WebPros released security updates addressing two severe flaws. These CSF plugin vulnerabilities enable remote attackers to run arbitrary system commands. Firewall administration requires strict access controls to prevent exploitation. Users must update their installations to secure their servers.
- Product: WebPros ConfigServer Security & Firewall
- Vulnerabilities: 2 flaws (CVE-2026-65638, CVE-2026-65639)
- Highest severity: 9.5 (Critical · CVSSv4)
- Status: No confirmed exploitation yet; patches available
- Action: Update to 16.30 now
| CVE | CVSS (CVSSv4) | Fixed in | Status |
|---|---|---|---|
| CVE-2026-65639 | 9.5 | 16.30 | Not exploited |
| CVE-2026-65638 | 9.2 | 16.30 | Not exploited |
Track every CVE that hits your stack the moment it's exploited.
Get free email alertsWhy This Matters
Web hosting providers rely heavily on the ConfigServer Security and Firewall software to protect Linux servers. A successful attack grants full server control to malicious actors. This deep access allows threat actors to steal sensitive data. Furthermore, they can use compromised servers to launch secondary attacks against other networks.
How the Attack Works
The first flaw, CVE-2026-65638, targets the MESSENGER service. An unauthenticated attacker sends malicious requests to this service. The advisory states it “could allow an unauthenticated remote attacker to execute arbitrary commands as the CSF service account.”
Meanwhile, the second flaw, CVE-2026-65639, exists in the advanced-rule parser. Attackers who control a configured allow or deny feed can inject malicious rules. These rules lead directly to remote code execution as the root user.
Affected Versions
These CSF plugin vulnerabilities impact multiple widely deployed software releases. Specifically, the MESSENGER vulnerability affects versions 14.00 through 16.29. Similarly, the rule parser flaw affects versions 2.15 through 16.29. Thankfully, default configurations disable both vulnerable features. Currently, researchers have confirmed no active in-the-wild exploitation. Likewise, no public proof-of-concept exploit exists for either flaw.
Patch and Mitigation Steps
Administrators must upgrade to version 16.30 or later immediately. You can update using the standard package update scripts. If immediate patching is impossible, you should disable the MESSENGER service manually. Additionally, administrators must review remote feed configurations. They must “remove any feed you do not fully control and trust.”
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!