Back to Security Advisories

ConfigServer Security & Firewall (CSF) 16.12-1 — cPanel & WHM Update

This is a security release for cPanel & WHM. Update the product on every affected server to the patched release — `sudo /scripts/upcp --force` — there is no workaround, and unpatched servers remain exposed until updated.

Medium
cPanel CSF

Affected Versions

16.12-1

Default Update CMD

cd /usr/src && rm -f csf.tgz && wget https://download.configserver.com/csf.tgz && tar -xzf csf.tgz && cd csf && sh install.sh && csf -r

What this means under a SharedLicense license

Your SharedLicense license itself is not affected — this is a change in cPanel & WHM software, not in licensing. Reinstall CSF from the latest ConfigServer package (csf.tgz) and run csf -r. Licenses keep working through updates; nothing needs re-issuing or re-activating.

Package removal cleanup fix Fixed an issue where uninstalling cpanel-csf left the CSF plugin entry and LFD service status behind in WHM (CPANEL-51933). Also suppresses harmless errors on missing symlinks during upgrades. For a full list of changes, read the ConfigServer Security & Firewall (CSF) change log.

Check your system for vulnerabilities

Select your product and operating system to see the exact fix commands that apply to you.

Check Your System