Back to Security Advisories

Security: CVE-2026-33278 cpanel-unbound 1.25.1 Security Release – May 21, 2026

An upstream vulnerability was recently reported for Unbound that affects supported cPanel & WHM versions 126 and higher.

Critical 9.8 CVSS
cPanel

Affected Versions

1.25.1

Default Update CMD

yum update cpanel-unbound

What this means under a SharedLicense license

Your SharedLicense license itself is not affected — this is a vulnerability in cPanel software, not in licensing. Licenses continue to work during and after the update; there is no need to re-issue or re-activate anything. If you resell cPanel under your own brand, patch client servers too — unpatched installs put your reputation at risk, not your license.

Situation

An upstream vulnerability was recently reported for Unbound that affects supported cPanel & WHM versions 126 and higher.

Impact

We have pushed out an update, including the updated package for the following cPanel & WHM versions: 

  • 11.126.0.63 and higher
  • 11.134.0.30 and higher
  • 11.136.0.14 and higher

We have also pushed out an update for the following WP Squared version:

  • 11.138.1.1 and higher

Note: All further versions of cPanel are patched for this issue as well. Please see the latest changelogs for version information of each cPanel branch:
https://docs.cpanel.net/changelogs/

Call to Action

  1. Update the cPanel version on the server to one of the versions listed above. This can be done with the following:

    # /scripts/upcp –force

  2. Once completed, verify the cPanel version with the following to ensure the update was successful.

    # /usr/local/cpanel/cpanel -V

Frequently Asked Questions

What is CVE-2026-33278?
NLnet Labs Unbound 1.19.1 up to and including version 1.25.0 has a vulnerability in the DNSSEC validator that enables denial of service and possible remote code execution as a result of deep copying a data structure and erroneously overwriting a destination pointer. An adversary can exploit the vulnerability by controlling a malicious signed zone and querying a vulnerable Unbound. When DS sub-queries need to suspend validation due to NSEC3 computational budget exhaustion (introduced in Unbound 1.19.1), Unbound deep-copies response messages to preserve them across memory region teardown. A struct-assignment bug overwrites the destination's pointer with the source's pointer. After the sub-query region is freed, the resumed validator dereferences this dangling pointer, triggering a crash or potentially enabling arbitrary code execution. Unbound 1.25.1 contains a patch with a fix to preserve the correct pointer when deep copying the data structure.
Is CVE-2026-33278 being exploited in the wild?
No confirmed exploitation is recorded. The EPSS model estimates a 1.27% probability of exploitation within the next 30 days — patch on your normal schedule.
How do I fix CVE-2026-33278?
Update cPanel to the patched release.Then confirm the running version matches the patched release listed above.

Check your system for vulnerabilities

Select your product and operating system to see the exact fix commands that apply to you.

Check Your System