External risk intelligence

Softaculous Virtualizor PHP Object Injection Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.2)

CVE-2026-43642

Virtualizor is a server management and virtualization platform typically deployed as an internet-facing administrative gateway. Because this vulnerability exists in a login handler reachable without authentication, the attack surface is exposed directly to the public internet by design in standard deployments.

Deserialization

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A vulnerability in Virtualizor's billing module handler could allow unauthenticated remote attackers to execute arbitrary code with root privileges. This is due to the way the system handles serialized PHP objects, potentially enabling exploitation by specially crafted data.

  • Unauthenticated remote code execution risk.
  • Critical vulnerability affects core system functions.
  • Assess exposure and confirm relevance promptly.

Attack Path

How an attacker could exploit the issue

An unauthenticated attacker can exploit a PHP object injection flaw in the billing module handler to execute arbitrary code as root. This is achieved by sending specially crafted serialized PHP data through the billing_data POST field to the application's login page, bypassing normal security checks and triggering a deserialization vulnerability.

  • Unauthenticated remote access required.
  • Supply malicious serialized data to billing module.
  • Remote code execution with root privileges.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow unauthenticated remote attackers to execute arbitrary code with root privileges on affected systems. This could occur when the billing module handler is accessed and the `act` parameter is set to `login` with the `from_billing_module` parameter present, and malicious serialized PHP object data is provided in the `billing_data` POST field. The system data at risk includes the entire operating system and any hosted services.

  • System data and service integrity.
  • Unauthenticated remote code execution.
  • Complete system compromise.

Operational Fix

Recommended remediation, mitigation, and detection steps

The billing and platform teams are likely responsible for addressing this vulnerability in Softaculous Virtualizor, as it affects the core virtualization management platform. The immediate first step is to identify all instances of Virtualizor within the environment, determine their exposure to the network, and assess their criticality to business operations to prioritize remediation efforts.

  • Owner: Billing and Platform Teams.
  • Verify: Instance exposure and business criticality.
  • Action: Plan targeted remediation.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Softaculous Virtualizor?

Softaculous Virtualizor is a server management and virtualization platform. Administrators use it to create and manage virtual machines, providing an interface to oversee cloud infrastructure, handle billing cycles, and control server resources in a centralized environment.

What does CVE-2026-43642 mean?

This CVE refers to a PHP object injection vulnerability, classified as CWE-502. It occurs when a program takes user-provided data and reconstructs it into complex objects without sufficient validation. In this case, the system mistakenly processes untrusted serialized data, which can allow an attacker to manipulate the program's logic and execute unauthorized commands.

How is this vulnerability triggered?

An attacker triggers the flaw by sending a specific POST request to the billing module handler. They must set the act parameter to login and include the from_billing_module parameter. Simply accessing the login page without these specific parameters and the corresponding malicious serialized data in the billing_data field does not trigger the vulnerability.

Do I need to worry if my instance is internal?

According to Halo Surface Signal, Virtualizor is typically deployed as an internet-facing administrative gateway by design. If your instance is accessible from the public internet, it carries a high risk because this vulnerability does not require authentication. Instances restricted strictly to internal networks face a lower direct risk from external remote attackers.

What is the first step to address this?

Start by identifying every instance of Virtualizor currently running in your environment. Once you have a complete inventory, verify which instances are reachable from external networks. Use this information to prioritize your patching efforts, focusing on the most exposed systems first.

References