Over the past week, three critical vulnerabilities have been publicly disclosed across components we use in our infrastructure stack: cPanel, and two separate Linux kernel privilege escalation flaws. Thousands of servers worldwide have already been compromised. None in our fleet.
Here's a breakdown of what happened, what we did, and what (if anything) you need to do.
- CPANEL-52908 — cPanel authentication bypass
Disclosed: April 28
Severity: Critical
What it is: A flaw in the cPanel session loading module that allowed attackers to bypass authentication and gain control of the panel without valid credentials.
What we did: Applied the official patch (version 134.0.20) across the entire fleet on the same day of disclosure.
Status: Resolved. No action required from you.
- "Copy Fail" — Linux kernel privilege escalation (CVE-2026-31431)
Disclosed: April 30
Severity: High
What it is: A flaw allowing a user with shell access to escalate to administrator privileges. Particularly dangerous on shared environments.
What we did: Deployed a kernel-level configuration mitigation across the fleet the same day, neutralizing the exploit path. The definitive fix requires a kernel reboot.
Status: Mitigated. We will coordinate the maintenance window for affected servers individually.
- "Dirty Frag" — Linux kernel privilege escalation
Disclosed: May 7
Severity: High
What it is: A newly disclosed vulnerability for which the kernel vendor has not yet released an official patch. As of this post, server operators worldwide are still waiting for an upstream fix.
What we did: Within hours of disclosure, we deployed a mitigation that disables kernel modules we don't use on our platform, neutralizing the exploit vector entirely.
Status: Mitigated across the fleet. We continue to monitor for the official upstream patch and will apply it as soon as it's released.
Why this matters
Three critical vulnerabilities in nine days is unusual, but not unheard of. What's worth noting is the response gap: many self-managed servers will remain exposed for days or weeks because patching requires time, expertise, and operational risk tolerance that many teams simply don't have.
This is the work managed hosting is supposed to do, quietly, before you hear about the threat. If you're a RemarkableCloud customer reading this for the first time, that gap is exactly what you've already paid for.
What you need to do
cPanel: Nothing. Already patched.
Copy Fail and Dirty Frag: A reboot is required to apply the definitive kernel update once available. We will reach out individually to schedule maintenance windows. If you'd like to schedule yours sooner, reply on your support ticket or open a new one.
If you have any questions about how these vulnerabilities affect your specific environment, we're here.