CVE-2026-65638
A flaw in ConfigServer Security & Firewall lets anyone on the network run commands as the CSF service account. The issue is caused by improper URL escaping that allows shell command injection. Updating to the latest version fixes the problem.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
ConfigServer Security & Firewall (CSF) versions before 16.30, including the WebPros-maintained fork. Other forks or independently maintained versions may also be affected.
Real-world impact
An attacker can execute any command on the server with the privileges of the CSF service account, potentially taking full control of the machine.
Why this severity
The CVSS score of 9.2 reflects that the vulnerability is easy to exploit (low attack complexity), requires no authentication, and gives an attacker complete control over the system, compromising confidentiality, integrity, and availability.
What to do about it
- 01Upgrade ConfigServer Security & Firewall to version 16.30 or later.
NVD-referenced vendor advisory
Timeline
- Sep 10, 2026 · 3d agoPublishedDisclosed and added to the National Vulnerability Database.
- Sep 10, 2026 · 3d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.