Howdy, Stranger!

It looks like you're new here. If you want to get involved, click one of these buttons!


Shells Virtual Desktop
BMail.ag - Secure Email Service
Server.net
CPLicense.net
VPS Server
Buy VPN
Vultr
VMs for AI
HostDare
HostDare
ReliableSite White-Label Dedicated Hosting for Resellers
InterServer VPS
BMail.ag - Secure Email Service
Best VPN
High-Performance Bare Metal Server Solutions
Karvl.com
Server Mania Cloud Hosting
DataWagon Hosting
AlphaVPS Hosting
Evoxt.com
Clouvider
VPS Hosting with NVMe
Residential IPs in the US & 4G Mobile Proxies in EU & US with Unlimited Bandwidth
ReliableSite White-Label Dedicated Hosting for Resellers
Rabisu - Hosting Solutions
Shells Virtual Desktop
New on LowEndTalk? Please Register and read our Community Rules.

All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.

HestiaCP servers are actively being exploited

HestiaCP servers are actively being exploited. If you have web terminal enabled check for IOCs. Surprisingly they didn't mention this on their latest release notes.

https://nvd.nist.gov/vuln/detail/CVE-2026-43634

https://mercuryiss.com.au/hestiacp-unauthenticated-rce-ip-spoofing-cve-2026-43633-cve-2026-43634

Thanked by 2Mumbly khalequzzaman

Comments

  • rpqurpqu Member

    Fuck

  • Published: 19 May 2026

    You are 2 weeks late. And the patch was merged in March.
    People who didn't update their shit for 3 months deserve to be pwned.

  • BoogeymanBoogeyman Member
    edited June 2

    @luckypenguin said:
    Published: 19 May 2026

    You are 2 weeks late. And the patch was merged in March.
    People who didn't update their shit for 3 months deserve to be pwned.

    Yes this was patched on March 19. But check the NVD date and 1.9.5(28th May) and 1.9.6(29th May) release date. If you use HestiaCP you should know how the upgrade process works.

Sign In or Register to comment.