CloudLinux develops a focused line of server-hardening and security products for hosting environments, including containerization (CageFS), malware detection (AI-Bolit), and defense automation (Imunify360). The observed vulnerability patterns center on information exposure, file-path manipulation, and code-injection issues—weaknesses characteristic of software that manages process isolation, file access controls, and security rule evaluation in multi-tenant hosting contexts. Current severity, exploitation activity, and CVE counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Cloudlinux over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-65530HIGH An eval injection in the malware de-obfuscation routines of CloudLinux ai-bolit before v32.7.4 allows attackers to overwrite arbitrary files as root via scanning a crafted file. | Dec 12, 2025 | 8.8 | 29 | NO | NO |
CVE-2021-21956HIGH A php unserialize vulnerability exists in the Ai-Bolit functionality of CloudLinux Inc Imunify360 5.10.2. A specially-crafted malformed file can lead to potential arbitrary command | Apr 14, 2022 | 7.8 | 26 | NO | NO |
CVE-2020-36771HIGH CloudLinux CageFS 7.1.1-1 or below passes the authentication token as a command line argument. In some configurations this allows local users to view the authentication token via t | Jan 22, 2024 | 7.8 | 22 | NO | NO |
CVE-2020-36772MEDIUM CloudLinux CageFS 7.0.8-2 or below insufficiently restricts file paths supplied to the sendmail proxy command. This allows local users to read and write arbitrary files of certain | Jan 22, 2024 | 4.4 | 16 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Cloudlinux.
Media articles that mention a CVE ID that affects a product developed by Cloudlinux — matched by CVE ID, not by vendor name.