CVE-2026-32992

HIGHCVSS 8.2/10EPSS 0.25%

Last modified

CVE-2026-32992 is a high-severity vulnerability rated 8.2/10 on the CVSS scale. SSL verification is disabled in the DNS Cluster system. This could allow for a malicious server to man-in-the-middle the request and capture credentials.. EPSS estimates a 0.25% chance of exploitation in the next 30 days.

Description

SSL verification is disabled in the DNS Cluster system. This could allow for a malicious server to man-in-the-middle the request and capture credentials.

Metrics

CVSS 3.1
8.2/10

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N

EPSS Probability
0.25%

16.7th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
CpanelCpanel>= 126.0.0, < 126.0.59
CpanelCpanel>= 130.0.0, < 130.0.23
CpanelCpanel>= 132.0.0, < 132.0.32
CpanelCpanel>= 134.0.0, < 134.0.26
CpanelCpanel>= 136.0.0, < 136.0.10
CpanelWp Squared>= 126.1.0, < 136.1.12
CpanelWhm>= 126.0.0, < 126.0.59
CpanelWhm>= 130.0.0, < 130.0.23
CpanelWhm>= 132.0.0, < 132.0.32
CpanelWhm>= 134.0.0, < 134.0.26
CpanelWhm>= 136.0.0, < 136.0.10

References

Timeline

Published
Last Modified
Status
Analyzed

Frequently Asked Questions

What is CVE-2026-32992?
SSL verification is disabled in the DNS Cluster system. This could allow for a malicious server to man-in-the-middle the request and capture credentials.
How severe is CVE-2026-32992?
CVE-2026-32992 has a CVSS score of 8.2/10 (HIGH severity). The EPSS model estimates a 0.25% probability of exploitation in the next 30 days.
How do I fix CVE-2026-32992?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2026

Are you affected by CVE-2026-32992?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST