惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

G
Google Developers Blog
GbyAI
GbyAI
Y
Y Combinator Blog
The GitHub Blog
The GitHub Blog
B
Blog
博客园 - 叶小钗
V
Visual Studio Blog
小众软件
小众软件
阮一峰的网络日志
阮一峰的网络日志
博客园 - 聂微东
S
SegmentFault 最新的问题
Engineering at Meta
Engineering at Meta
博客园 - Franky
V
V2EX
人人都是产品经理
人人都是产品经理
H
Hackread – Cybersecurity News, Data Breaches, AI and More
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
月光博客
月光博客
IT之家
IT之家
T
The Blog of Author Tim Ferriss
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
C
Check Point Blog
N
Netflix TechBlog - Medium
博客园 - 【当耐特】

Cyber Security News

AIRecon: AI-Powered Penetration Testing Tool with Kali Linux Sandbox Critical Chrome Vulnerabilities Allow Attackers to Execute Arbitrary Code - Update Now! UNC3753 Uses Screen-Sharing Sessions and RMM Tools to Exfiltrate Sensitive Legal Data New OnionDrop Loader Campaign Uses gainmsg C2 to Deliver LegionLoader Payloads ClickFix Campaign Uses EtherHiding and GULoader to Infect Windows Users via Fake CAPTCHA Ghostwriter Hackers Abuse Gmail Admin-Themed Emails to Steal Credentials and 2FA Codes The Half-Life of Threat Intelligence: When Does an IOC Stop Being Useful? Critical Fortinet FortiSandbox Vulnerabilities Actively Exploited in Attacks Aembit Extends IAM for Agentic AI to Microsoft Copilot Studio India Temporarily Bans Telegram Messenger Over Medical Exam Fraud Microsoft 365 Device Code Phishing Campaign Bypasses Password Theft With Legitimate Login Flow AppViewX Launches Agent Identity Security to Govern Agents for the AI and Quantum Era Hackers Weaponize Microsoft Teams Relay to Hide Ransomware Traffic Developer laptops are the credential store attackers are picking through in 2026, GitGuardian announces Endpoint Protection Interlock and Rhysida Ransomware Operations Share Supper Backdoor and Malware Codebase Novo Nordisk Confirms Cyber Attack — Hackers Accessed Patient Medical Data and Internal AI Assets Russian and Chinese Influence Actors Use AI to Evade Bot Detection and Mimic Human Behavior Microsoft Teams Analyze the Wi-Fi Hotspot Data Connected to an Employee’s Device PRC-Nexus Hackers Exploit REDCap Servers to Spy on US Medical Research Institutions Infinite Campus Data Breach Exposes 137,000 Users Personal Details OptinMonster Plugin Hack Exposes 1.2 Million Wordpress Sites to Cyberattack Ransomware Ecosystem Consolidates Around LockBit Alumni, Qilin, Hyflock, and The Gentlemen Hackers Abuse Legitimate RMM Tools in The Quarry IRS and SSA Phishing Campaigns LiteSpeed cPanel Plugin 0-Day Vulnerability Actively Exploited in the Wild Cisco SD-WAN vManage Vulnerability Exploited in Zero-Day Attacks Nearly 14,000 SimpleHelp Servers Exposed Amid Critical Authentication Bypass Disclosure Microsoft Site Showing Warning Following Certificate Expiry DPAPISnoop Tool Extracts CREDHIST Hashes for Offline Windows Credential Recovery SHADOWBYT3$ Allegedly Claim Breach of Nintendo, Stealing Sensitive Data Anthropic Updated Privacy Policy to Include Identity Verification for Claude Users
Critical Webmin Vulnerabilities Allow Attackers to Impers...
Abinaya · 2026-06-24 · via Cyber Security News

Critical security flaws in Webmin have exposed systems to severe risks, allowing attackers to impersonate users, bypass authentication, and gain root-level control across affected environments.

Webmin, a widely used web-based system administration tool for Unix-like systems, has disclosed multiple vulnerabilities affecting versions before 2.641.

These issues range from stored cross-site scripting (XSS) to privilege escalation and authentication bypass flaws, significantly increasing the attack surface for both remote and insider threats.

Webmin Vulnerabilities

One of the most critical issues, tracked as CVE-2026-22678, is a stored XSS vulnerability in the System and Server Status module.

An attacker with limited Webmin access can inject malicious scripts into notification templates. When viewed by an administrator, the payload executes in the context of the root user, enabling full system compromise.

Another high-risk vulnerability involves privilege escalation via the built-in Help feature in versions before 2.640.

This flaw allows untrusted users to execute arbitrary commands with root privileges, regardless of their assigned module permissions. This effectively breaks Webmin’s access control model.

In addition, multiple vulnerabilities in the Read User Mail module further expand the scope of exploitation.

CVE-2026-49102 enables XSS via malicious SVG email attachments, while CVE-2026-49103 allows file overwrites due to unsafe filename handling when detaching email attachments. These issues can be chained to achieve persistent compromise.

Critically, Webmin also suffers from a two-factor authentication bypass (CVE-2026-42210 and CVE-2026-56022). Attackers can bypass 2FA protections by using HTTP Basic Authentication instead of the standard session-based login.

Although valid credentials are still required, this flaw undermines a key security control designed to prevent account takeover. Earlier versions of Webmin are also affected by several severe vulnerabilities.

These include command execution via the Squid module (CVE-2025-67738), host header injection in password reset functionality (CVE-2025-61541), and SSL trust misconfigurations allowing attackers to spoof client certificates (CVE-2026-56020).

For example, an attacker with limited Webmin access could exploit the Help feature to gain root privileges, then leverage the 2FA bypass to maintain unauthorized access even on hardened accounts, effectively impersonating legitimate administrators.

Security researchers from multiple organizations, including TIM Security Red Team and independent contributors, have reported these issues, highlighting ongoing risks in widely deployed administrative tools.

Users are strongly advised to upgrade to the latest Webmin version immediately. Administrators should also turn off unnecessary modules, enforce strict access controls, and avoid granting Webmin access to untrusted users.

Additionally, reviewing authentication mechanisms and disabling Basic Authentication where possible can help mitigate the risk of 2FA bypass.

Organizations relying on Webmin for infrastructure management should treat these vulnerabilities as a high priority, as exploitation could result in a full system takeover, data exposure, and persistent attacker access.

Follow us on Google NewsLinkedIn, and X to Get More Instant Updates.

Abinaya

Abinayahttps://cybersecuritynews.com/

Abi is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.