cPanel · Top 20

Targeted Security Release For a full list of changes, read the ConfigServer Security & Firewall (CSF) change log.

cPanel Release Notes (RSS) 2026-09-03 15:30 UTC · 2026-09-03 12:30 -03

EasyApache 4 25.81

⚠️ Importante

Maintenance and security updates We released updated packages for EasyApache 4. This release patches ea-openssl11 on CentOS 7 for a heap buffer overflow in CMS key unwrapping (CVE-2026-63072) and excessive memory use when buffering DTLS re…

cPanel Release Notes (RSS) CVE-2026-63072CVE-2026-54874 CVSS 7.5 2026-09-03 14:30 UTC · 2026-09-03 11:30 -03

EasyApache 4 25.80

⚠️ Importante

Maintenance and security updates We released updated packages for EasyApache 4. This release updates ea-nginx to v1.31.4, which adds PROXY protocol version 2 support to the stream and mail modules, sends the ":authority" pseudo-h…

cPanel Release Notes (RSS) CVE-2026-66299CVE-2026-26962 CVSS 7.5 2026-08-26 21:00 UTC · 2026-08-26 18:00 -03

EasyApache 4 25.79

⚠️ Importante

Security and maintenance updates We released updated packages for EasyApache 4. This security release hardens the Phusion Passenger agent API authorization boundary so an empty API account database confers no privileges, resolving a local …

cPanel Release Notes (RSS) 2026-08-19 17:00 UTC · 2026-08-19 14:00 -03

Sitejet Builder 4.12.1-1

⚠️ Importante

Security fix This release validates that Sitejet single sign-on links point to the expected Sitejet host before use (DUCKS-6701). For a full list of changes, read the Sitejet Builder change log.

cPanel Release Notes (RSS) 2026-08-13 22:00 UTC · 2026-08-13 19:00 -03

EasyApache 4 25.78

⚠️ Importante

Maintenance and Security Release We released updated packages for EasyApache 4. This release hardens container isolation, authorization, and registry integrity in ea-podman (CPANEL-55335, CPANEL-55336, CPANEL-55337, CPANEL-55342, CPANEL-55…

cPanel Release Notes (RSS) 2026-08-12 23:30 UTC · 2026-08-12 20:30 -03

EasyApache 4 25.77

⚠️ Importante

Maintenance and Security Release We released updated packages for EasyApache 4. This release resolves three PHP vulnerabilities across ea-php82, ea-php83, ea-php84, and ea-php85: a libgd vulnerability (CVE-2026-9672), a SQL injection via b…

cPanel Release Notes (RSS) CVE-2026-9672CVE-2026-17543CVE-2026-7260CVE-2026-17544 CVSS 9.8 2026-08-11 21:30 UTC · 2026-08-11 18:30 -03

Security fixes This security release resolves several vulnerabilities in CSF (CPANEL-54191, CPANEL-55183, CPANEL-54192, CPANEL-55265). It also includes several firewall reliability fixes for AlmaLinux 10, Debian, and Ubuntu. For a full lis…

cPanel Release Notes (RSS) 2026-08-05 22:00 UTC · 2026-08-05 19:00 -03

Faster site publishing Sitejet Builder now downloads website files in parallel when you publish a site. This reduces publish time for large sites. For a full list of changes, read the Sitejet Builder change log.

cPanel Release Notes (RSS) 2026-07-30 18:30 UTC · 2026-07-30 15:30 -03

Maintenance updates We released updated packages for EasyApache 4. This maintenance release includes updates to ea-passenger-src (v6.1.8), ea-ruby27-passenger (v6.1.8), ea-redis62 (v6.2.23), ea-valkey72 (v7.2.14), ea-memcached16 (v1.6.45),…

cPanel Release Notes (RSS) 2026-07-29 23:30 UTC · 2026-07-29 20:30 -03

cPanel & WHM version 138

⚠️ Importante

Introduced the Meridian interface We introduced Meridian, a new goal-based cPanel interface. Meridian organizes common hosting tasks into six purpose-built hubs for Websites, Email, Files, Databases, Security, and Performance. Its Dashboar…

cPanel Release Notes (RSS) 2026-07-27 22:00 UTC · 2026-07-27 19:00 -03

EasyApache 4 25.74

⚠️ Importante

Security Hotfix We released an updated ea-nginx package family (nginx 1.31.3) for EasyApache 4. This security release resolves three nginx vulnerabilities, including a critical heap buffer overflow in the map directive with regular express…

cPanel Release Notes (RSS) CVE-2026-42533CVE-2026-60005CVE-2026-56434 CVSS 9.2 2026-07-16 22:00 UTC · 2026-07-16 19:00 -03

EasyApache 4 25.73

⚠️ Importante

Maintenance updates We released updated ea-tomcat101, ea-memcached16, ea-apache24-mod_security2, ea-modsec2-rules-owasp-crs, ea-ioncube15, ea-nodejs22, and Phusion Passenger 6.1.7 (ea-passenger-src, ea-ruby27-passenger, ea-apache24-mod-pas…

cPanel Release Notes (RSS) 2026-07-15 21:00 UTC · 2026-07-15 18:00 -03

EasyApache 4 25.72

⚠️ Importante

Maintenance updates We released updated ea-modsec30, ea-modsec30-connector-apache24, and ea-modsec30-rules-owasp-crs packages for EasyApache 4. This maintenance release fixes ModSecurity audit logs silently failing to write across mod_ruid…

cPanel Release Notes (RSS) 2026-07-14 19:30 UTC · 2026-07-14 16:30 -03

Comet Backup 1.5.6

⚠️ Importante

Bug fixes This release fixes Comet Backup jobs failing en masse with locked-by-device retention errors on busy servers. The plugin now requests the less-often automatic-retention ruleset for dispatched backups and no longer cancels orphan…

cPanel Release Notes (RSS) 2026-07-14 14:30 UTC · 2026-07-14 11:30 -03

EasyApache 4 25.71

⚠️ Importante

Security hotfix We released updated ea-modsec30 and ea-modsec30-rules-owasp-crs packages for EasyApache 4. This security hotfix updates ea-modsec30 to 3.0.16, addressing two issues: CVE-2026-52747 (the multipart/form-data request body pars…

cPanel Release Notes (RSS) CVE-2026-52747CVE-2026-52761 CVSS 8.6 2026-07-13 19:00 UTC · 2026-07-13 16:00 -03

Sitejet Builder 4.11.0-1

⚠️ Importante

Improved read-only API token enforcement Sitejet Builder UAPI methods are now classified as read-only for cPanel & WHM API token enforcement. For a full list of changes, read the Sitejet Builder change log.

cPanel Release Notes (RSS) 2026-07-08 20:30 UTC · 2026-07-08 17:30 -03

EasyApache 4 25.70

⚠️ Importante

Security and maintenance updates We released updated packages for EasyApache 4. This security release updates PHP 8.2, 8.3, 8.4, and 8.5 to address CVE-2026-14355 (a memory corruption issue in openssl_encrypt with AES-WRAP-PAD) and, for PH…

cPanel Release Notes (RSS) CVE-2026-14355CVE-2026-12184 CVSS 5.6 2026-07-08 19:30 UTC · 2026-07-08 16:30 -03

EasyApache 4 25.69

⚠️ Importante

Security and maintenance updates We released an updated ea-tomcat101 package for EasyApache 4. This security release updates Apache Tomcat to 10.1.56, addressing six CVEs (CVE-2026-55956, CVE-2026-55955, CVE-2026-55276, CVE-2026-53434, CVE…

cPanel Release Notes (RSS) CVE-2026-55956CVE-2026-55955CVE-2026-55276CVE-2026-53434CVE-2026-53404CVE-2026-50229 CVSS 9.1 2026-07-02 15:30 UTC · 2026-07-02 12:30 -03

AWS partner rollout Server Monitoring rollout for the AWS partner. For a full list of changes, read the Server Monitoring change log.

cPanel Release Notes (RSS) 2026-06-26 16:00 UTC · 2026-06-26 13:00 -03