securityonline.info 11 Sept 2026, 03:17 UTC

Critical CSF flaws enable server takeover through remote code execution

Critical CSF flaws enable server takeover through remote code execution
CyberSIXT Evidence Panel
CISA KEV Not in KEV
Patch Patch Status Unknown

WEBPROS has issued security updates for ConfigServer Security & Firewall (CSF) addressing two critical flaws, CVE-2026-65638 and CVE-2026-65639, both rated CVSSv4 at 9.5 and 9.2 respectively. The advisories state that the vulnerabilities could allow an attacker to execute arbitrary commands on the compromised system, potentially giving full control of the server.

The issues affect multiple widely deployed releases, with the MESSENGER service vulnerable in versions 14.00 through 16.29 and the advanced-rule parser vulnerable in versions 2.15 through 16.29. Default configurations reportedly disable the affected features, and there is currently no public evidence of in-the-wild exploitation.

CVE-2026-65638 concerns unauthenticated remote execution via the MESSENGER service, where an attacker could send malicious requests to trigger arbitrary command execution as the CSF service account. CVE-2026-65639 exists in the parser that handles allow/deny feeds; if an attacker controls a feed, they can inject malicious rules leading to remote code execution as root. The recommended mitigation is an upgrade to version 16.30 or later.

If immediate patching isn’t possible, administrators should disable the MESSENGER service and audit remote feed configurations, removing feeds that are not fully controlled and trusted. Evidence indicates no exploitation has been publicly confirmed, and no PoC exploits are currently disclosed.

View full article

Article by CyberSIXT