Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Virtualmin

Virtualmin Vendor Cyber Rating & Cyber Score

virtualmin.com

Virtualmin is a computer software company based out of 285B Mountain View Ave, Mountain View, California, United States.


Virtualmin A.I CyberSecurity Scoring

Virtualmin
Company Information
Website:http://www.virtualmin.com
Employees number:3
Number of followers:66
NAICS:5112
Industry Type:Software Development
Homepage:virtualmin.com
Virtualmin Risk Score (AI oriented)
Between 700 and 749
logo
VirtualminSoftware Development
Updated:
24/06/2026
749/1000
Moderate
Ba
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
✖ Insurance prefers TPRM score to calculate premium
Virtualmin Global Score (TPRM)
xxxx
logo
VirtualminSoftware Development
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

VirtualminModerate
Current Score
749Ba (MODERATE)
01000
1 incidents
-2 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
SEPTEMBER 2026
750Before Incident
AUGUST 2026
749Before Incident
JULY 2026
749Before Incident
JUNE 2026
751Before Incident
Vulnerability
01 Jun 2026 • Virtualmin
Virtualmin and Webmin: Critical Webmin Stored XSS Vulnerability Lets Untrusted Users Exploit Root Accounts

Critical Webmin Vulnerabilities Expose Root Access and Bypass 2FA

749After Incident
CRITICAL-2
VIRSER1782304191
Critical Webmin Vulnerabilities Expose Root Access and Bypass 2FA A critical stored cross-site scripting (XSS) vulnerability in Webmin, the popular web-based Unix system administration tool, has been disclosed, allowing untrusted users to compromise root-level accounts through malicious notification email templates. Tracked as CVE-2026-22678, the flaw affects all Webmin versions prior to 2.641 and resides in the System and Server Status module. The vulnerability enables attackers with permission to create email templates to inject malicious scripts that execute with root privileges when viewed. This poses a severe risk in multi-tenant or enterprise environments, where administrative access is often delegated to less-privileged users. Since the payload is stored on the server, root accounts can be silently compromised during routine administrative tasks without requiring direct interaction. Security researcher Wade Sparks responsibly disclosed the flaw, which was patched in Webmin 2.641. The update also addressed three additional vulnerabilities reported by Andrea Carlo Maria Dattola, Marco Ventura, and Massimiliano Brolli: - CVE-2026-49102 – XSS via SVG email attachments in the Read User Mail module, potentially exposing session tokens and user data. - CVE-2026-49103 – Arbitrary file overwrite in the Read User Mail module due to unsafe filename handling. - CVE-2026-42210 / CVE-2026-56022 – 2FA bypass via Basic HTTP authentication, allowing attackers to circumvent multi-factor authentication with only valid credentials. An additional privilege escalation flaw in Webmin’s Help feature, which allowed untrusted users to execute root-level commands regardless of permissions, was also patched without a CVE assignment. The vulnerabilities highlight systemic risks in Webmin’s permission delegation model, particularly in hosting environments where Webmin or Virtualmin manages multiple domains with separate user credentials. The 2FA bypass flaw is especially concerning, as it weakens a critical security layer and could facilitate credential stuffing or phishing attacks against administrators. Affected and Fixed Versions: - CVE-2026-22678 – Fixed in Webmin 2.641 - CVE-2026-49102, CVE-2026-49103, CVE-2026-42210 / CVE-2026-56022 – Fixed in Webmin 2.640 Administrators are urged to upgrade immediately to mitigate these risks.
INCIDENT DETAILS -
TYPE
XSSPrivilege Escalation2FA BypassArbitrary File Overwrite
IMPACT
Session tokensUser dataPersonally identifiable informationWebmin versions prior to 2.641Webmin versions prior to 2.640Operational Impact: Root-level account compromise, potential unauthorized system administrationBrand Reputation Impact: Severe risk in multi-tenant or enterprise environmentsIdentity Theft Risk: High
DATA BREACH
Session tokensUser dataPersonally identifiable informationSensitivity Of Data: HighEmail templatesSVG attachmentsPersonally Identifiable Information: Potentially exposed
MAY 2026
751Before Incident
APRIL 2026
751Before Incident
MARCH 2026
751Before Incident
FEBRUARY 2026
751Before Incident
JANUARY 2026
751Before Incident
DECEMBER 2025
751Before Incident
NOVEMBER 2025
751Before Incident
OCTOBER 2025
751Before Incident

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for Virtualmin ?
?
What was Virtualmin's A.I Rankiteo Cyber Score in August 2026 ?
?
What was Virtualmin's A.I Rankiteo Cyber Score in July 2026 ?
?
What was Virtualmin's A.I Rankiteo Cyber Score in June 2026 ?
?
What was Virtualmin's A.I Rankiteo Cyber Score in May 2026 ?
?
What was Virtualmin's A.I Rankiteo Cyber Score in April 2026 ?
?
What was Virtualmin's A.I Rankiteo Cyber Score in March 2026 ?
?
What was Virtualmin's A.I Rankiteo Cyber Score in February 2026 ?
?
What was Virtualmin's A.I Rankiteo Cyber Score in January 2026 ?
?
What was Virtualmin's A.I Rankiteo Cyber Score in December 2025 ?
?
What was Virtualmin's A.I Rankiteo Cyber Score in November 2025 ?
?
What was Virtualmin's A.I Rankiteo Cyber Score in October 2025 ?
?
What is the average per-incident point impact on Virtualmin's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with Virtualmin ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view Virtualmin's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?