Millions of Linux‑Hosted Sites in the Crosshairs: A Remote Code Execution Flaw in ImunifyAV
A critical RCE vulnerability in the ImunifyAV malware scanner threatens 56 million websites running on shared Linux hosts, allowing attackers to execute arbitrary PHP code and potentially seize entire servers. The flaw, uncovered by Patchstack and patched by CloudLinux in November, exploits the scanner’s deobfuscation logic and remains unassigned a CVE ID, leaving many admins unaware of the risk.