cPanel disclosed and patched CVE-2026-67401 on September 8, a SQL injection vulnerability in its EmailTrack feature. According to the advisory, an authenticated hosting account holder with mail-related privileges could exploit the flaw to create arbitrary files on the server through EmailTrack, then use that file-creation capability to execute code as the root user, the highest level of system access. The flaw affected every supported release line of cPanel and WHM. cPanel published patched builds for each affected line, including 11.110.0.143, 11.134.0.55, 11.136.0.39, 11.138.0.4 and 11.138.1.9. Because exploitation requires only an authenticated mail-privileged account rather than any special administrative access, the flaw posed particular risk to shared-hosting providers and multi-tenant environments, where a single compromised customer account could have endangered every other customer on the same server. Researchers Ali Mustafa and abed1526 are credited with reporting the vulnerability. As of September 9, no public exploit code or evidence of active exploitation had been reported, and the flaw did not appear in CISA's Known Exploited Vulnerabilities catalog. B2B SaaS companies that rely on shared or reseller hosting for customer-facing infrastructure should confirm their hosting provider has applied the patched cPanel/WHM builds.