Panel patched CVE-2026-67401, which lets a hosting account with mail privileges create files anywhere and run code as root.