Blog & News
Latest updates, feature announcements, and security news from Panelica.
Fragnesia (CVE-2026-46300): What Panelica Users Need to Know
CVE-2026-46300 (CVSS 7.8) is a Linux kernel local privilege escalation. Panelica itself is not affected. For most users, apt update && apt upgrade and a reboot is all that is needed. Here is what to check and when to act sooner.
Read MoreMay 2026 Hosting Panel Security Crisis: cPanel, WHMCS, Plesk, DirectAdmin, and CyberPanel
Nine CVEs, 44,000 compromised IPs, active ransomware, and cross-customer billing data exposure -- the full May 2026 security breakdown across every major hosting panel and billing platform, with per-audience action plans.
Read MoreThe AI Cyber Arms Race Is Here: What Claude Mythos Means for Your Servers
Anthropic's Claude Mythos can find zero-days autonomously. Chinese models are 6-12 months behind. Here is why the hosting industry is unprepared and how Panelica is built for this threat era.
Read MoreTwo Critical Vulnerabilities This Week: nginx RCE (CVE-2026-42945) and Fragnesia Kernel LPE (CVE-2026-46300)
CVE-2026-42945 brings a heap buffer overflow to every nginx version since 2008 -- PoC is public, patch today. CVE-2026-46300 (Fragnesia) is an ESP-in-TCP kernel LPE. Grep-verified Panelica exposure map, AppArmor containment analysis, AI discovery context, and operator action plan for both.
Read MoreCVE-2026-43284 Dirty Frag: One-Command Root on Every Linux Server Built Since 2017
Dirty Frag (CVE-2026-43284, CVE-2026-43500) lets any unprivileged user gain root on Linux. Patched versions, mitigation, and KernelCare guidance inside.
Read MorecPanel's 30-Day Security Storm: 44,000 Servers, 70M Domains, Two Emergency TSRs
Inside cPanel's 30-day security storm: CVE-2026-41940, 44,000 compromised servers, the .sorry ransomware wave, and what the May 8, 2026 TSR signals.
Read MorecPanel Pre-Discloses Three New CVEs (CVE-2026-29201, 29202, 29203) — Second Emergency TSR in 10 Days
cPanel pre-disclosed three new CVEs ahead of the May 8, 2026 patch — the second emergency TSR in 10 days after CVE-2026-41940. Affected versions, /scripts/upcp guidance, and what hosters must do now.
Read MoreInside CVE-2026-41940: The cPanel Vulnerability Behind the .sorry Ransomware Campaign
CVE-2026-41940 (CVSS 9.8) has been actively exploited since February 2026. This technical breakdown covers the CRLF injection chain, .sorry ransomware file format forensics, a verified YARA rule, IOC pack, and a 10-step incident response playbook.
Read MoreCVE-2026-31431 (Copy Fail): The 9-Year-Old Linux Kernel Flaw Affecting CloudLinux, Ubuntu, RHEL and Beyond
CVE-2026-31431 Copy Fail is a Linux kernel privilege escalation affecting CloudLinux, Ubuntu, RHEL, Debian and SUSE since 2017. Full mitigation guide, technical analysis and what hosting operators must do.
Read MorecPanel Auth Bypass Crisis (CVE-2026-41940): Why Panelica Customers Are Not Affected
A CVSS 9.8 authentication bypass in cPanel (CVE-2026-41940) exposed the entire hosting industry. Here is a technical breakdown of the exploit and why Panelica\u2019s architecture makes this class of attack structurally impossible.
Read MoreThe MySQL 9.7 cPanel Meltdown: Why Upstream Trust Without Guardrails Breaks Production
On April 21, 2026, a MySQL repository metadata bug caused thousands of cPanel servers to silently upgrade to MySQL 9.7 overnight. Here is what happened, why cPanel servers had no structural defense, and how Panelica's build pipeline prevents this class of failure.
Read MorePlesk Vulnerability History: Why Security-Conscious Admins Are Switching
An honest review of Plesk security vulnerabilities including CVE-2025-66431 root code execution and CVE-2025-66430 Apache injection. Compares panel security architectures and how Panelica five-layer isolation reduces attack surface.
Read More