EasyApache 4 25.71 — cPanel & WHM Update
Security hotfix We released updated ea-modsec30 and ea-modsec30-rules-owasp-crs packages for EasyApache 4. This security hotfix updates ea-modsec30 to 3.0.16, addressing two issues: CVE-2026-52747 (the multipart/form-data request body parser invalidly handled r and characters, allowing an unauthenticated WAF rule b…
Affected Versions
25.71
Security hotfix We released updated ea-modsec30 and ea-modsec30-rules-owasp-crs packages for EasyApache 4. This security hotfix updates ea-modsec30 to 3.0.16, addressing two issues: CVE-2026-52747 (the multipart/form-data request body parser invalidly handled r and characters, allowing an unauthenticated WAF rule b…
EasyApache 4 25.71
2026 July 13
Security hotfix
We released updated ea-modsec30 and ea-modsec30-rules-owasp-crs packages for EasyApache 4.
This security hotfix updates ea-modsec30 to 3.0.16, addressing two issues: CVE-2026-52747 (the multipart/form-data request body parser invalidly handled r and n characters, allowing an unauthenticated WAF rule bypass) and CVE-2026-52761 (wrong behavior in utf8toUnicode on i386 architecture).
For a full list of changes, read the EasyApache 4 change log.
How to Apply the Fix
Update the affected packages on your server to the patched release, then restart the relevant services.
sudo /scripts/upcp --force
Check your system for vulnerabilities
Select your product and operating system to see the exact fix commands that apply to you.
Check Your System