Back to Security Advisories
Low 2026-06-25

Security Advisory: CSF Firewall Port Rule Race Condition

CSF AlmaLinux 8 AlmaLinux 9 CentOS 7 CloudLinux 7 CloudLinux 8 CloudLinux 9

Under heavy connection churn, CSF may briefly drop an active port rule before the reload completes, exposing SSH briefly on default configurations.

Affected Versions

CSF 14.20 and earlier

Patched Version

CSF 14.21

Default Update CMD

yum update -y

Fix Commands

AlmaLinux 9 / CloudLinux 9

cd /etc/csf
csf -u
csf -r

AlmaLinux 8 / CloudLinux 8

cd /etc/csf
csf -u
csf -r

CentOS 7 / CloudLinux 7

cd /etc/csf
csf -u
csf -r
More Information

Check your system for vulnerabilities

Select your product and operating system to see the exact fix commands that apply to you.

Check Your System