[Important] cPanel & WHM Targeted Security Release: Patch Arriving Wednesday, May 20 at 8am EST

Jade @ Absolute Hosting

Absolute Hosting Representative
Company Rep
Company Rep
Joined
Nov 17, 2015
Messages
2,048
Reaction score
1,466
Location
Centurion
As recieved :

We are writing to let you know that a cPanel & WHM security patch is expected to be released on Wednesday, May 20 at 8am EST.

This release addresses vulnerabilities across versions of cPanel & WHM, including fixes for the several vulnerabilities rated up to High severity.

All vulnerabilities were either responsibly disclosed by external researchers or identified internally by our security team. At this time, there are no known exploits or proof-of-concept code in the wild. To help protect customers prior to patch availability, technical details about vulnerabilities will be released alongside the patches.

Patch & Affected Versions
The patch will be available on Wednesday, May 20 at 8am EST and will be distributed through the standard cPanel automatic update process and through the manual update process. We strongly recommend performing a manual update once the patch is made available.

Versions Impacted:
86, 94, 102, 110, 110 (CL6), 118, 124, 126, 130, 132, 134, 136, 136 (WP2)

Prepare Now
Identify affected servers. Review your servers on the affected versions above.
Check the update configuration. For servers where automatic updates are disabled or version-pinned, review /etc/cpupdate.conf now so there are no delays when the patch lands.
Brief your team. If your environment requires a maintenance window, notify the relevant people so they are ready to act.
Manual update. To update impacted servers before an automatic update is triggered, run /scripts/upcp once the patch is made available.
Note for CloudLinux 6 users. Before manually updating, set the update tier to the cl6110 branch
Watch for a follow-up email with exact patched versions and a link to all technical details in the support article.
We will follow up the moment the patch is live with full details and remediation steps.

Please reach out to your account manager or our support team, if you have any questions or need further guidance.

Best regards,
Your cPanel Security Team
 
We are writing to confirm that the latest patched builds for cPanel & WHM are now available, addressing multiple vulnerabilities including those rated up to High severity.



Note: Due to an actively exploited vulnerability in the LiteSpeed User-End Plugin - a third-party plugin that integrates with cPanel (see details below), this security release was published approximately 12 hours ahead of the originally scheduled May 20, 2026 release. We regret any disruption this may have caused.



Vulnerabilities Addressed



This release addresses the following security issues:

  • SEC-73728: See support article for details.
  • SEC-73755: See support article for details.
  • LiteSpeed User-End cPanel Plugin: A privilege-escalation vulnerability allowing unauthorized root access, actively exploited in the wild. As an interim security measure, an automated fix has been included in this release that uninstalls the LiteSpeed User-End cPanel Plugin. See support article for details.
Please follow the instructions in the linked support articles and update cPanel & WHM to one of the patched versions listed below. We strongly recommend performing a manual update.

Note for CloudLinux 6 users: Customers on CentOS 6 or CloudLinux 6 should update to the cl6110 branch (11.110.0.120) before manually updating.



Key Resources

Please reach out to your account manager or our support team, if you have any questions or need further guidance.
 
Top
Sign up to the MyBroadband newsletter
X