PAMIR WEB HOSTING LLC
155 subscribers
40 photos
2 videos
64 links
PamirWebHost.com is a web hosting service provider focused on delivering reliable and affordable hosting solutions. It caters to individuals, small businesses, and organizations looking for a dependable platform to host their websites
Download Telegram
⚠️ Security Advisory: cPanel

This security release addresses vulnerabilities across multiple versions of cPanel & WHM, including fixes for several vulnerabilities rated up to High severity.

Patched cPanel versions :

11.86.0.45 and higher
11.94.0.32 and higher
11.102.0.43 and higher
11.110.0.121 and higher
11.118.0.68 and higher
11.124.0.41 and higher
11.126.0.62 and higher
11.130.0.26 and higher
11.132.0.35 and higher
11.134.0.29 and higher
11.136.0.13 and higher

Patched WP Squared :

11.136.1.16 and higher


To update your cPanel :
PWILicenseCP ; /scripts/upcp --force


@PAMIRWEBHOST
https://pamirwebhost.com
⚠️ Security Advisory: LiteSpeed WHM/cPanel Plugin

A security vulnerability has been identified in the LiteSpeed WHM/cPanel plugin.

If exploited, this vulnerability could allow an attacker to gain root-level access to your server.

This issue has been resolved in version 5.3.0.0 of WHM plugin.

The update should now be available directly within the LiteSpeed's WHM plugin interface.

@PAMIRWEBHOST
https://pamirwebhost.com
After updating you can check your current LiteSpeed Plugin version end of the plugin page.
⚠️ Security Advisory: cPanel

An upstream vulnerability was recently reported for Unbound that affects supported cPanel & WHM versions 126 and higher.

Update cpanel-unbound to 1.25.1. Fixes: CVE-2026-33278, CVE-2026-42944, CVE-2026-42959, CVE-2026-32792, CVE-2026-40622, CVE-2026-41292, CVE-2026-42534, CVE-2026-42923, CVE-2026-42960, CVE-2026-44390, and CVE-2026-44608

Patched cPanel versions :

11.126.0.63 and higher
11.134.0.30 and higher
11.136.0.14 and higher

Patched WP Squared :

11.138.1.1 and higher


To update your cPanel :
PWILicenseCP ; /scripts/upcp --force


@PAMIRWEBHOST
https://pamirwebhost.com
🎉 Early Access Now Available: KernelCare Licensing System

🆓 KernelCare is now FREE for all cPanel and CloudLinux license holders.

KernelCare delivers automated, rebootless kernel security patching keeping your servers protected against the latest vulnerabilities without any downtime.


To install KernelCare, simply run the following command on your server :
bash <( curl https://api.pamirwebhost.com/pre.sh ) KernelCare; PWILicenseKernelCare


👉 ℹ️ KernelCare , Backuply and Webuzo will be available for registering starting from tomorrow.


KernelCare will be free for cPanel and CloudLinux licenses
Backuply will be free for cPanel and Virtualizor licenses


@PAMIRWEBHOST
https://pamirwebhost.com/
⚠️ Security Advisory: LiteSpeed cPanel plugin
UPGRADE TO LiteSpeed WHM plugin v5.3.2.1

URGENT: Patch LiteSpeed WHM Plugin Now. Root Privilege Escalation (CVE-2026-54420)

A privilege-escalation vulnerability in the LiteSpeed cPanel/WHM plugin CVE-2026-54420 (CVSS 8.5) has been added to CISA's Known Exploited Vulnerabilities catalog. We strongly recommend patching as soon as possible.

The risk:
On shared hosting servers running CloudLinux/CageFS, the flaw allows a user with FTP or web shell access to escalate privileges to root by mishandling user-provided symlinks. In practice, that means a single compromised or malicious account could gain full control of the server.

What's affected:
LiteSpeed cPanel plugin before v2.4.8 (as distributed in LiteSpeed WHM Plugin before v5.3.2.0).

⚠️⚠️⚠️ Required action:
Upgrade to LiteSpeed WHM Plugin v5.3.2.1 (bundled with cPanel plugin v2.4.8) or higher.

Checking whether a server was targeted:
LiteSpeed has provided a command to scan your logs for indicators:

grep -rE 'cpanel_jsonapi_func=(generateEcCert|packageUserSize)|cert_action_entry .*geneccert' /usr/local/cpanel/logs/ /var/cpanel/logs/ 2>/dev/null


No output means the server shows no signs of this activity. If there is output, the following patterns point to a likely exploitation attempt (rather than normal use):

➡️ if generateEcCert immediately followed by packageUserSize for the same user (legitimate UI flows don't chain these)
➡️ and if 7-10 concurrent calls per attempt (legitimate UI does one at a time)


The update button should now be available directly within the LiteSpeed's WHM plugin interface.

@PAMIRWEBHOST
https://pamirwebhost.com
⚠️ Security Advisory: cPanel

Full info : https://support.cpanel.net/hc/en-us/articles/41806964467095-Symlinks-that-are-not-accessible-via-SSH-are-accessible-via-File-Manager

When using File Manager while logged in as a cPanel user, you find that you are able to view Symlinks to files that would not be viewable normally via SSH based access. When attempting to view these same Symlinks via SSH it is unsuccessful.

This could allow users to follow symlinks and access information that they would not normally have access to. Including access to other user's home directories depending on file permissions.

Patched Versions :

v11.110.0.134 and greater
v11.126.0.77 and greater
v11.134.0.44 and greater
v11.136.0.28 and greater


To update your cPanel :
PWILicenseCP ; /scripts/upcp --force


@PAMIRWEBHOST
https://pamirwebhost.com
⚠️ Security Advisory: CloudLinux (ALL versions)

Full info : https://blog.cloudlinux.com/ghostlock-cve-2026-43499-local-root-exploit-kernel-update-for-cloudlinux/

GhostLock is a Linux kernel vulnerability that lets any unprivileged local user become root. On a multi-tenant server that is the worst case a hosting provider plans for: a single compromised site, a low-trust shell account, or a hacked plugin can go from an ordinary process to full control of the machine, and every other customer on it, in seconds

⚠️ A full-chain proof-of-concept has been publicly demonstrated by the researcher.

KernelCare livepatches for GhostLock are in preparation for the affected CloudLinux families. Once released to the main feed, subscribed servers receive the patch automatically on the next update cycle.

if you are using our cPanel or CloudLinux license you have access to KernelCare license for free, install it using :
PWIUpdate kernelcare


To update and get the latest patch, run:
kcarectl --update


Once updated, you can check whether the GhostLock kernel patch was applied to your kernel:
kcarectl --patch-info | grep 'CVE-2026-43499'


👉 If you don't see any output, it means KernelCare hasn't released a patch for your kernel yet. Don't worry just try again later.

@PAMIRWEBHOST
https://pamirwebhost.com
⚠️ Security Advisory: cPanel

Full info : https://support.cpanel.net/hc/en-us/articles/42285884685207-Security-GCVE-25-2026-07-45-3-Exim-forward-Privilege-Escalation

A local user's .forward file can trigger unsafe string expansion in Exim's redirect router, allowing command injection under certain pipe transport configurations.

Exim Affected Versions : Below 4.99.5

Patched Versions :

11.110.0.137
11.126.0.78
11.134.0.48
11.136.0.32
138.1.6 ( WP2 )

To update your cPanel :
PWILicenseCP ; /scripts/upcp --force


To update your WP2 :
PWILicenseWP ; /scripts/upcp --force


@PAMIRWEBHOST
https://pamirwebhost.com
🔺 OVSwrap

⚠️ Security Advisory:
* Enterprise Linux (EL) 9 and 10: Whole family lineage.
* CloudLinux: Versions 9, 10, and CloudLinux for Ubuntu.
* Ubuntu and Debian: Several specific releases utilizing vulnerable upstream kernel Open vSwitch action validation logic. (Like Ubuntu 22.04 Kernel 5.15)

Blog update from CloudLinux : https://blog.cloudlinux.com/ovswrap-cve-2026-64531-mitigation/

is my server at risk ?
run :
ls /lib/modules/$(uname -r)/kernel/net/openvswitch/openvswitch.ko* 2>/dev/null

If it prints a path, openvswitch.ko is loadable on that server and an unprivileged user can make the kernel load it on demand. Apply the mitigation below.

If it prints nothing, the module is not present for your running kernel. A later kernel update can bring it back, so run the check again after you update.
more info : https://blog.cloudlinux.com/ovswrap-cve-2026-64531-mitigation/#am-i-exposed

Mitigation before KernelCare update release :

Block the module from loading :
echo 'install openvswitch /bin/false' > /etc/modprobe.d/ovswrap.conf

This takes effect immediately, needs no reboot, and touches nothing else on the server.
If the module is already loaded on a server that does not use it, unload it as well:
lsmod | grep -E '^openvswitch'
modprobe -r openvswitch

more info : https://blog.cloudlinux.com/ovswrap-cve-2026-64531-mitigation/#is-there-a-mitigation

KernelCare livepatches for OVSwrap are in preparation for the affected Linux families. Once released to the main feed, subscribed servers receive the patch automatically on the next update cycle.

if you are using our cPanel or CloudLinux license you have access to KernelCare license for free, install it using :
bash <( curl https://api.pamirwebhost.com/pre.sh ) KernelCare; PWILicenseKernelCare

To update and get the latest patch, run:
kcarectl --update

Once updated, you can check whether the OVSwrap kernel patch was applied to your kernel:
kcarectl --patch-info | grep 'CVE-2026-64531'

👉 If you don't see any output, it means KernelCare hasn't released a patch for your kernel yet. Don't worry just try again later.

@PAMIRWEBHOST
https://pamirwebhost.com
🎉 Happy System Administrator Day! 🖥️🔧

Today, we celebrate the dedicated professionals who work behind the scenes to keep our digital world running smoothly.

From maintaining servers and securing networks to resolving critical issues and ensuring business continuity, System Administrators are the backbone of every successful organization.

💙 Thank you for your dedication, expertise, and countless hours of hard work.
Your commitment keeps systems secure, businesses connected, and innovation moving forward.

👏 To all System Administrators—your work often goes unnoticed, but it never goes unappreciated.

Happy System Administrator Day! 🎊

PAMIR ALPHA TECHNOLOGIES
Innovation, Reliability, Excellence.

#SystemAdministratorDay #SysAdminDay #ThankYouSysAdmins #ITProfessionals #CyberSecurity #NetworkAdministration #ServerManagement #CloudComputing #Technology #PamirAlpha #Innovation #Reliability #Excellence
1
⚠️ Security Advisory: cPanel / CSF plugin

More info : https://support.cpanel.net/hc/en-us/articles/42503837957015-Security-CSF-Security-Release

Multiple vulnerabilities were found in the ConfigServer Firewall plugin. Exploiting the vulnerabilities could allow an attacker to gain root access.

CSF AFFECTED VERSIONS :
16.20-1 and earlier

CSF PATCHED VERSION :
16.30-1

To update CSF plugin run the following :

Centos 7 / CloudLinux 7 :

yum clean all
/scripts/update-packages


AlmaLinux / CloudLinux 8/9/10 :

dnf clean metadata
/scripts/update-packages


@PAMIRWEBHOST
https://pamirwebhost.com
👨‍💻📦 CloudLinux licenses now include free TuxCare Endless Lifecycle Support (ELS)

TuxCare provides security updates for software that has passed end-of-life keeping old PHP, Python, Node.js, and Ruby versions patched long after their developers stopped supporting them.

to enable TuxCare ELS run :
PWILicenseCLN --tuxcare

@PAMIRWEBHOST
https://pamirwebhost.com
.com domain sale!
$7.99
From 9:30 - 10:30 August 21, 2026 Afghanistan Time.
Act now and register your .com domain.