Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Vulnerabilities

Imunify360 Vulnerability Could Expose Millions of Sites to Hacking

A vulnerability in ImunifyAV can be exploited for arbitrary code execution by uploading a malicious file to shared servers.

Hacking

Imunify360 website security products are affected by a serious vulnerability that could expose millions of sites to hacking. 

Imunify360 is designed for Linux-based web hosting environments. According to October 2024 data from the vendor, Imunify360 had been used to protect 56 million sites.

According to website security company Patchstack, the Imunify360 antivirus is impacted by a flaw that can be exploited to execute arbitrary code and possibly fully compromise the hosting environment. An attacker can use a specially crafted file that triggers the vulnerability when the product scans it. 

The vulnerability was recently patched, but Imunify360 developer Cloud Linux Software has not assigned a CVE identifier. 

In an advisory published on November 4, Cloud Linux Software informed customers that the Ai-Bolit malware scanner used in Imunify360, ImunifyAV+, and ImunifyAV is impacted by a “critical security vulnerability”. A patch has been available since October 21. 

Patchstack reported that information about the flaw has been spreading since late October, but the security firm cannot say whether it has been exploited in the wild.

Advertisement. Scroll to continue reading.

Oliver Sild, co-founder and CEO of Patchstack, told SecurityWeek that hackers could sign up for shared hosting accounts at providers that use Imunify360 and intentionally upload malware designed to trigger the vulnerability. 

Code planted inside the bait malware file would be executed with the elevated privileges of the malware scanner. 

“Shared web hosting servers often service hundreds of sites at the same time, which have to be carefully isolated from each other as they belong to different customers. Since the vulnerable malware scanner runs with root privileges, this could potentially give the attacker access to all sites in the shared server,” Sild explained.

Patchstack has made public technical details and a proof-of-concept (PoC) exploit. The security firm has advised hosting providers to check their systems for signs of compromise.

UPDATE: In an update to its initial blog post, Patchstack clarified that an attacker does not need to upload malware to exploit the flaw. Instead, posting a specially crafted comment on a WordPress site is enough to trigger the bug, which makes it even more dangerous than previously believed.

UPDATE, November 20, 2025: Imunify has addressed the matter in a blog post. The company says the vast majority of servers have already been automatically updated and secured. It also noted that there is no evidence of exploitation in the wild.

Related: New HTTP Request Smuggling Attacks Impacted CDNs, Major Orgs, Millions of Websites

Related: Reflectiz Raises $22 Million for Website Security Solution

Related: Year-Old WordPress Plugin Flaws Exploited to Hack Websites

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join this live webinar as we break down why email-layer defenses alone can't keep pace with the modern phishing ecosystem, how agentic AI is changing the capacity equation for security teams, and more.

Register

This year's summit will help organizations learn how to utilize tools, controls, and design models needed to properly secure cloud environments. Interact with leading solution providers and other end users facing similar challenges in securing a variety of cloud deployments.

Register

People on the Move

Fable Security has appointed Jacob Berry as Chief Information Security Officer.

iCOUNTER has named Ali Waezzadah as Chief Information Security Officer.

Roger Hale has joined 1Kosmos as Chief Information Security Officer.

More People On The Move

Expert Insights

Four decades of incident response experience suggest that exploits are often the symptom, not the root cause, of today’s cybersecurity failures.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.