A fix is now available for a serious privilege-escalation vulnerability in the LiteSpeed User-End cPanel Plugin.
Vulnerability Summary
Any cPanel user (including an attacker or a compromised account) could exploit the lsws.redisAble function to execute arbitrary scripts as root. This issue is...
We are writing to confirm that the latest patched builds for cPanel & WHM are now available, addressing multiple vulnerabilities including those rated up to High severity.
Note: Due to an actively exploited vulnerability in the LiteSpeed User-End Plugin - a third-party plugin that integrates...
As recieved :
We are writing to let you know that a cPanel & WHM security patch is expected to be released on Wednesday, May 20 at 8am EST.
This release addresses vulnerabilities across versions of cPanel & WHM, including fixes for the several vulnerabilities rated up to High severity.
All...
We are writing to update you about a follow-up security release. Following responsible disclosure by an external security researcher, we have released an enhanced fix for CVE-2026-29205.
For the listed versions, if you applied yesterday's update, you need to apply this one as well. The updated...
More about this vulnerability
Whmcs recommends that you monitor the activity log for any unexpected single sign-on or service access events originating from mismatched user accounts prior to patching
All clients with an active WHMCS License from Absolute Hosting have immediate access to patch files and the latest versions.
Access the patch and full versions of WHMCS from the downloads page linked to your WHMCS Product within the client service area.
As received :
We are writing to let you know that a cPanel & WHM security patch is expected to be released on Wednesday, May 13, 2026 at 1:00pm EST.
This release addresses multiple vulnerabilities across versions of cPanel & WHM, including fixes for the following vulnerabilities rated up to...
WHMCS 9.0.4 and WHMCS 8.13.3 are now available as important maintenance releases for the WHMCS 9.0 and 8.13 series.
These releases address a security vulnerability, CVE-2026-29204, which affects WHMCS 7.4 and later. We strongly recommend that all self-managed WHMCS customers update to the...
The following notice applies to all clients hosted on shared cPanel and DirectAdmin servers.
As part of our ongoing commitment to maintaining a secure and reliable hosting environment, we will be performing emergency reboots of affected servers at 18H00 this evening in order to apply important...