EasyApache 4 25.71 — cPanel & WHM Update
Affected Versions
25.71
What this means under a SharedLicense license
Your SharedLicense license itself is not affected — this is a change in cPanel & WHM software, not in licensing. Apply it on every affected server: sudo /scripts/upcp --force. Licenses keep working through updates; nothing needs re-issuing or re-activating.
Security hotfix We released updated ea-modsec30 and ea-modsec30-rules-owasp-crs packages for EasyApache 4. This security hotfix updates ea-modsec30 to 3.0.16, addressing two issues: CVE-2026-52747 (the multipart/form-data request body parser invalidly handled r and characters, allowing an unauthenticated WAF rule b…
EasyApache 4 25.71
2026 July 13
Security hotfix
We released updated ea-modsec30 and ea-modsec30-rules-owasp-crs packages for EasyApache 4.
This security hotfix updates ea-modsec30 to 3.0.16, addressing two issues: CVE-2026-52747 (the multipart/form-data request body parser invalidly handled r and n characters, allowing an unauthenticated WAF rule bypass) and CVE-2026-52761 (wrong behavior in utf8toUnicode on i386 architecture).
For a full list of changes, read the EasyApache 4 change log.
References
Check your system for vulnerabilities
Select your product and operating system to see the exact fix commands that apply to you.
Check Your System