ConfigServer Security & Firewall (CSF) 16.20-1 — cPanel & WHM Update
This is a security release for cPanel & WHM. Update the product on every affected server to the patched release — `sudo /scripts/upcp --force` — there is no workaround, and unpatched servers remain exposed until updated.
Affected Versions
16.20-1
Default Update CMD
cd /usr/src && rm -f csf.tgz && wget https://download.configserver.com/csf.tgz && tar -xzf csf.tgz && cd csf && sh install.sh && csf -r
What this means under a SharedLicense license
Your SharedLicense license itself is not affected — this is a change in cPanel & WHM software, not in licensing. Reinstall CSF from the latest ConfigServer package (csf.tgz) and run csf -r. Licenses keep working through updates; nothing needs re-issuing or re-activating.
Bug fixes Fixed regex.custom.pm custom rules silently failing to match log lines (CPANEL-53173). Fixed csf -cf $file no longer retaining newlines in the file (CPANEL-52801). For a full list of changes, read the ConfigServer Security & Firewall (CSF) change log.
References
Check your system for vulnerabilities
Select your product and operating system to see the exact fix commands that apply to you.
Check Your System