CVE-2026-93698 and CVE-2026-93697: Security Updates for cPanel and WP Squared

This text was generated using artificial intelligence (AI).Security updates for two critically rated vulnerabilities are available for cPanel and WP Squared. CVE-2026-93698 affects the Multilang-Adminbin in cPanel and has a CVSS score of 9.9. CVE-2026-93697 affects the WHM interface „Mass Modify Accounts“ and has a CVSS score of 9.0.

The security updates were provided on September 29, 2026 The disclosure of the two CVEs occurred on October 2, 2026. An active exploitation has not been publicly documented so far; CVE-2026-93698 is not listed in the CISA KEV catalog. Organizations should first determine which cPanel and WP-Squared instances are affected and whether the required minimum builds have been installed.

Are my systems affected? Check now →