Back to Security Advisories

EasyApache 4 25.71 — cPanel & WHM Update

Critical
cPanel

Affected Versions

25.71

What this means under a SharedLicense license

Your SharedLicense license itself is not affected — this is a change in cPanel & WHM software, not in licensing. Apply it on every affected server: sudo /scripts/upcp --force. Licenses keep working through updates; nothing needs re-issuing or re-activating.

Security hotfix We released updated ea-modsec30 and ea-modsec30-rules-owasp-crs packages for EasyApache 4. This security hotfix updates ea-modsec30 to 3.0.16, addressing two issues: CVE-2026-52747 (the multipart/form-data request body parser invalidly handled r and characters, allowing an unauthenticated WAF rule b…

EasyApache 4 25.71

2026 July 13

Security hotfix

We released updated ea-modsec30 and ea-modsec30-rules-owasp-crs packages for EasyApache 4.

This security hotfix updates ea-modsec30 to 3.0.16, addressing two issues: CVE-2026-52747 (the multipart/form-data request body parser invalidly handled r and n characters, allowing an unauthenticated WAF rule bypass) and CVE-2026-52761 (wrong behavior in utf8toUnicode on i386 architecture).

For a full list of changes, read the EasyApache 4 change log.

Check your system for vulnerabilities

Select your product and operating system to see the exact fix commands that apply to you.

Check Your System