Back to Security Advisories
More Information
Medium
2026-04-09
Security Advisory: Imunify360 Quarantine Bypass via Symlink
Imunify360
AlmaLinux 8
AlmaLinux 9
CentOS 7
CloudLinux 8
CloudLinux 9
Ubuntu 20.04
Ubuntu 22.04
A symlink placed inside the quarantine directory is followed by the cleanup job, allowing a compromised account to redirect removal operations to arbitrary files.
Affected Versions
Imunify360 6.12 and earlier
Patched Version
Imunify360 6.13
Default Update CMD
yum update -y
Fix Commands
AlmaLinux 9 / CloudLinux 9
yum update imunify360-antivirus /usr/share/immuni360/imunify360-update
AlmaLinux 8 / CloudLinux 8
yum update imunify360-antivirus /usr/share/immuni360/imunify360-update
CentOS 7 / CloudLinux 7
yum update imunify360-antivirus /usr/share/immuni360/imunify360-update
Ubuntu 22.04
apt update apt upgrade imunify360-antivirus
Ubuntu 20.04
apt update apt upgrade imunify360-antivirus
Check your system for vulnerabilities
Select your product and operating system to see the exact fix commands that apply to you.
Check Your System