Imunify360 website security products are affected by a serious vulnerability that could expose millions of sites to hacking.
Imunify360 is designed for Linux-based web hosting environments. According to October 2024 data from the vendor, Imunify360 had been used to protect 56 million sites.
According to website security company Patchstack, the Imunify360 antivirus is impacted by a flaw that can be exploited to execute arbitrary code and possibly fully compromise the hosting environment. An attacker can use a specially crafted file that triggers the vulnerability when the product scans it.
The vulnerability was recently patched, but Imunify360 developer Cloud Linux Software has not assigned a CVE identifier.
In an advisory published on November 4, Cloud Linux Software informed customers that the Ai-Bolit malware scanner used in Imunify360, ImunifyAV+, and ImunifyAV is impacted by a “critical security vulnerability”. A patch has been available since October 21.
Patchstack reported that information about the flaw has been spreading since late October, but the security firm cannot say whether it has been exploited in the wild.
Oliver Sild, co-founder and CEO of Patchstack, told SecurityWeek that hackers could sign up for shared hosting accounts at providers that use Imunify360 and intentionally upload malware designed to trigger the vulnerability.
Code planted inside the bait malware file would be executed with the elevated privileges of the malware scanner.
“Shared web hosting servers often service hundreds of sites at the same time, which have to be carefully isolated from each other as they belong to different customers. Since the vulnerable malware scanner runs with root privileges, this could potentially give the attacker access to all sites in the shared server,” Sild explained.
Patchstack has made public technical details and a proof-of-concept (PoC) exploit. The security firm has advised hosting providers to check their systems for signs of compromise.
UPDATE: In an update to its initial blog post, Patchstack clarified that an attacker does not need to upload malware to exploit the flaw. Instead, posting a specially crafted comment on a WordPress site is enough to trigger the bug, which makes it even more dangerous than previously believed.
UPDATE, November 20, 2025: Imunify has addressed the matter in a blog post. The company says the vast majority of servers have already been automatically updated and secured. It also noted that there is no evidence of exploitation in the wild.
Related: New HTTP Request Smuggling Attacks Impacted CDNs, Major Orgs, Millions of Websites
Related: Reflectiz Raises $22 Million for Website Security Solution
Related: Year-Old WordPress Plugin Flaws Exploited to Hack Websites
