Security: CSF Security Release – September 3rd, 2026
A vulnerability was found in the MESSENGER service in the ConfigServer Firewall (CSF) software which could allow for unauthorized code execution.
Default Update CMD
cd /usr/src && rm -f csf.tgz && wget https://download.configserver.com/csf.tgz && tar -xzf csf.tgz && cd csf && sh install.sh && csf -r
Fix Commands
EL7 (CentOS/CloudLinux 7)
sudo yum update
EL8+ (AlmaLinux/CloudLinux/Rocky)
sudo dnf update
What this means under a SharedLicense license
Your SharedLicense license itself is not affected — this is a change in cPanel & WHM software, not in licensing. Reinstall CSF from the latest ConfigServer package (csf.tgz) and run csf -r. Licenses keep working through updates; nothing needs re-issuing or re-activating.
Situation
A vulnerability was found in the MESSENGER service in the ConfigServer Firewall (CSF) software which could allow for unauthorized code execution.
This has a public CVE record listed with further information: CVE-2026-67402
Note: By default, the MESSENGER service is disabled.
Affected Product versions
| Product | Affected Versions | Patched Versions |
|---|---|---|
| CSF | 16.30-1 and older | 16.31+ |
Impact
Exploiting this could allow an attacker to execute code as the Apache user.
Call to action
Update to the latest version of the ConfigServer Firewall plugin:
CentOS 7/CloudLinux 7
# yum clean all
# /scripts/update-packages
AlmaLinux/CloudLinux 8/9/10
# dnf clean all
# /scripts/update-packages
Ubuntu
# apt update
# /scripts/update-packages
Mitigation
It is highly recommended that you update the installed CSF version as soon as possible.
If this is not possible, you can disable the MESSENGERV3 setting in CSF.
- Access the server as the
rootuser via SSH, or the Terminal in WHM. -
Edit the CSF configuration file:
# nano /etc/csf/csf.conf
-
Update the
MESSENGERV3option to be disabled:CONFIG_TEXT: MESSENGERV3 = 0
-
Save and restart the CSF and LFD services:
# systemctl restart csf lfd
References
Check your system for vulnerabilities
Select your product and operating system to see the exact fix commands that apply to you.
Check Your System