High SEVERITY — Vulnerability

CVE-2026-32992 — SSL verification is disabled in the DNS Cluster system.

SSL verification is disabled in the DNS Cluster system. This could allow for a malicious server to man-in-the-middle the request and capture credentials.

Platform
cPanel & WHM
CVE Record
CVE-2026-32992
CVSS Score
8.2/10
Published
13 May 2026
Views
22
Primary source: Review the official advisory at nvd.nist.gov Go to Source

Summary

SSL verification is disabled in the DNS Cluster system. This could allow for a malicious server to man-in-the-middle the request and capture credentials.

Assessment

  • CVE: CVE-2026-32992
  • CVSS base score: 8.2
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
  • Source: NVD record

References

Action

  • Verify affected systems against your inventory
  • Apply the vendor patch during a maintenance window
  • Restrict access at the network layer until patched
cpanel * wp squared * whm *

cPanel & WHM — Related Advisories

VIEW ALL →