CVE-2026-93698 and CVE-2026-93697: Security Updates for cPanel and WP Squared
This text was generated using artificial intelligence (AI).Security updates for two critically rated vulnerabilities are available for cPanel and WP Squared. CVE-2026-93698 affects the Multilang-Adminbin in cPanel and has a CVSS score of 9.9. CVE-2026-93697 affects the WHM interface „Mass Modify Accounts“ and has a CVSS score of 9.0.
The security updates were provided on September 29, 2026 The disclosure of the two CVEs occurred on October 2, 2026. An active exploitation has not been publicly documented so far; CVE-2026-93698 is not listed in the CISA KEV catalog. Organizations should first determine which cPanel and WP-Squared instances are affected and whether the required minimum builds have been installed.
Network access, low privileges, no user interaction
CVE-2026-93697
WHM „Mass Modify Accounts“
CVSS 9.0
Network access, low privileges, user interaction
According to the cPanel Security Advisory for CVE-2026-93698, insufficient validation in the Multilang-Adminbin may allow the execution of arbitrary commands.
CVE-2026-93697 is a stored XSS vulnerability in the WHM function „Mass Modify Accounts“. It could allow the execution of arbitrary code in the affected interface. User interaction is required for this vulnerability.
Affected products and provided minimum builds
Affected are cPanel versions below the following minimum builds:
cPanel Branch 138: 11.138.0.11
cPanel Branch 136: 11.136.0.45
cPanel Branch 134: 11.134.0.61
cPanel Branch 110 LTS: 11.110.0.148
For WP Squared on Branch 138, the minimum build is 11.138.1.13 onwards.
The required cPanel builds are documented in the corresponding changelogs: Branch 138, Branch 136, Branch 134, and Branch 110 LTS. The fix for WP Squared is listed in the WP-Squared changelog.
Check Patch Status Prioritization
The security updates were available prior to the disclosure of the CVEs. Therefore, the examination of patch status takes precedence for operational processing.
A robust prioritization includes, in particular:
Cataloging existing cPanel and WP-Squared instances.
Determining the installed branch and build per instance.
Identifying systems that are still below the provided minimum builds.
Assigning externally reachable cPanel and WHM management interfaces to the responsible teams.
Prioritizing and updating affected systems.
Checking accounts with low administrative permissions in the context of the affected functions.
CVE-2026-93698 and CVE-2026-93697 should be assessed separately. The first vulnerability affects the Multilang-Adminbin and does not require user interaction. The second vulnerability pertains to the WHM function for bulk editing of accounts and requires user interaction.
NIS-2 obligated operators in Germany and Austria using cPanel-based infrastructure should document the review and implementation of updates as part of their patch management duties. Organizations in Switzerland are subject to the revised Information Security Act (ISG) with a reporting obligation to the Federal Office for Cybersecurity (BACS). If there are indications of a compromise of affected systems related to personal data of EU citizens, the reporting obligation under Art. 33 GDPR with a deadline of 72 hours also applies.
Visibility of Externally Reachable cPanel and WHM Systems
For processing, not only the patch status is relevant. Equally important is the question of which cPanel and WHM systems are publicly accessible under their own domains and who is responsible for updates.
LocateRisk supports in External Attack Surface Management to make publicly reachable systems and deployed software visible. This can aid in assigning cPanel and WHM interfaces to responsibilities. LocateRisk does not necessarily identify the specifically vulnerable version; the technical confirmation of the patch status remains a task for the responsible teams.
Additionally, Continuous Vendor Risk Management can classify security-relevant reports from technology providers into supplier assessment. In this case, two evaluation paths are connected: the visibility of one's own publicly reachable cPanel and WHM systems, as well as the assessment of dependency on the manufacturer's products.
Am I affected?
Affected are webpros cpanel and WP Squared in the versions mentioned above; the respective error-corrected releases can be found in the table above. Those who want to know if webpros cpanel and WP Squared are even visible in their own externally reachable infrastructure can check the CVE Quick Check Use the tool at the end of this article: It shows exposed systems and the software that is visible from the outside.
It is not always possible to determine the specific version that has been installed from the outside—the key factor is comparing it with the manufacturer's advisory.
CVE-2026-93698 allows the execution of arbitrary commands without user interaction due to insufficient validation in the Multilang Adminbin. CVE-2026-93697 is a stored XSS vulnerability in the WHM function „Mass Modify Accounts,“ which allows arbitrary code execution but requires user interaction. Both vulnerabilities are rated critical (CVSS 9.9 and 9.0 respectively).
This affects all cPanel instances below builds 11.138.0.11 (Branch 138), 11.136.0.45 (Branch 136), 11.134.0.61 (Branch 134), and 11.110.0.148 (Branch 110 LTS). For WP Squared on Branch 138, build 11.138.1.13 fixes the vulnerabilities. The updates were provided on September 29, 2026.
Until the disclosure on October 2, 2026, no active exploitation was publicly documented; CVE-2026-93698 is not listed in the CISA KEV catalog. The lack of exploit pressure does not change the urgency: the CVSS score of 9.9 for CVE-2026-93698 and the ability to execute arbitrary commands without user interaction warrant prioritization.
Status: October 02, 2026. This post is for general informational purposes and is not legal, security, or action advice in individual cases. The IT security situation and patch availability may have changed since publication; the linked vendor advisory is always authoritative. Despite careful research, we do not guarantee the timeliness, correctness, and completeness.
CVE Quick Check
In just a few minutes, check whether there are any indications of a current CVE on your externally visible attack surface.
A rough estimate in just a few minutes via email.
Learn more during a free consultation with a LocateRisk consultant.
You'll receive this by email
companyYour Company, LLC
Verified CVECVE-2026-93698
Passive Assessment
Information About the CVEfound or not found
Want to find out more, book a demo or simply exchange ideas? We look forward to hearing from you!
We use cookies to optimize our website and our service.
Functional
Always active
Technical storage or access is strictly necessary for the lawful purpose of enabling the use of a particular service expressly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a message over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that have not been requested by the subscriber or user.
Statistics
The technical storage or access, which is carried out exclusively for statistical purposes.Technical storage or access used solely for anonymous statistical purposes. Without a subpoena, the voluntary consent of your Internet service provider, or additional records from third parties, information stored or accessed for this purpose alone generally cannot be used to identify you.
Marketing
Technical storage or access is necessary to create user profiles, to send advertisements, or to track the user on a website or across multiple websites for similar marketing purposes.