ConfigServer Firewall (CSF) software vulnerability

A vulnerability was found in the MESSENGER service in the ConfigServer Firewall (CSF) software which could allow for unauthorized code execution.

This has a public CVE record listed with further information: CVE-2026-67402

Webpros/cPanel have an update for their version.

Anyone else:

  1. Access the server as the root user via SSH, or the Terminal

  2. Edit the CSF configuration file:

    nano /etc/csf/csf.conf

  3. Update the MESSENGERV3 option to be disabled:

    MESSENGERV3 = 0

  4. Save and restart the CSF and LFD services.

I went on there Discord (link here ConfigServer Firewall - ConfigServer Security & Firewall) and they should be pushing a fix soon by the chatter today.
Webpros/Cpanel version is a different fork.