Back to Security Advisories

EasyApache 4 25.86 — cPanel & WHM Update

EasyApache 4 release 25.86 (September 30, 2026) fixes eleven PHP vulnerabilities by updating ea-php82 to 8.2.34, ea-php83 to 8.3.35, ea-php84 to 8.4.26 and ea-php85 to 8.5.11, and also bumps ea-nodejs22 to 22.23.3 and ea-ruby27-libuv to 1.53.0. The individual issues are mostly low severity (the release's aggregate CVSS is 3.4, including a buffer-overflow class item, CWE-122), but any EasyApache 4 server running PHP should take the package update.

High 3.4 CVSS
cPanel

Affected Versions

25.86

What this means under a SharedLicense license

The fixes close eleven vulnerabilities in the packaged PHP interpreters — memory-corruption and parsing flaws of mostly low severity individually, but PHP runs every hosted site, so unpatched interpreters expose all hosted accounts on the server.

EasyApache 4 25.86

2026 September 30

Security and maintenance updates

We released updated packages for EasyApache 4.

This security release updates ea-php82 to 8.2.34, ea-php83 to 8.3.35, ea-php84 to 8.4.26 and ea-php85 to 8.5.11, which fix eleven vulnerabilities (CVE-2025-1218, CVE-2025-14181, CVE-2026-6103, CVE-2026-17545, CVE-2026-91765, CVE-2026-91766, CVE-2026-91767, CVE-2026-91768, CVE-2026-91769, CVE-2026-92842 and CVE-2026-93682). It also updates ea-nodejs22 to 22.23.3 and ea-ruby27-libuv to 1.53.0, and improves ea-podman container upgrades and cleanup.

For a full list of changes, read the EasyApache 4 change log.

Frequently Asked Questions

What does EasyApache 4 25.86 fix?
Eleven PHP vulnerabilities (CVE-2025-1218, CVE-2025-14181, CVE-2026-6103, CVE-2026-17545, CVE-2026-91765, CVE-2026-91766, CVE-2026-91767, CVE-2026-91768, CVE-2026-91769, CVE-2026-92842 and CVE-2026-93682) via PHP point-release updates to 8.2.34, 8.3.35, 8.4.26 and 8.5.11. It also updates ea-nodejs22 to 22.23.3 and ea-ruby27-libuv to 1.53.0, and improves ea-podman container upgrades and cleanup.
Which EasyApache 4 versions are affected?
Package builds before 25.86. The marker release is 25.86 (September 30, 2026); all four PHP package lines (ea-php82 through ea-php85) received the fixes, so servers running any PHP 8.2–8.5 version on EasyApache 4 should update.
How do I apply the fix?
Run yum update 'ea-*' or use WHM → EasyApache 4 → Update, then confirm the PHP packages show the 25.86-era versions (ea-php84 8.4.26, ea-php85 8.5.11 or later). Per-advisory update commands vary for the individual CVEs, but the package refresh covers all eleven.
Are these PHP flaws severe?
Individually mostly low — the release's aggregate CVSS is 3.4, with a buffer overflow class issue (CWE-122) among them. Low severity does not mean skip: PHP processes untrusted input on every request, and the update also carries Node.js and libuv refreshes.

Check your system for vulnerabilities

Select your product and operating system to see the exact fix commands that apply to you.

Check Your System