" data-delay=\"0\">\n<div class=\"vc_column-inner\">\n<div class=\"wpb_wrapper\">\n<div class=\"nectar-split-heading \" data-align=\"default\" data-m-align=\"inherit\" data-text-effect=\"none\" data-animation-type=\"line-reveal-by-space\" data-animation-delay=\"0\" data-animation-offset=\"\" data-m-rm-animation=\"\" data-stagger=\"\" data-custom-font-size=\"false\">\n<h3>Frequently Asked Questions<\/h3>\n<\/div>\n<div class=\"divider-wrap\" data-alignment=\"default\">\n<div style=\"margin-top: 12.5px;height: 3px;margin-bottom: 12.5px\" data-width=\"100%\" data-animate=\"\" data-animation-delay=\"\" data-color=\"default\" class=\"divider-border\"><\/div>\n<\/div><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/div>\n<\/div>\n<div id=\"fws_6ab1eeff91e3e\" data-midnight=\"\" data-column-margin=\"default\" class=\"wpb_row vc_row-fluid vc_row inner_row\">\n<div class=\"row-bg-wrap\">\n<div class=\"row-bg\"><\/div>\n<\/p><\/div>\n<div class=\"row_col_wrap_12_inner col span_12  left\">\n<div class=\"vc_col-sm-12 wpb_column column_container vc_column_container col child_column no-extra-padding inherit_tablet inherit_phone \" data-padding-pos=\"all\" data-has-bg-color=\"false\" data-bg-color=\"\" data-bg-opacity=\"1\" data-animation=\"\" data-delay=\"0\">\n<div class=\"vc_column-inner\">\n<div class=\"wpb_wrapper\">\n<div class=\"nectar-split-heading \" data-align=\"default\" data-m-align=\"inherit\" data-text-effect=\"none\" data-animation-type=\"line-reveal-by-space\" data-animation-delay=\"0\" data-animation-offset=\"\" data-m-rm-animation=\"\" data-stagger=\"\" data-custom-font-size=\"false\">\n<h3>Do I need to do anything if I don&#8217;t use CSF, LiteSpeed, or Acronis Backup?<\/h3>\n<\/div>\n<div class=\"iwithtext\">\n<div class=\"iwt-icon\"> <i class=\"icon-default-style fa fa-thumb-tack accent-color\"><\/i> <\/div>\n<div class=\"iwt-text\"> If your server doesn&#8217;t run these specific products, these particular flaws don&#8217;t apply to you, but it&#8217;s still worth checking which control panel add-ons and backup tools are installed, since these products are common defaults on many cPanel\/WHM servers. <\/div>\n<div class=\"clear\"><\/div>\n<\/div><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/div>\n<\/div>\n<div id=\"fws_6ab1eeff91fa6\" data-midnight=\"\" data-column-margin=\"default\" class=\"wpb_row vc_row-fluid vc_row inner_row\">\n<div class=\"row-bg-wrap\">\n<div class=\"row-bg\"><\/div>\n<\/p><\/div>\n<div class=\"row_col_wrap_12_inner col span_12  left\">\n<div class=\"vc_col-sm-12 wpb_column column_container vc_column_container col child_column no-extra-padding inherit_tablet inherit_phone \" data-padding-pos=\"all\" data-has-bg-color=\"false\" data-bg-color=\"\" data-bg-opacity=\"1\" data-animation=\"\" data-delay=\"0\">\n<div class=\"vc_column-inner\">\n<div class=\"wpb_wrapper\">\n<div class=\"nectar-split-heading \" data-align=\"default\" data-m-align=\"inherit\" data-text-effect=\"none\" data-animation-type=\"line-reveal-by-space\" data-animation-delay=\"0\" data-animation-offset=\"\" data-m-rm-animation=\"\" data-stagger=\"\" data-custom-font-size=\"false\">\n<h3>Is my site at risk if I&#8217;m on shared hosting versus a VPS?<\/h3>\n<\/div>\n<div class=\"iwithtext\">\n<div class=\"iwt-icon\"> <i class=\"icon-default-style fa fa-thumb-tack accent-color\"><\/i> <\/div>\n<div class=\"iwt-text\"> The CSF and LiteSpeed issues are most severe on shared hosting, where one compromised account could affect the whole server. VPS and dedicated server customers, where isolation already exists at the virtual machine level, face a narrower risk from these two issues, though the Acronis and WordPress plugin flaws can affect any hosting type. <\/div>\n<div class=\"clear\"><\/div>\n<\/div><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/div>\n<\/div>\n<div id=\"fws_6ab1eeff9210c\" data-midnight=\"\" data-column-margin=\"default\" class=\"wpb_row vc_row-fluid vc_row inner_row\">\n<div class=\"row-bg-wrap\">\n<div class=\"row-bg\"><\/div>\n<\/p><\/div>\n<div class=\"row_col_wrap_12_inner col span_12  left\">\n<div class=\"vc_col-sm-12 wpb_column column_container vc_column_container col child_column no-extra-padding inherit_tablet inherit_phone \" data-padding-pos=\"all\" data-has-bg-color=\"false\" data-bg-color=\"\" data-bg-opacity=\"1\" data-animation=\"\" data-delay=\"0\">\n<div class=\"vc_column-inner\">\n<div class=\"wpb_wrapper\">\n<div class=\"nectar-split-heading \" data-align=\"default\" data-m-align=\"inherit\" data-text-effect=\"none\" data-animation-type=\"line-reveal-by-space\" data-animation-delay=\"0\" data-animation-offset=\"\" data-m-rm-animation=\"\" data-stagger=\"\" data-custom-font-size=\"false\">\n<h3>How urgently should I patch these?<\/h3>\n<\/div>\n<div class=\"iwithtext\">\n<div class=\"iwt-icon\"> <i class=\"icon-default-style fa fa-thumb-tack accent-color\"><\/i> <\/div>\n<div class=\"iwt-text\"> The CSF and Acronis issues are already being exploited or are trivially exploitable, so these should be treated as priorities. The LiteSpeed issue has no confirmed public exploitation yet but affects the core hosting isolation model, so it should also be addressed promptly. The WordPress plugin issue should be dealt with immediately if that specific plugin is in use, since exploitation requires no special access. <\/div>\n<div class=\"clear\"><\/div>\n<\/div><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/div>\n<\/div>\n<div id=\"fws_6ab1eeff9226e\" data-midnight=\"\" data-column-margin=\"default\" class=\"wpb_row vc_row-fluid vc_row inner_row\">\n<div class=\"row-bg-wrap\">\n<div class=\"row-bg\"><\/div>\n<\/p><\/div>\n<div class=\"row_col_wrap_12_inner col span_12  left\">\n<div class=\"vc_col-sm-12 wpb_column column_container vc_column_container col child_column no-extra-padding inherit_tablet inherit_phone \" data-padding-pos=\"all\" data-has-bg-color=\"false\" data-bg-color=\"\" data-bg-opacity=\"1\" data-animation=\"\" data-delay=\"0\">\n<div class=\"vc_column-inner\">\n<div class=\"wpb_wrapper\">\n<div class=\"nectar-split-heading \" data-align=\"default\" data-m-align=\"inherit\" data-text-effect=\"none\" data-animation-type=\"line-reveal-by-space\" data-animation-delay=\"0\" data-animation-offset=\"\" data-m-rm-animation=\"\" data-stagger=\"\" data-custom-font-size=\"false\">\n<h3>Why doesn&#8217;t the LiteSpeed flaw have a CVE number yet?<\/h3>\n<\/div>\n<div class=\"iwithtext\">\n<div class=\"iwt-icon\"> <i class=\"icon-default-style fa fa-thumb-tack accent-color\"><\/i> <\/div>\n<div class=\"iwt-text\"> CVE assignment can lag behind vendor advisories, particularly when a vendor chooses not to publish technical detail about how a flaw works. The absence of a CVE doesn&#8217;t reduce the severity of the issue; the fixed version should still be applied as a priority. <\/div>\n<div class=\"clear\"><\/div>\n<\/div><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/div>\n<\/div>\n<div id=\"fws_6ab1eeff923de\" data-midnight=\"\" data-column-margin=\"default\" class=\"wpb_row vc_row-fluid vc_row inner_row\">\n<div class=\"row-bg-wrap\">\n<div class=\"row-bg\"><\/div>\n<\/p><\/div>\n<div class=\"row_col_wrap_12_inner col span_12  left\">\n<div class=\"vc_col-sm-12 wpb_column column_container vc_column_container col child_column no-extra-padding inherit_tablet inherit_phone \" data-padding-pos=\"all\" data-has-bg-color=\"false\" data-bg-color=\"\" data-bg-opacity=\"1\" data-animation=\"\" data-delay=\"0\">\n<div class=\"vc_column-inner\">\n<div class=\"wpb_wrapper\">\n<div class=\"nectar-split-heading \" data-align=\"default\" data-m-align=\"inherit\" data-text-effect=\"none\" data-animation-type=\"line-reveal-by-space\" data-animation-delay=\"0\" data-animation-offset=\"\" data-m-rm-animation=\"\" data-stagger=\"\" data-custom-font-size=\"false\">\n<h3>What should I do if I can&#8217;t immediately update one of these products?<\/h3>\n<\/div>\n<div class=\"iwithtext\">\n<div class=\"iwt-icon\"> <i class=\"icon-default-style fa fa-thumb-tack accent-color\"><\/i> <\/div>\n<div class=\"iwt-text\"> Where an immediate update isn&#8217;t possible, consider temporary mitigations: disabling the vulnerable feature (for example, CSF&#8217;s MESSENGER service), restricting access, or, for CageFS-dependent servers, closely monitoring for unusual account activity until the update can be applied. <\/div>\n<div class=\"clear\"><\/div>\n<\/div><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/div>\n<\/div><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/div>\n<\/div>\n<div id=\"fws_6ab1eeff926c4\" data-column-margin=\"default\" data-midnight=\"dark\" class=\"wpb_row vc_row-fluid vc_row\" style=\"padding-top: 0px;padding-bottom: 0px\">\n<div class=\"row-bg-wrap\" data-bg-animation=\"none\" data-bg-animation-delay=\"\" data-bg-overlay=\"false\">\n<div class=\"inner-wrap row-bg-layer\">\n<div class=\"row-bg viewport-desktop\"><\/div>\n<\/div>\n<\/div>\n<div class=\"row_col_wrap_12 col span_12 dark left\">\n<div class=\"vc_col-sm-12 wpb_column column_container vc_column_container col no-extra-padding inherit_tablet inherit_phone \" data-padding-pos=\"all\" data-has-bg-color=\"false\" data-bg-color=\"\" data-bg-opacity=\"1\" data-animation=\"\" data-delay=\"0\">\n<div class=\"vc_column-inner\">\n<div class=\"wpb_wrapper\">\n<div class=\"nectar-split-heading \" data-align=\"default\" data-m-align=\"inherit\" data-text-effect=\"none\" data-animation-type=\"line-reveal-by-space\" data-animation-delay=\"0\" data-animation-offset=\"\" data-m-rm-animation=\"\" data-stagger=\"\" data-custom-font-size=\"false\">\n<h3>Summary<\/h3>\n<\/div>\n<div class=\"wpb_text_column wpb_content_element \">\n<div class=\"wpb_wrapper\">\n<table>\n<tbody>\n<tr>\n<td width=\"96\"><strong>Vulnerability<\/strong><\/td>\n<td width=\"96\"><strong>CVE<\/strong><\/td>\n<td width=\"96\"><strong>CVSS<\/strong><\/td>\n<td width=\"96\"><strong>Affected<\/strong><\/td>\n<td width=\"96\"><strong>Fixed<\/strong><\/td>\n<td width=\"96\"><strong>Action<\/strong><\/td>\n<\/tr>\n<tr>\n<td width=\"96\">ConfigServer Firewall MESSENGER command injection<\/td>\n<td width=\"96\">CVE-2026-65638<\/td>\n<td width=\"96\">9.2<\/td>\n<td width=\"96\">CSF 14.00-16.29<\/td>\n<td width=\"96\">16.30+<\/td>\n<td width=\"96\">Update CSF<\/td>\n<\/tr>\n<tr>\n<td width=\"96\">ConfigServer Firewall advanced-rule parser command injection<\/td>\n<td width=\"96\">CVE-2026-65639<\/td>\n<td width=\"96\">9.5<\/td>\n<td width=\"96\">CSF 2.15-16.29<\/td>\n<td width=\"96\">16.30+<\/td>\n<td width=\"96\">Update CSF<\/td>\n<\/tr>\n<tr>\n<td width=\"96\">LiteSpeed Enterprise CageFS bypass<\/td>\n<td width=\"96\">None assigned<\/td>\n<td width=\"96\">N\/A<\/td>\n<td width=\"96\">LiteSpeed Enterprise &lt;6.3.7<\/td>\n<td width=\"96\">6.3.7<\/td>\n<td width=\"96\">Update LiteSpeed<\/td>\n<\/tr>\n<tr>\n<td width=\"96\">Acronis Backup plugin\/extension local privilege escalation<\/td>\n<td width=\"96\">CVE-2026-87886<\/td>\n<td width=\"96\">7.8<\/td>\n<td width=\"96\">cPanel\/WHM &lt;1.9.3.1021, Plesk &lt;1.8.11.638<\/td>\n<td width=\"96\">1.9.3 HF3 \/ 1.8.11<\/td>\n<td width=\"96\">Update Acronis plugin<\/td>\n<\/tr>\n<tr>\n<td width=\"96\">Login with QR unauthenticated admin takeover<\/td>\n<td width=\"96\">CVE-2026-86710<\/td>\n<td width=\"96\">Pending<\/td>\n<td width=\"96\">&lt;=1.0.0<\/td>\n<td width=\"96\">None yet<\/td>\n<td width=\"96\">Deactivate plugin<\/td>\n<\/tr>\n<\/tbody>\n<\/table><\/div>\n<\/div><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/div>\n<\/div>\n<div id=\"fws_6ab1eeff92b2a\" data-column-margin=\"default\" data-midnight=\"dark\" data-top-percent=\"3%\" class=\"wpb_row vc_row-fluid vc_row\" style=\"padding-top: calc(100vw * 0.03);padding-bottom: 0px\">\n<div class=\"row-bg-wrap\" data-bg-animation=\"none\" data-bg-animation-delay=\"\" data-bg-overlay=\"false\">\n<div class=\"inner-wrap row-bg-layer\">\n<div class=\"row-bg viewport-desktop\"><\/div>\n<\/div>\n<\/div>\n<div class=\"row_col_wrap_12 col span_12 dark left\">\n<div class=\"vc_col-sm-12 wpb_column column_container vc_column_container col no-extra-padding inherit_tablet inherit_phone \" data-padding-pos=\"all\" data-has-bg-color=\"false\" data-bg-color=\"\" data-bg-opacity=\"1\" data-animation=\"\" data-delay=\"0\">\n<div class=\"vc_column-inner\">\n<div class=\"wpb_wrapper\">\n<div id=\"fws_6ab1eeff92c10\" data-midnight=\"\" data-column-margin=\"default\" class=\"wpb_row vc_row-fluid vc_row inner_row\">\n<div class=\"row-bg-wrap\">\n<div class=\"row-bg\"><\/div>\n<\/p><\/div>\n<div class=\"row_col_wrap_12_inner col span_12  left\">\n<div class=\"vc_col-sm-12 wpb_column column_container vc_column_container col child_column no-extra-padding inherit_tablet inherit_phone \" data-padding-pos=\"all\" data-has-bg-color=\"false\" data-bg-color=\"\" data-bg-opacity=\"1\" data-animation=\"\" data-delay=\"0\">\n<div class=\"vc_column-inner\">\n<div class=\"wpb_wrapper\">\n<div class=\"nectar-split-heading \" data-align=\"default\" data-m-align=\"inherit\" data-text-effect=\"none\" data-animation-type=\"line-reveal-by-space\" data-animation-delay=\"0\" data-animation-offset=\"\" data-m-rm-animation=\"\" data-stagger=\"\" data-custom-font-size=\"false\">\n<h3>Need Help? Get in Touch<\/h3>\n<\/div>\n<div class=\"divider-wrap\" data-alignment=\"default\">\n<div style=\"margin-top: 12.5px;height: 3px;margin-bottom: 12.5px\" data-width=\"100%\" data-animate=\"\" data-animation-delay=\"\" data-color=\"default\" class=\"divider-border\"><\/div>\n<\/div>\n<div class=\"wpb_text_column wpb_content_element \">\n<div class=\"wpb_wrapper\">\n<p>If you have any questions about these issues or need help checking your account, please raise a support ticket via the Customer Area at heartinternet.uk, or use live chat, available Monday to Friday, 09:30 to 16:00. You can also find more guidance in our knowledge base at heartinternet.uk\/support. We&#8217;re here to help if you&#8217;re not sure whether any of this affects you.<\/p>\n<\/p><\/div>\n<\/div><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/div>\n<\/div><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/div>\n<\/div>\n<p>The post <a href=\"https:\/\/www.heartinternet.uk\/blog\/weekly-cybersecurity-summary-11-september-to-17-september-2026\/\">Weekly Cybersecurity Summary &#8211; 11 September to 17 September 2026<\/a> appeared first on <a href=\"https:\/\/www.heartinternet.uk\/blog\">Heart Internet<\/a>.<\/p>\n\n","protected":false},"excerpt":{"rendered":"<p>The Heart Internet Team are aware of several security issues affecting web hosting infrastructure this week, and we want to help customers understand what they mean, who may be affected, and what sensible steps to take. This week we&#8217;re covering four issues: two critical command injection flaws in a firewall tool used on a large [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":7063636,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[95],"tags":[15439,4968,4028,6039],"dealstore":[],"offerexpiration":[],"class_list":["post-7063635","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-internet-business","tag-cybersecurity","tag-september","tag-summary","tag-weekly"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v26.4 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Weekly Cybersecurity Summary \u2013 11 September to 17 September 2026 - Som2ny Network<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/fivemor.com\/?p=7063635\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Weekly Cybersecurity Summary \u2013 11 September to 17 September 2026 - Som2ny Network\" \/>\n<meta property=\"og:description\" content=\"The Heart Internet Team are aware of several security issues affecting web hosting infrastructure this week, and we want to help customers understand what they mean, who may be affected, and what sensible steps to take. This week we&#8217;re covering four issues: two critical command injection flaws in a firewall tool used on a large [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/fivemor.com\/?p=7063635\" \/>\n<meta property=\"og:site_name\" content=\"Som2ny Network\" \/>\n<meta property=\"article:published_time\" content=\"2026-09-22T02:59:12+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/fivemor.com\/wp-content\/uploads\/2026\/09\/cybersecurity-1.webp.webp\" \/>\n\t<meta property=\"og:image:width\" content=\"2000\" \/>\n\t<meta property=\"og:image:height\" content=\"1181\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/webp\" \/>\n<meta name=\"author\" content=\"admin\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"admin\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"7 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/fivemor.com\/?p=7063635#article\",\"isPartOf\":{\"@id\":\"https:\/\/fivemor.com\/?p=7063635\"},\"author\":{\"name\":\"admin\",\"@id\":\"https:\/\/fivemor.com\/#\/schema\/person\/b85e3c3dc0e1daea076524dc8810c371\"},\"headline\":\"Weekly Cybersecurity Summary \u2013 11 September to 17 September 2026\",\"datePublished\":\"2026-09-22T02:59:12+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/fivemor.com\/?p=7063635\"},\"wordCount\":1503,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\/\/fivemor.com\/#organization\"},\"image\":{\"@id\":\"https:\/\/fivemor.com\/?p=7063635#primaryimage\"},\"thumbnailUrl\":\"https:\/\/fivemor.com\/wp-content\/uploads\/2026\/09\/cybersecurity-1.webp.webp\",\"keywords\":[\"Cybersecurity\",\"September\",\"Summary\",\"Weekly\"],\"articleSection\":[\"Internet Business\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\/\/fivemor.com\/?p=7063635#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/fivemor.com\/?p=7063635\",\"url\":\"https:\/\/fivemor.com\/?p=7063635\",\"name\":\"Weekly Cybersecurity Summary \u2013 11 September to 17 September 2026 - Som2ny Network\",\"isPartOf\":{\"@id\":\"https:\/\/fivemor.com\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/fivemor.com\/?p=7063635#primaryimage\"},\"image\":{\"@id\":\"https:\/\/fivemor.com\/?p=7063635#primaryimage\"},\"thumbnailUrl\":\"https:\/\/fivemor.com\/wp-content\/uploads\/2026\/09\/cybersecurity-1.webp.webp\",\"datePublished\":\"2026-09-22T02:59:12+00:00\",\"breadcrumb\":{\"@id\":\"https:\/\/fivemor.com\/?p=7063635#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/fivemor.com\/?p=7063635\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/fivemor.com\/?p=7063635#primaryimage\",\"url\":\"https:\/\/fivemor.com\/wp-content\/uploads\/2026\/09\/cybersecurity-1.webp.webp\",\"contentUrl\":\"https:\/\/fivemor.com\/wp-content\/uploads\/2026\/09\/cybersecurity-1.webp.webp\",\"width\":2000,\"height\":1181},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/fivemor.com\/?p=7063635#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/fivemor.com\/?bp_activities=1\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Weekly Cybersecurity Summary \u2013 11 September to 17 September 2026\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/fivemor.com\/#website\",\"url\":\"https:\/\/fivemor.com\/\",\"name\":\"Som2ny Network\",\"description\":\"Daily Deals\",\"publisher\":{\"@id\":\"https:\/\/fivemor.com\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/fivemor.com\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/fivemor.com\/#organization\",\"name\":\"Som2ny Network\",\"url\":\"https:\/\/fivemor.com\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/fivemor.com\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/fivemor.com\/wp-content\/uploads\/2026\/07\/4a0953c4-logo-300x86-1.png\",\"contentUrl\":\"https:\/\/fivemor.com\/wp-content\/uploads\/2026\/07\/4a0953c4-logo-300x86-1.png\",\"width\":300,\"height\":86,\"caption\":\"Som2ny Network\"},\"image\":{\"@id\":\"https:\/\/fivemor.com\/#\/schema\/logo\/image\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\/\/fivemor.com\/#\/schema\/person\/b85e3c3dc0e1daea076524dc8810c371\",\"name\":\"admin\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/fivemor.com\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/729ae85bf62b9917e93538db2f2688ca?s=96&r=g&default=https%3A%2F%2Ffivemor.com%2Fwp-content%2Fplugins%2Fbuddypress-first-letter-avatar%2Fimages%2Fdefault%2F96%2Flatin_a.png\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/729ae85bf62b9917e93538db2f2688ca?s=96&r=g&default=https%3A%2F%2Ffivemor.com%2Fwp-content%2Fplugins%2Fbuddypress-first-letter-avatar%2Fimages%2Fdefault%2F96%2Flatin_a.png\",\"caption\":\"admin\"},\"sameAs\":[\"https:\/\/fivemor.com\"],\"url\":\"https:\/\/fivemor.com\/?author=1\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Weekly Cybersecurity Summary \u2013 11 September to 17 September 2026 - Som2ny Network","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/fivemor.com\/?p=7063635","og_locale":"en_US","og_type":"article","og_title":"Weekly Cybersecurity Summary \u2013 11 September to 17 September 2026 - Som2ny Network","og_description":"The Heart Internet Team are aware of several security issues affecting web hosting infrastructure this week, and we want to help customers understand what they mean, who may be affected, and what sensible steps to take. This week we&#8217;re covering four issues: two critical command injection flaws in a firewall tool used on a large [&hellip;]","og_url":"https:\/\/fivemor.com\/?p=7063635","og_site_name":"Som2ny Network","article_published_time":"2026-09-22T02:59:12+00:00","og_image":[{"width":2000,"height":1181,"url":"https:\/\/fivemor.com\/wp-content\/uploads\/2026\/09\/cybersecurity-1.webp.webp","type":"image\/webp"}],"author":"admin","twitter_card":"summary_large_image","twitter_misc":{"Written by":"admin","Est. reading time":"7 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/fivemor.com\/?p=7063635#article","isPartOf":{"@id":"https:\/\/fivemor.com\/?p=7063635"},"author":{"name":"admin","@id":"https:\/\/fivemor.com\/#\/schema\/person\/b85e3c3dc0e1daea076524dc8810c371"},"headline":"Weekly Cybersecurity Summary \u2013 11 September to 17 September 2026","datePublished":"2026-09-22T02:59:12+00:00","mainEntityOfPage":{"@id":"https:\/\/fivemor.com\/?p=7063635"},"wordCount":1503,"commentCount":0,"publisher":{"@id":"https:\/\/fivemor.com\/#organization"},"image":{"@id":"https:\/\/fivemor.com\/?p=7063635#primaryimage"},"thumbnailUrl":"https:\/\/fivemor.com\/wp-content\/uploads\/2026\/09\/cybersecurity-1.webp.webp","keywords":["Cybersecurity","September","Summary","Weekly"],"articleSection":["Internet Business"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/fivemor.com\/?p=7063635#respond"]}]},{"@type":"WebPage","@id":"https:\/\/fivemor.com\/?p=7063635","url":"https:\/\/fivemor.com\/?p=7063635","name":"Weekly Cybersecurity Summary \u2013 11 September to 17 September 2026 - Som2ny Network","isPartOf":{"@id":"https:\/\/fivemor.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/fivemor.com\/?p=7063635#primaryimage"},"image":{"@id":"https:\/\/fivemor.com\/?p=7063635#primaryimage"},"thumbnailUrl":"https:\/\/fivemor.com\/wp-content\/uploads\/2026\/09\/cybersecurity-1.webp.webp","datePublished":"2026-09-22T02:59:12+00:00","breadcrumb":{"@id":"https:\/\/fivemor.com\/?p=7063635#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/fivemor.com\/?p=7063635"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/fivemor.com\/?p=7063635#primaryimage","url":"https:\/\/fivemor.com\/wp-content\/uploads\/2026\/09\/cybersecurity-1.webp.webp","contentUrl":"https:\/\/fivemor.com\/wp-content\/uploads\/2026\/09\/cybersecurity-1.webp.webp","width":2000,"height":1181},{"@type":"BreadcrumbList","@id":"https:\/\/fivemor.com\/?p=7063635#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/fivemor.com\/?bp_activities=1"},{"@type":"ListItem","position":2,"name":"Weekly Cybersecurity Summary \u2013 11 September to 17 September 2026"}]},{"@type":"WebSite","@id":"https:\/\/fivemor.com\/#website","url":"https:\/\/fivemor.com\/","name":"Som2ny Network","description":"Daily Deals","publisher":{"@id":"https:\/\/fivemor.com\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/fivemor.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/fivemor.com\/#organization","name":"Som2ny Network","url":"https:\/\/fivemor.com\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/fivemor.com\/#\/schema\/logo\/image\/","url":"https:\/\/fivemor.com\/wp-content\/uploads\/2026\/07\/4a0953c4-logo-300x86-1.png","contentUrl":"https:\/\/fivemor.com\/wp-content\/uploads\/2026\/07\/4a0953c4-logo-300x86-1.png","width":300,"height":86,"caption":"Som2ny Network"},"image":{"@id":"https:\/\/fivemor.com\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/fivemor.com\/#\/schema\/person\/b85e3c3dc0e1daea076524dc8810c371","name":"admin","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/fivemor.com\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/729ae85bf62b9917e93538db2f2688ca?s=96&r=g&default=https%3A%2F%2Ffivemor.com%2Fwp-content%2Fplugins%2Fbuddypress-first-letter-avatar%2Fimages%2Fdefault%2F96%2Flatin_a.png","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/729ae85bf62b9917e93538db2f2688ca?s=96&r=g&default=https%3A%2F%2Ffivemor.com%2Fwp-content%2Fplugins%2Fbuddypress-first-letter-avatar%2Fimages%2Fdefault%2F96%2Flatin_a.png","caption":"admin"},"sameAs":["https:\/\/fivemor.com"],"url":"https:\/\/fivemor.com\/?author=1"}]}},"_links":{"self":[{"href":"https:\/\/fivemor.com\/index.php?rest_route=\/wp\/v2\/posts\/7063635","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/fivemor.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/fivemor.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/fivemor.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/fivemor.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=7063635"}],"version-history":[{"count":0,"href":"https:\/\/fivemor.com\/index.php?rest_route=\/wp\/v2\/posts\/7063635\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/fivemor.com\/index.php?rest_route=\/wp\/v2\/media\/7063636"}],"wp:attachment":[{"href":"https:\/\/fivemor.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=7063635"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/fivemor.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=7063635"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/fivemor.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=7063635"},{"taxonomy":"dealstore","embeddable":true,"href":"https:\/\/fivemor.com\/index.php?rest_route=%2Fwp%2Fv2%2Fdealstore&post=7063635"},{"taxonomy":"offerexpiration","embeddable":true,"href":"https:\/\/fivemor.com\/index.php?rest_route=%2Fwp%2Fv2%2Fofferexpiration&post=7063635"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}