A critical CentOS Web Panel bug is now under active exploitation, prompting a new alert from the U.S. Cybersecurity and Infrastructure Security Agency. Attackers target exposed servers running outdated versions of the control panel, which powers thousands of Linux-based web hosting environments. CISA added the flaw to its Known Exploited Vulnerabilities catalog and urged administrators to apply updates immediately.
What the Vulnerability Allows
Security researchers reported that the flaw enables remote code execution on affected systems. Attackers send crafted requests that bypass security checks within the control panel. Once they gain access, they execute commands with high privileges and take control of the server.
The vulnerability carries a critical severity rating because it gives attackers direct access to underlying system functions. Successful exploitation lets intruders:
- Install backdoors
- Modify files and databases
- Steal credentials
- Deploy ransomware
- Move deeper into a network
These capabilities make the bug particularly dangerous for hosting providers and administrators who depend on CentOS Web Panel (also known as CWP).
Attacks Already Observed in the Wild
Multiple security teams confirmed that threat actors already exploit the CentOS Web Panel bug. Attackers scan the internet for unpatched systems and launch automated attempts to compromise them. Logs collected by researchers show a wave of requests designed to trigger the vulnerability.
Some servers experienced unauthorized command execution within minutes of exposure. In several cases, administrators noticed unusual processes, new user accounts, and malicious scripts added to the system. These signs suggest coordinated exploitation efforts by threat groups that monitor newly disclosed vulnerabilities.
Why CISA Issued an Urgent Warning
CISA adds vulnerabilities to its catalog only when there is reliable evidence of real-world exploitation. Once listed, all U.S. federal agencies must patch the flaw by the deadline set in the advisory. The agency also encourages private organizations to follow the same requirement due to the risk of full system compromise.
CISA stressed that unpatched CWP systems remain high-value targets. Web hosting servers store sensitive customer data, API keys, configuration files, and operational credentials. Attackers who compromise one system often pivot to other parts of the network.
Patch Availability and Mitigation Steps
The CWP team released a fixed version and advised administrators to update immediately. The control panel does not auto-update by default, which means many installations remain outdated. Administrators should review the version number, apply patches, and check their logs for suspicious activity.
Key recommended actions include:
- Updating to the latest CWP build
- Replacing credentials used on the affected system
- Reviewing logs for unusual authentication attempts
- Blocking unnecessary external access to the panel
- Enabling firewall rules and intrusion detection tools
These steps help limit exposure and reduce the risk of further compromise.
Conclusion
The CentOS Web Panel bug represents a serious threat to organizations running Linux-based hosting environments. Attackers already exploit the flaw to gain full control of vulnerable servers. CISA’s warning highlights the urgency of rapid patching, stronger access controls, and continuous monitoring. Administrators must update immediately and verify the integrity of their systems to prevent further exploitation.


0 responses to “CentOS Web Panel Bug: Why CISA Warns About Active Exploitation”