Birch Hosting logo.

May 2026 Security Update

  • 3 minutes read time

Published: 12/08/2026

green hosting

May 2026 Security Update: Recent Linux & cPanel Vulnerabilities Successfully Patched Across Our Infrastructure

Security remains a top priority across our platform and hosting infrastructure. Over the past month, several high-profile vulnerabilities affecting Linux systems and cPanel/WHM environments have been publicly disclosed, with some already being actively exploited in the wild.

In response, our engineering and security teams immediately assessed our exposure, implemented mitigations where necessary, and deployed all relevant security patches across managed systems.

We are pleased to confirm that all affected systems under our management have now been fully patched and secured.

Recent Linux Kernel Vulnerabilities

Over recent weeks, the Linux ecosystem has faced multiple serious privilege escalation vulnerabilities affecting a broad range of distributions and kernel versions.

One of the most significant disclosures was **CVE-2026-31431**, also referred to as **“Copy Fail”**. This vulnerability affects Linux kernels dating back to 2017 and could allow a local user to escalate privileges to root access through flaws within the kernel cryptographic subsystem. Public proof-of-concept exploit code became available shortly after disclosure, increasing the urgency for remediation.

Researchers also disclosed another Linux privilege escalation issue known as **“Dirty Frag”**, a kernel-level flaw capable of granting unauthorised root access across major Linux distributions including Ubuntu, RHEL, AlmaLinux, Fedora, and CentOS-based systems.

In addition, security researchers recently identified **Fragnesia (CVE-2026-46300)**, a Linux kernel vulnerability affecting memory handling and packet fragmentation mechanisms. The flaw could potentially allow local privilege escalation and system instability under specific conditions. Given the widespread use of affected kernel components across hosting environments, this vulnerability was treated with high priority as part of our patching and remediation process.

These vulnerabilities reinforce the importance of proactive monitoring, rapid patch deployment, and layered security controls within modern hosting environments.

Critical cPanel & WHM Vulnerability

Alongside the Linux kernel disclosures, a critical vulnerability affecting cPanel & WHM was also announced during the past month.

Tracked as **CVE-2026-41940**, the vulnerability could allow unauthenticated attackers to bypass authentication protections and potentially gain administrative access to hosting control panels. Security researchers and industry vendors confirmed that exploitation activity had already been observed shortly after disclosure.

As cPanel remains one of the most widely deployed hosting control panels globally, the issue received immediate attention from our infrastructure and security teams.

Our Response

Immediately following disclosure of these vulnerabilities, our teams initiated our internal vulnerability response and patch management procedures, including:

  • Reviewing all managed Linux and hosting infrastructure for exposure
  • Applying vendor-provided kernel and cPanel security updates
  • Implementing temporary mitigations where appropriate
  • Verifying patch deployment and system integrity across all environments
  • Increasing monitoring for suspicious authentication attempts and privilege escalation activity

All affected systems within our managed infrastructure have now been fully patched and secured against the disclosed vulnerabilities.

Our Ongoing Commitment to Security

Cybersecurity threats continue to evolve rapidly, particularly within widely deployed infrastructure platforms such as Linux and cPanel. Our approach combines proactive monitoring, rapid vulnerability assessment, layered security controls, and timely patch management to minimise operational risk and maintain service reliability.

We strongly encourage all organisations operating Linux servers or cPanel environments to ensure systems are updated promptly and to regularly review access controls, monitoring policies, and backup procedures.

If you have any questions regarding our security practices or infrastructure hardening procedures, please contact our team.

Table of Contents