High WHMCS 9.1.0 Security Update 2026-10-01
WHMCS-22707 — Undisclosed Security Fix
Betroffen
9.1.0
Control Panel
cPanel Lizenz$4.50DirectAdmin Lizenz$4.00Plesk Lizenz$3.00Abrechnung
WHMCS Lizenz$4.00Auto-Installer
Softaculous Lizenz$1Backup
JetBackup Lizenz$2.00Betriebssystem
CloudLinux Lizenz$4.50Reseller
DAReseller Lizenz$1.5WHMReseller Lizenz$2Sicherheit
CXS Lizenz$2Imunify360 Lizenz$2.00KernelCare Lizenz$2MailScanner Front-End Lizenz$1OSM Lizenz$2Virtualisierung
SolusVM Lizenz$2.00Virtualizor Lizenz$4.00Webserver
LiteSpeed Lizenz$4.50Website-Builder
SitePad Lizenz$2Desktop
Windows 10$12.00Windows 11$12.00Produktivität
Microsoft Access$10Microsoft Outlook$9.00Microsoft Project$9.00Microsoft SQL Server$12.00Microsoft Visio$7.00Office 2010$35Office 2013$15.00Office 2016$8Office 2019$8.00Office 2021$8.00Office 2024$8.00Office 365$10.00Visual Studio$10.00Server
Windows Server 2012 R2$10Windows Server 2016$10Windows Server 2019$10Windows Server 2022$10Windows Server 2025$10Select your product and operating system to see relevant security advisories and fix commands.
Ausgewählt:
Die meisten Fixes werden durch ein Update auf die neueste Version behoben. Hier ist der Befehl dazu:
Für detailliertere Lösungen siehe unten.
WHMCS-22707 — Undisclosed Security Fix
Betroffen
9.1.0
Security and maintenance updates We released updated packages for EasyApache 4. This security release updates ea-php82 to 8.2.34, ea-php83 to 8.3.35, ea-php84 to 8.4.26 and ea-php85 to 8.5.11, which fix eleven vulnerabilities (CVE-2025-1218, CVE-2025-14181, CVE-2026-6103, CVE-2026-17545, CVE-2026-91765, CVE-2026-917…
Betroffen
25.86
LiteSpeed Web Server (LSWS) before 6.3.7 build 1 mishandles internal redirect URL validation in a certain "corner case."
Harden iptables command For a full list of changes, read the ConfigServer Security & Firewall (CSF) change log.
Betroffen
16.32-1
Security update Sitejet Builder ships with an updated build-time library to resolve CVE-2026-40175. For a full list of changes, read the Sitejet Builder change log.
Betroffen
4.13.1-1
Security and maintenance updates We released updated packages for EasyApache 4. This release updates ea-nginx to 1.31.6, which includes the upstream fix for CVE-2026-90439, a buffer overflow in the ngx_http_v3_module module. EasyApache 4 does not build that module, so EasyApache 4 installations are not affected. It …
Betroffen
25.83
Security and maintenance updates We released updated packages for EasyApache 4. This security release updates ea-libxml2 to 2.15.4, which fixes eight vulnerabilities (CVE-2026-86137, CVE-2026-86138, CVE-2026-86139, CVE-2026-86140, CVE-2026-86141, CVE-2026-86142, CVE-2026-86143 and CVE-2026-86144), and patches ea-rub…
Betroffen
25.82
Maintenance and security updates We released updated packages for EasyApache 4. This release patches ea-openssl11 on CentOS 7 for a heap buffer overflow in CMS key unwrapping (CVE-2026-63072) and excessive memory use when buffering DTLS records (CVE-2026-54874). It also updates ea-re2c to v4.6 and fixes three ea-pod…
Betroffen
25.81
Maintenance and security updates We released updated packages for EasyApache 4. This release updates ea-nginx to v1.31.4, which adds PROXY protocol version 2 support to the stream and mail modules, sends the ":authority" pseudo-header on HTTP/2 and gRPC requests to backends, and fixes a worker-process segm…
Betroffen
25.80
Insufficient validation allows arbitrary commands to be executed via the Multilang adminbin.
There is a stored XSS vulnerability allowing arbitrary code execution in the WHM Mass Modify Accounts interface.
There is a stored XSS vulnerability allowing arbitrary code execution in the WHM Manage SSL Hosts interface.
Execution with unnecessary privileges in cPanel allows remote authenticated users to execute arbitrary code with root privileges.
Betroffen
11.120.0.0 before 11.134.0.57 | 11.136.0.0 before 11.136.0.41 | 11.138.0.0 before 11.138.0.8
Gepatcht
11.134.0.57 / 11.136.0.41 / 11.138.0.8 / WP Squared 11.138.1.11
AlmaLinux / CloudLinux / RHEL / Rocky Linux
# cPanel updates automatically; run manually to patch now
/usr/local/cpanel/scripts/upcp --force
# The update also repairs calendar and contact permissions for existing accounts
cat /usr/local/cpanel/version
Argument injection in WP Toolkit for cPanel 6.11.2-10794 and earlier allows remote authenticated users to read arbitrary files and execute arbitrary code across customer accounts.
Betroffen
6.11.2-10794 and earlier
Gepatcht
6.11.3-10850
All supported operating systems
# WP Toolkit (package wp-toolkit-cpanel) updates independently of cPanel & WHM
bash <(curl -SsL https://wp-toolkit.plesk.com/cPanel/installer.sh || wget -qO- https://wp-toolkit.plesk.com/cPanel/installer.sh) --version 6.11.3
An untrusted search path vulnerability in Plesk from 18.0.34 before 18.0.80.8 and 18.0.81 before 18.0.81.1 allows remote authenticated users to execute arbitrary code as root via the "Plesk RESTful API".
Betroffen
18.0.34 before 18.0.80.8 | 18.0.81 before 18.0.81.1 | 2.4.2 before 2.4.7
Gepatcht
18.0.80.8 / 18.0.81.1
AlmaLinux / Ubuntu / Debian / CloudLinux / Rocky Linux
plesk installer --select-release-current --reinstall-patch
plesk version
OS command injection in Plesk allows remote authenticated users to execute arbitrary code with root privileges.
Betroffen
1.6.6 – 1.12.1
Gepatcht
1.12.2
All supported operating systems
# Update the Site Import extension to 1.12.2 or later
# Plesk → Extensions → Updates → Site Import → Update
Incorrect permission assignment allows local users to obtain sensitive CalDAV/CardDAV information belonging to other accounts.
Betroffen
11.120.0.0 before 11.134.0.57 | 11.136.0.0 before 11.136.0.41 | 11.138.0.0 before 11.138.0.8
Gepatcht
11.134.0.57 / 11.136.0.41 / 11.138.0.8
AlmaLinux / CloudLinux / RHEL / Rocky Linux
# cPanel updates automatically; run manually to patch now
/usr/local/cpanel/scripts/upcp --force
# The update also repairs calendar and contact permissions for existing accounts
cat /usr/local/cpanel/version
Incorrect permission assignment allows local users to obtain sensitive CalDAV/CardDAV information belonging to other accounts.
Betroffen
11.120.0.0 before 11.134.0.57 | 11.136.0.0 before 11.136.0.41 | 11.138.0.0 before 11.138.0.8
Gepatcht
11.134.0.57 / 11.136.0.41 / 11.138.0.8 / WP Squared 11.138.1.11
AlmaLinux / CloudLinux / RHEL / Rocky Linux
# cPanel updates automatically; run manually to patch now
/usr/local/cpanel/scripts/upcp --force
# The update also repairs calendar and contact permissions for existing accounts
cat /usr/local/cpanel/version
Softaculous Virtualizor before 3.2.9 (Patch 9) and 3.0.0 contains an OS command injection vulnerability in the billing module handler that allows unauthenticated remote attackers to execute arbitrary commands as root.
Betroffen
before 3.2.9 (Patch 9)
Gepatcht
3.2.9 (Patch 9)
AlmaLinux / CloudLinux / Rocky Linux
yum update virtualizor
# Or in the admin panel: Config → Check for Updates → Update Now
Softaculous Virtualizor before 3.2.9 (Patch 9) and 3.0.0 contains a PHP object injection vulnerability in the billing module handler that allows unauthenticated remote attackers to supply arbitrary serialized PHP objects.
Betroffen
before 3.2.9 (Patch 9)
Gepatcht
3.2.9 (Patch 9)
AlmaLinux / CloudLinux / Rocky Linux
yum update virtualizor
# Or in the admin panel: Config → Check for Updates → Update Now
Softaculous Virtualizor before 3.2.9 (Patch 9) and 3.0.0 contains an authorization bypass vulnerability in the billing module handler that allows unauthenticated remote attackers to modify any tenant's account balance by.
Betroffen
before 3.2.9 (Patch 9)
Gepatcht
3.2.9 (Patch 9)
AlmaLinux / CloudLinux / Rocky Linux
yum update virtualizor
# Or in the admin panel: Config → Check for Updates → Update Now
This security release features a fix for a critical severity security vulnerability. Because this is a security release, it is recommended that you update your sites immediately. You can download WordPress 7.1.2 from WordPress.org, or visit your WordPress Dashboard, click “Updates”, and then click “Update Now”…
Betroffen
7.1.2
The LiteSpeed Cache plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'esi' parameter in all versions up to, and including, 7.9 due to insufficient input sanitization and.
Betroffen
all versions up to and including 7.9
All supported operating systems
wp plugin update litespeed-cache
# or: WordPress → Plugins → LiteSpeed Cache → Update Now
wp plugin get litespeed-cache --field=version
The pure-Perl implementation of Mojo::JSON in Mojolicious before 9.47 does not limit JSON nesting depth, allowing a small, deeply nested JSON document to trigger unbounded recursion, memory exhaustion, and a process crash. The path is only used when Cpanel::JSON::XS is not installed or MOJO_NO_JSON_XS is set — the Cpanel::JSON::XS fast path already enforces a nesting limit and is not affected.
Betroffen
Mojolicious (Mojo::JSON) before 9.47 — pure-Perl decode path only
Gepatcht
9.47
cPanel & WHM (all supported OS)
perl -MCpanel::JSON::XS -e 'print "fast path OKn"'
# cPanel ships the affected fast path by default — if the check above prints "fast path OK", you are not exposed on cPanel's own stack.
# If it errors, or MOJO_NO_JSON_XS is set, update the Perl Mojo stack:
cpanm [email protected]
Generic Perl / Mojolicious hosts
cpanm [email protected]
perl -MMojo::JSON -e 'print Mojo::JSON->VERSION, "n"'
Dear Exim users, The Exim maintainers are releasing a security fix for four security issues. * GCVE-25-2026-09-50-1 * GCVE-25-2026-09-51-1 * GCVE-25-2026-09-55-1 * GCVE-25-2026-09-56-1 ---- Title: Exim Security Advisory for EXIM-Security-2026-09-12.1 / GCVE-25-2026-09-50-1 Announced: 2026-09-18 Affects: Ex…
Betroffen
4.100.1
Hello, Got an email today: URGENT — Security AdvisoryA critical privilege-escalation vulnerability has been identified in LiteSpeed Web Server Enterprise. On shared-hosting servers, a malicious low-privilege website user could potentially gain root-level access to the server. This could a…
Betroffen
6.3.7
Local privilege escalation due to insecure file permissions. The following products are affected: Acronis Backup plugin for cPanel & WHM (Linux) before build 1.9.3.1021, Acronis Backup extension for Plesk (Linux).
Betroffen
cPanel plugin before 1.9.3.1021 | Plesk extension before 1.8.11.638 | other builds before 1.2.3.238
Gepatcht
1.9.3.1021 / 1.8.11.638 / 1.2.3.238
All supported operating systems
# WHM → Plugins → Marketplace → Installed → Acronis Backup → Update (≥ 1.9.3.1021)
# Plesk → Extensions → Updates → Acronis Backup → Update (≥ 1.8.11.638)
The Paid Downloads plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 3.15 via the admin_request_handler function. This is due to missing authorization.
Betroffen
all versions up to and including 3.15
All supported operating systems
# Update the Paid Downloads plugin to the latest WordPress.org release
wp plugin update --all
This security and maintenance release features 17 bug fixes on Core, 19 bug fixes for the Block Editor, and 11 security fixes. Because this is a security release, it is recommended that you update your sites immediately. You can download WordPress 7.1.1 from WordPress.org, or visit your WordPress Dashboard, cl…
Betroffen
7.1.1
Static Code Injection in Plesk extensions "Ruby" before 1.6.6 and "Node.js Toolkit" before 2.5.0 allows remote authenticated users to execute arbitrary code as root via custom environment variables.
Betroffen
before 1.6.6 | before 2.5.0
All supported operating systems
# Update the Ruby extension stack to the patched release
# Plesk → Extensions → Updates → apply pending updates
Situation We have received notice that a critical privilege-escalation vulnerability has been identified in LiteSpeed Web Server Enterprise. On shared-hosting servers, a malicious low-privilege website user could potentially gain root-level access to the server. This could allow an attacker to access or alter othe…
Path traversal in Plesk's Backup Manager causes arbitrary file write as root by an authenticated customer.
A Time-of-check Time-of-use (TOCTOU) race condition leading to insecure symlink following in Plesk causes local privilege escalation to root via arbitrary file/directory ownership takeover.
SituationA vulnerability was found in the advanced-rule parser in the ConfigServer Security & Firewall (CSF) software which could allow a remote attacker who controls a configured allow/deny feed to execute arbitrary commands as root.Note: By default, no remote allow/deny feed is configured.Affected Product vers…
EL7 (CentOS/CloudLinux 7)
sudo yum update
EL8+ (AlmaLinux/CloudLinux/Rocky)
sudo dnf update
SituationA vulnerability was found in the MESSENGER service in the ConfigServer Security & Firewall (CSF) software which could allow an unauthenticated remote attacker to execute arbitrary commands as the CSF service account.Note: By default, the MESSENGER service is disabled.Affected Product versions Prod…
EL7 (CentOS/CloudLinux 7)
sudo yum update
EL8+ (AlmaLinux/CloudLinux/Rocky)
sudo dnf update
CloudLinux specific take on it: bridge-stp-uaf (CVE-2026-72389) local root vulnerability: kernel update and mitigation for CloudLinux - CloudLinux 📋 TL;DR — last updated September 10, 2026, 16:20 UTC bridge-stp-uaf (CVE-2026-72389, C…
A vulnerability in cPanel allows a mail-enabled account to achieve remote code execution as root through SQLi in EmailTrack component
Use of less trusted source vulnerability in PayTR Payment and Electronic Money Institution Inc. PayTR Virtual Pos iFrame API (v9x) WHMCS Module allows Exploitation of Trusted Identifiers. This issue affects
Improper validation of specified quantity in input vulnerability in PayTR Payment and Electronic Money Institution Inc. PayTR Virtual Pos iFrame API (v9x) WHMCS Module allows Input Data Manipulation. This issue.
Betroffen
v9.0.0 before v9.0.3
Gepatcht
v9.0.3
All supported operating systems
# Replace the PayTR Virtual POS iFrame module with v9.0.3 from the vendor
# WHMCS → Setup → Payment Gateways → confirm the module version
Observable timing discrepancy vulnerability in PayTR Payment and Electronic Money Institution Inc. PayTR Virtual Pos iFrame API (v9x) WHMCS Module allows Black Box Reverse Engineering. This issue affects PayTR Virtual.
Betroffen
v9.0.0 before v9.0.3
Gepatcht
v9.0.3
All supported operating systems
# Replace the PayTR Virtual POS iFrame module with v9.0.3 from the vendor
# WHMCS → Setup → Payment Gateways → confirm the module version
Unauthenticated Remote Code Execution (CVE-2026-67399)
Improved security around email previews
Undisclosed Security Fix
Undisclosed Security Fix
Client Area Authorization Bypass (CVE-2026-29204)
Undisclosed Security Fix
Honour parent theme definition for captcha.tpl on Login as Owner link
Correct bulk removal of IPs on Security tab of General Settings
Unauthenticated Remote Code Execution (CVE-2026-67399)
Improved security around email previews
Undisclosed Security Fix
Undisclosed Security Fix
Client Area Authorization Bypass (CVE-2026-29204)
Undisclosed Security Fix
Add clarifying messaging on Integration Links regarding Captcha
The ShortPixel Adaptive Images – WebP, AVIF, CDN, Image Optimization plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.11.5. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to modify configuration options of third-party plugins including ShortPixel Image Optimizer, Autoptimize, WP Rocket, Imagify, and LiteSpeed Cache, as well as the plugin's own API key and account binding. Exploitation requires the respective third-party plugins to be installed, as the impact against those plugins' settings is only reachable when those plugins are present.
The LiteSpeed Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content in all versions up to, and including, 7.8.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. A comment payload crafted exclusively from decimal numeric character references (e.g. ", <, >) placed inside an allowed element such as <code> bypasses WordPress's wp_kses sanitization, as kses does not treat a data-settings="..." substring within text content as an HTML attribute, allowing the malicious payload to reach the vulnerable function. For this to be exploitable, the site must allow users with previously approved comments to write new comments, and the require_name_email setting must be disabled.
The LiteSpeed Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via crafted `` tag attributes in all versions up to, and including, 7.7. This is due to a
A security vulnerability has been discovered in Phusion Passenger's Watchdog API.
EL7 (CentOS/CloudLinux 7)
sudo yum update
EL8+ (AlmaLinux/CloudLinux/Rocky)
sudo dnf update
A local user's .forward file can trigger unsafe string expansion in Exim's redirect router, allowing command injection under certain pipe transport configurations.
A privilege escalation vulnerability exists in cPanel & WHM's database management functionality.
A vulnerability in the cPanel web server allows manipulation of cpsrvd responses under limited conditions.
WordPress recently announced a few vulnerabilities that were fixed.
Security vulnerabilities tied to the ea-nginx ngx_http_rewrite_module (CVE-2026-9256) have been discovered.
Betroffen
31.1
An unauthenticated endpoint in cpsrvd was found that could allow the insertion of arbitrary HTTP headers. This affects cPanel & WHM versions 132 and higher.
An unsafe symlink handling error was found that allows a user to chmod an arbitrary file, allowing for denial of service and possible privilege escalation.
Apache HTTP Server: http2: Double Free and possible RCE on early reset (CVE-2026-23918). Double Free and possible RCE vulnerability in Apache HTTP Server with the HTTP/2 protocol.
An authentication bypass security issue has been identified in the cPanel software (including DNSOnly) affecting all versions after 11.40.We would like to thank Sybre Waaijer for helping to identify and responsibly report this vulnerability to us.
EL7 (CentOS/CloudLinux 7)
sudo yum update
An authenticated cPanel account holder with mail-related privileges can create arbitrary files on the server through cPanel's EmailTrack functionality.
A vulnerability was found in the MESSENGER service in the ConfigServer Firewall (CSF) software which could allow for unauthorized code execution.
EL7 (CentOS/CloudLinux 7)
sudo yum update
EL8+ (AlmaLinux/CloudLinux/Rocky)
sudo dnf update
An authenticated cPanel account holder who is able to add parked or addon domains can create arbitrary files on the server.
Multiple vulnerabilities were found in the ConfigServer Firewall plugin.
EL7 (CentOS/CloudLinux 7)
sudo yum update
EL8+ (AlmaLinux/CloudLinux/Rocky)
sudo dnf update
Argument injection vulnerability in WP Toolkit before version 6.11.0 as used in cPanel & WHM, allows remote authenticated users to bypass cross-tenant authorization and execute arbitrary wp-toolkit CLI commands as another account.
A combination of two vulnerabilities in the LiteSpeed cPanel plugin allowed an authenticated cPanel user to escalate privileges to root, including on servers running CloudLinux and CageFS.
Security vulnerabilities tied to ea-nginx-njs(CVE-2026-8711) and ea-memcached16(CVE-2026-47783, CVE-2026-47784) have been discovered.
An upstream vulnerability was recently reported for Unbound that affects supported cPanel & WHM versions 126 and higher.
Betroffen
1.25.1
A security vulnerability was found in the plugin provided by LiteSpeed that allowed unauthorized root access to the server.
A vulnerability has been reported that currently affects cPanel & WHM versions 132 and higher.
This security release addresses vulnerabilities across multiple versions of cPanel & WHM, including fixes for several vulnerabilities rated up to High severity.
It was found that SSL verification was not fully enforced in the DNS Cluster system, which could allow for a malicious server to man-in-the-middle the request and capture credentials. This affects cPanel & WHM versions 126 and higher.
It was found that a low-privilege team user (role=default) can escalate to the owner account's full capabilities through the use of certain UAPI modules. This affects cPanel & WHM versions 110 and higher.
It was found that, as part of the sqloptimizer script, it was possible that a created SQL query could be injected with arbitrary SQL queries. This affects all cPanel & WHM versions.
Through a combination of incorrect dropping of privileges and insufficient path filtering, it was possible to read arbitrary files via certain cpdavd endpoints. This affects cPanel & WHM versions 120 and higher.
The vulnerability, tracked as CVE-2026-45185, aka Dead.Letter, has been described as a use-after-free vulnerability in Exim's binary data transmission (BDAT) message body parsing when a TLS connection is handled by GnuTLS.
A Perl code injection method was found in the create_user API call, relating to the plugin parameter.
An arbitrary file read found was found in the feature::LOADFEATUREFILE adminbin call where it does not adequately validate the feature file name. A relative path may be passed as the argument to this call, causing an arbitrary file to be made world-readable.
Several security vulnerabilities were reported in Exim, impacting versions prior to 4.99.2:
An escalation-of-privilege bug in various modules in Apache HTTP Server 2.4.66 and earlier allows local .htaccess authors to read files with the privileges of the httpd user.
Path traversal in Plesk 18.0.79.9 and earlier and 18.0.80 through 18.0.80.5 allows local users to execute arbitrary code as root.
Betroffen
before 18.0.79.9 | 18.0.80 before 18.0.80.5
AlmaLinux / Ubuntu / Debian / CloudLinux / Rocky Linux
plesk installer --select-release-current --reinstall-patch
plesk version
Unauthenticated Server Side Request Forgery (SSRF) in LiteSpeed Cache.
Betroffen
all versions up to and including 7.9
All supported operating systems
wp plugin update litespeed-cache
# or: WordPress → Plugins → LiteSpeed Cache → Update Now
wp plugin get litespeed-cache --field=version
Targeted Security Release For a full list of changes, read the ConfigServer Security & Firewall (CSF) change log.
Betroffen
16.31-1
The JetBackup WordPress plugin before 3.1.23.5 does not verify the role or capabilities of the account it preserves across a restore or migration before granting it administrator privileges, allowing a.
Betroffen
before 3.1.23.5
Gepatcht
3.1.23.5
All supported operating systems
wp plugin update jetbackup
# or: WordPress → Plugins → JetBackup → Update to 3.1.23.5
A critical local privilege escalation via OS command injection vulnerability has been discovered in Plesk for Linux, affecting all versions from 18.0.34 before 18.0.79.9 and 18.0.80.5. The vulnerability allows a.
Betroffen
18.0.34 before 18.0.79.9 | 18.0.80 before 18.0.80.5
AlmaLinux / Ubuntu / Debian / CloudLinux / Rocky Linux
plesk installer --select-release-current --reinstall-patch
plesk version
Ruby is an extensible, interpreted, object-oriented, scripting language. It has features to process text files and to perform system management tasks. Security Fix(es): * zlib: zlib: Memory corruption via buffer overflow in Zlib::GzipReader (CVE-2026-27820) * net-imap: Net::IMAP: Arbitrary IMAP command inj…
Betroffen
4.0
EL8+ (AlmaLinux/CloudLinux/Rocky)
sudo dnf update
Iperf is a tool which can measure maximum TCP bandwidth and tune various parameters and UDP characteristics. Iperf reports bandwidth, delay jitter, and data-gram loss. Security Fix(es): * iperf3: iperf3 server accepts unbounded peer-controlled JSON parameters enabling remote denial of service via resource ex…
EL8+ (AlmaLinux/CloudLinux/Rocky)
sudo dnf update
USN-8555-1 fixed vulnerabilities in Ubuntu Advantage Tools. On Ubuntu 14.04 LTS only, it was discovered that some machines were unable to enable esm-infra-legacy due to a preemptive apt-helper check. This update fixes the problem. We apologize for the inconvenience. Original advisory details: Bilal Teke discover…
Security and maintenance updates We released updated packages for EasyApache 4. This security release hardens the Phusion Passenger agent API authorization boundary so an empty API account database confers no privileges, resolving a local privilege escalation in the Passenger Watchdog API (SEC-75753). The fix is app…
Betroffen
25.79
It was discovered that primitive decoders in openCryptoki produced integer underflows when the encoded length was zero. An attacker could possibly use this issue to trigger out-of-bounds reads. (CVE-2026-40253) It was discovered that openCryptoki incorrectly handled symlinks. An attacker in the token-group could po…
Debian/Ubuntu
sudo apt update && sudo apt upgrade
Dovecot v2.4.5 released ref.: https://github.com/dovecot/core/releases/tag/2.4.5 https://dovecot.org/releases/2.4/
Betroffen
4.5
The JetBackup WordPress plugin before 3.1.23.5 does not perform its multisite authorisation check before serving backup archives and job logs, allowing an administrator of the network's main site who is.
Betroffen
before 3.1.23.5
Gepatcht
3.1.23.5
All supported operating systems
wp plugin update jetbackup
# or: WordPress → Plugins → JetBackup → Update to 3.1.23.5
Insecure direct object reference in Plesk 18.0.79.7 and earlier or 18.0.80 through 18.0.80.3, allows remote authenticated users to read and modify other customers' databases.
Betroffen
0 – 18.0.79.7 | 18.0.80 before 18.0.80.4
AlmaLinux / Ubuntu / Debian / CloudLinux / Rocky Linux
plesk installer --select-release-current --reinstall-patch
plesk version
Improper neutralization of special elements in in Plesk's DNS zone management functionality allows remote authenticated users to disclose arbitrary local files and escalate privileges.
Betroffen
before 18.0.79.11 | 18.0.80 before 18.0.80.7
AlmaLinux / Ubuntu / Debian / CloudLinux / Rocky Linux
plesk installer --select-release-current --reinstall-patch
plesk version
Improper symlink resolution before file access in Plesk allows remote authenticated users to execute arbitrary code as root.
Betroffen
Migrator before 2.36.0, Site Import before 1.12.1
All supported operating systems
# Update the Migrator extension to 2.36.0 and Site Import to 1.12.1
# Plesk → Extensions → Updates → apply pending updates
The kernel packages contain the Linux kernel, the core of any Linux operating system. Security Fix(es): * kernel: accel/ivpu: Fix signed integer truncation in IPC receive (CVE-2026-53202) * kernel: net/sched: act_api: use RCU with deferred freeing for action lifecycle (CVE-2026-53264) Bug Fix(es) and Enh…
EL8+ (AlmaLinux/CloudLinux/Rocky)
sudo dnf update
RtabRace (CVE-2026-68138) is a Linux kernel race in the traffic-control subsystem that lets an unprivileged local user corrupt kernel memory. On CloudLinux the reliably reachable result is a host crash, and CloudLinux 8 and CloudLinux 7 Hybrid ship exposed. Here is how to check whether a server is exposed and what t…
EL7 (CentOS/CloudLinux 7)
sudo yum update
EL8+ (AlmaLinux/CloudLinux/Rocky)
sudo dnf update
Debian/Ubuntu
sudo apt update && sudo apt upgrade
https://support.cpanel.net/hc/en-us/articles/42503837957015-Security-CSF-Security-Release Since DirectAdmin maintains its own CSF ‘fork’ and quite a lot of DirectAdmin servers are still running CSF, is DA aware of these vulnerabilities and are there plans to release fixes for the DirectAdmin version?
BadGarbage (CVE-2026-53361) is a Linux kernel race condition that lets any local user, including a process inside a container, become root on the host. It affects CloudLinux 10 only. CloudLinux 7 through 9 are not affected. There is no runtime mitigation, so the fix is the patched kernel or a KernelCare livepatch. H…
EL7 (CentOS/CloudLinux 7)
sudo yum update
EL8+ (AlmaLinux/CloudLinux/Rocky)
sudo dnf update
Maintenance and Security Release We released updated packages for EasyApache 4. This release resolves three PHP vulnerabilities across ea-php82, ea-php83, ea-php84, and ea-php85: a libgd vulnerability (CVE-2026-9672), a SQL injection via backslash breakout in PGSQL (CVE-2026-17543), and a crash via recursive symlink…
Betroffen
25.77
It was discovered that libgit2 incorrectly handled the Git Smart Protocol. A remote attacker could possibly use this issue to cause a denial of service or execute arbitrary code. This issue only affected Ubuntu 14.04 LTS and Ubuntu 16.04 LTS. (CVE-2016-10128) It was discovered that libgit2 incorrectly handled empty…
Debian/Ubuntu
sudo apt update && sudo apt upgrade
WordPress 7.0.4 is now available WordPress 7.0.4 is now available which features a security fix. Because this is a security release, it is recommended that you update your sites immediately. You can update to WordPress 7.0.4 by downloading it from WordPress.org, or visiting your site’s Dashboard → Updates and …
Betroffen
7.0.4
Security updates 1.6.18 and 1.7.3 released ref.: https://roundcube.net/news/2026/08/09/security-updates-1.6.18-and-1.7.3
Betroffen
1.6.18
Security fixes This security release resolves several vulnerabilities in CSF (CPANEL-54191, CPANEL-55183, CPANEL-54192, CPANEL-55265). It also includes several firewall reliability fixes for AlmaLinux 10, Debian, and Ubuntu. For a full list of changes, read the ConfigServer Security & Firewall (CSF) change log.
Betroffen
16.30-1
Faster site publishing Sitejet Builder now downloads website files in parallel when you publish a site. This reduces publish time for large sites. For a full list of changes, read the Sitejet Builder change log.
Betroffen
4.12.0-1
Introduced the Meridian interface We introduced Meridian, a new goal-based cPanel interface. Meridian organizes common hosting tasks into six purpose-built hubs for Websites, Email, Files, Databases, Security, and Performance. Its Dashboard highlights required actions, suggests relevant next steps, and provides an a…
Security Hotfix We released an updated ea-nginx package family (nginx 1.31.3) for EasyApache 4. This security release resolves three nginx vulnerabilities, including a critical heap buffer overflow in the map directive with regular expressions (CVE-2026-42533) that could allow remote code execution or a worker proce…
Betroffen
25.74
Maintenance updates We released updated packages for EasyApache 4. This maintenance release includes updates to ea-passenger-src (v6.1.8), ea-ruby27-passenger (v6.1.8), ea-redis62 (v6.2.23), ea-valkey72 (v7.2.14), ea-memcached16 (v1.6.45), and ea-podman (v1.0-23), plus companion rebuilds for ea-apache24-mod-passenge…
Betroffen
25.76
Stronger two-factor authentication for API requests We’ve added a Security Policy that closes a gap in API authentication: when it’s enabled alongside two-factor authentication (2FA), API requests can no longer skip 2FA protection. Once you turn on both settings, the system handles inbound API requests a…
Maintenance updates We released updated ea-tomcat101, ea-memcached16, ea-apache24-mod_security2, ea-modsec2-rules-owasp-crs, ea-ioncube15, ea-nodejs22, and Phusion Passenger 6.1.7 (ea-passenger-src, ea-ruby27-passenger, ea-apache24-mod-passenger, ea-nginx-passenger) packages for EasyApache 4. This maintenance releas…
Betroffen
25.73
Maintenance updates We released updated ea-modsec30, ea-modsec30-connector-apache24, and ea-modsec30-rules-owasp-crs packages for EasyApache 4. This maintenance release fixes ModSecurity audit logs silently failing to write across mod_ruid2 user IDs, forces a full Apache restart on package update so the updated libm…
Betroffen
25.72
Bug fixes This release fixes Comet Backup jobs failing en masse with locked-by-device retention errors on busy servers. The plugin now requests the less-often automatic-retention ruleset for dispatched backups and no longer cancels orphaned in-flight jobs, so overlapping retention passes cannot wedge the device.
Betroffen
1.5.6
Security hotfix We released updated ea-modsec30 and ea-modsec30-rules-owasp-crs packages for EasyApache 4. This security hotfix updates ea-modsec30 to 3.0.16, addressing two issues: CVE-2026-52747 (the multipart/form-data request body parser invalidly handled r and characters, allowing an unauthenticated WAF rule b…
Betroffen
25.71
Improved read-only API token enforcement Sitejet Builder UAPI methods are now classified as read-only for cPanel & WHM API token enforcement. For a full list of changes, read the Sitejet Builder change log.
Betroffen
4.11.0-1
Security and maintenance updates We released updated packages for EasyApache 4. This security release updates PHP 8.2, 8.3, 8.4, and 8.5 to address CVE-2026-14355 (a memory corruption issue in openssl_encrypt with AES-WRAP-PAD) and, for PHP 8.3, CVE-2026-12184 (a TLS setup failure leading to remote DoS). It also upd…
Betroffen
25.70
Security and maintenance updates We released an updated ea-tomcat101 package for EasyApache 4. This security release updates Apache Tomcat to 10.1.56, addressing six CVEs (CVE-2026-55956, CVE-2026-55955, CVE-2026-55276, CVE-2026-53434, CVE-2026-53404, CVE-2026-50229) with a top severity of Moderate. For a full list …
Betroffen
25.69
Maintenance updates We released updated packages for EasyApache 4. This maintenance release updates three nginx scripting and header modules: ea-nginx-echo to v0.65 (OOM safety fix), ea-nginx-headers-more to v0.40 (Content-Type charset parsing fix), and ea-nginx-njs to v1.0.0 (major version; includes security harden…
Betroffen
25.68
Bug fix We released a bug fix update for Site Quality Monitoring. * SQM-227: Fixed an infinite redirect loop and repeated authentication emails when re-opening Site Quality Monitoring from cPanel. For a full list of changes, read the Site Quality Monitoring change log.
Betroffen
3.2.0-1
Removed Sitejet AI promotional banner We removed the Sitejet AI promotional banner from the cPanel Tools page. This does not change Sitejet Builder functionality. For a full list of changes, read the Sitejet Builder change log.
Betroffen
4.10.0-1
Security updates We released updated packages for EasyApache 4. This security release updates ea-nginx from v1.31.1 to v1.31.2, addressing two CVEs from the nginx 2026-06-17 advisory: CVE-2026-42055 (Medium: buffer overflow in ngx_http_proxy_v2_module and ngx_http_grpc_module) and CVE-2026-48142 (Low: buffer over-re…
Betroffen
25.67
Security and maintenance updates We released updated packages for EasyApache 4. This security and maintenance release patches ea-openssl11 to 1.1.1w-8 (CentOS 7 only) with TuxCare/ELS backports addressing five CVEs including four High-severity issues (CVE-2026-45447, CVE-2026-34180, CVE-2026-7383, CVE-2026-9076). It…
Betroffen
25.66
AWS partner rollout Server Monitoring rollout for the AWS partner. For a full list of changes, read the Server Monitoring change log.
Betroffen
2.8.0-1
DigitalOcean partner rollout Server Monitoring rollout for the DigitalOcean partner. For a full list of changes, read the Server Monitoring change log.
Betroffen
2.7.0-1
Security and maintenance updates We released updated packages for EasyApache 4. This security and maintenance release updates ea-apache24 to v2.4.68, which addresses thirteen CVEs in the Apache HTTP Server including two critical mod_http2 issues (CVE-2026-49975, CVE-2026-48913). It also updates the Passenger ecosyst…
Betroffen
25.65
Google Cloud partner rollout Server Monitoring rollout for the Google Cloud partner. For a full list of changes, read the Server Monitoring change log.
Betroffen
2.6.0-1
Bug fixes This release fixes an issue where WebPros remote storage did not update after a Comet Backup license change, and enables cloud storage provisioning from the Destinations tab on storage-tier licenses with re-authentication resume.
Betroffen
1.5.5
Improved permission and domain-ownership validation Improve permission and domain-ownership validation for Sitejet actions. For a full list of changes, read the Sitejet Builder change log.
Betroffen
4.9.0-1
Bug fixes and improvements This release stops Comet backups from consuming all local disk space during a backup run, fixes restore backup options being hidden in the UI when no backup jobs exist, ensures the outbound User-Agent is not inherited from the parent process, removes the credentials download warning, and …
Betroffen
1.5.4
Security and maintenance updates We released updated packages for EasyApache 4. This security release patches CVE-2026-49975 in ea-apache24. Attackers can craft malicious HTTP/2 cookie headers that multiply across streams, consuming excessive memory. The fix makes cookie headers count against LimitRequestFields. Not…
Betroffen
25.64
Hotfix security release We released updated packages for EasyApache 4. This release addresses CVE-2026-9256 (nginx-poolslip), a critical remote code execution vulnerability affecting all nginx versions, fixed in ea-nginx 1.31.1. Phusion Passenger was also updated to version 6.1.3. For a full list of changes, read th…
Betroffen
25.63
Updated publish/polling access controls Improve Sitejet publish/polling access controls. For a full list of changes, read the Sitejet Builder change log.
Betroffen
4.8.0-1
Hotfix security release We released updated packages for EasyApache 4. This release addresses CVE-2026-8711 in ea-nginx-njs and CVE-2026-47783, CVE-2026-47784 in ea-memcached16. For a full list of changes, read the EasyApache 4 change log.
Betroffen
25.62
Maintenance release We released updated packages for EasyApache 4. For a full list of changes, read the EasyApache 4 change log.
Betroffen
25.61
Bug fixes Fixed regex.custom.pm custom rules silently failing to match log lines (CPANEL-53173). Fixed csf -cf $file no longer retaining newlines in the file (CPANEL-52801). For a full list of changes, read the ConfigServer Security & Firewall (CSF) change log.
Betroffen
16.20-1
SPA modal notification for new activations SPA modal notification after plugin activation. New partner rollout. For a full list of changes, read the Server Monitoring change log.
Betroffen
2.5.0-1
Conditional Server Monitoring registration Server Monitoring now only registers in WHM when it has been set up. For a full list of changes, read the Server Monitoring change log.
Betroffen
2.4.0-1
New "Start Monitoring" onboarding experience We updated the server monitoring setup flow. New servers no longer automatically create anonymous accounts. A new "Start Monitoring" button in the top widget lets users set up monitoring for servers without an anonymous account on demand. For a full li…
Betroffen
2.3.0-1
Security update We released updated packages for EasyApache 4. This security release addresses CVE-2026-42945 (Critical: heap buffer overflow in ngx_http_rewrite_module) in ea-nginx (v1.30.0 to v1.31.0), along with rebuilds of ea-nginx-echo, ea-nginx-headers-more, ea-nginx-passenger, and ea-nginx-njs against the pat…
Betroffen
25.60
Security and maintenance updates We released updated packages for EasyApache 4. This security release addresses CVE-2026-43515 and CVE-2026-43512 (Moderate) and five Low-severity CVEs in ea-tomcat101 (v10.1.54 to v10.1.55), and includes a heap buffer overflow fix in ea-apache24-mod_security2 (no CVE assigned) along …
Betroffen
25.59
Security and maintenance updates We released updated packages for EasyApache 4. This security release addresses CVE-2026-6735, CVE-2026-7259, CVE-2025-14179, CVE-2026-6722, CVE-2026-7261, CVE-2026-7262, CVE-2026-7568, and CVE-2026-7258 in ea-php82, ea-php83, ea-php84, and ea-php85. For a full list of changes, read t…
Betroffen
25.58
Security and maintenance updates We released updated packages for EasyApache 4. This security release updates ea-apache24 to 2.4.67, addressing 11 CVEs including an important remote code execution vulnerability (CVE-2026-23918 in mod_http2). It also patches ea-libcurl (CentOS 7 only) with 6 security fixes backported…
Betroffen
25.57
Managesieve LFD alert fix Added managesieve-login to csf.pignore to prevent excessive LFD resource alerts triggered by the Dovecot managesieve plugin (CPANEL-52448). For a full list of changes, read the ConfigServer Security & Firewall (CSF) change log.
Betroffen
16.18-1
LFD startup and detection fixes Fixed multiple LFD issues: brute-force IMAP/POP3 login failure detection on Dovecot 2.4, LFD not starting after cPanel version upgrades, firewall rules failing to load after package upgrades, and LFD startup crashes when /etc/csf/csf.error is absent. For a full list of changes, read t…
Betroffen
16.17-1
Annual billing now available for Solo, Admin, and Pro licenses Annual billing is now available for cPanel Solo ($329.49/year), Admin ($395.49/year), and Pro ($593.49/year) licenses in the <a href="https://store.cpanel.net/store/cpanel-licenses" target="_blank">cPanel Store. Annual subscript…
Maintenance updates We released updated packages for EasyApache 4. This maintenance release updates ea-nginx-njs from v0.9.6 to v0.9.7 and marks ea-scl-php54, ea-scl-php55, ea-scl-php56, ea-scl-php70, ea-scl-php71, ea-scl-php72, ea-scl-php73, ea-php74, ea-php80, ea-php81, ea-nodejs16, ea-nodejs18, ea-scl-ruby24, and…
Betroffen
25.56
Maintenance updates We released updated packages for EasyApache 4. This maintenance release includes an ea-nginx update from v1.29.8 to v1.30.0 with five associated module rebuilds, a libxml2 update from v2.15.2 to v2.15.3, and an nghttp2 update from v1.68.1 to v1.69.0. For a full list of changes, read the EasyApach…
Betroffen
25.55
Fixed enabling Vulnerability Protection with large vulnerability sets Enabling Vulnerability Protection no longer fails with a STDIN data is corrupted error when a WordPress installation contains a large number of vulnerabilities.
Betroffen
6.10.1
Security and maintenance updates We released updated packages for EasyApache 4. This security and maintenance release includes a security patch for ea-openssl11 (CVE-2026-28387, CVE-2026-28388, CVE-2026-28389, CVE-2026-28390), version updates for ea-php84 (8.4.19 to 8.4.20) and ea-php85 (8.5.4 to 8.5.5), and an ea-n…
Betroffen
25.54
Security Risk ratings for WordPress sites and components WP Toolkit now introduces a Security Risk rating for WordPress sites and individual components. This rating helps administrators quickly identify which vulnerable sites or plugins require attention first. As part of this change, the previous Vulnerabilities wi…
Betroffen
6.10.0
Updated monitoring polling interval DUCKS-5510: We updated the monitoring polling interval for signed and anonymous accounts. We also updated the permissions for the agent360.sh script. For a full list of changes, read the Server Monitoring change log.
Betroffen
2.2.0-1
Security and maintenance updates We released updated packages for EasyApache 4. This security and maintenance release includes CVE fixes for ea-ruby27-rubygem-rack (CVE-2026-34830, CVE-2026-34785) and ea-modsec2-rules-owasp-crs (CVE-2026-33691), and maintenance updates for ea-tomcat101, ea-re2c, and ea-cpanel-tools.…
Betroffen
25.53
cPanel & WHM updates now provide ConfigServer Security & Firewall (CSF) WebPros International, LLC has created a fork of CSF (ConfigServer Security & Firewall) for cPanel & WHM. We distribute this new fork of CSF via our update mirrors. cPanel & WHM will migrate any unsupported or outdated versio…
Updated Sitejet default feature list Sitejet Builder no longer enables itself in standalone Nova’s default feature list. For a full list of changes, read the Sitejet Builder change log.
Betroffen
4.7.1-1
Maintenance updates Package build maintenance updates for Sitejet Builder. For a full list of changes, read the Sitejet Builder change log.
Betroffen
4.7.0-1
Maintenance updates Package build maintenance updates for Site Quality Monitoring. For a full list of changes, read the Site Quality Monitoring change log.
Betroffen
3.1.0-1
Maintenance updates Package build maintenance updates for Server Monitoring. For a full list of changes, read the Server Monitoring change log.
Betroffen
2.1.0-1
Security and maintenance updates We released updated packages for EasyApache 4. This security and maintenance release addresses 6 CVEs in ea-nginx 1.29.7, 7 CVEs in ea-nodejs22 and ea-nodejs20, and 1 CVE in ea-nghttp2 (CVE-2026-27135). It also includes a proxy configuration fix for Apache 2.4.64+ compatibility, ngin…
Betroffen
25.52
Maintenance and security updates We released updated packages for EasyApache 4. This maintenance and security release includes security backports for ea-libcurl (4 CVEs from curl 8.19.0), version updates for ea-php84, ea-php85, and ea-nginx, and bug fixes for ea-apache24 and ea-cpanel-tools. For a full list of chang…
Betroffen
25.51
Package removal cleanup fix Fixed an issue where uninstalling cpanel-csf left the CSF plugin entry and LFD service status behind in WHM (CPANEL-51933). Also suppresses harmless errors on missing symlinks during upgrades. For a full list of changes, read the ConfigServer Security & Firewall (CSF) change log.
Betroffen
16.12-1
Maintenance updates We released updated packages for EasyApache 4. This maintenance release includes bug fixes for ea-nginx and version updates for ea-nginx-njs, ea-memcached16, ea-ruby27-libuv, ea-nodejs22, and ea-nodejs20. For a full list of changes, read the EasyApache 4 change log.
Betroffen
25.50
Package upgrade behavior fix Fixed an issue where upgrading cpanel-csf would overwrite custom csf-cron entries. For a full list of changes, read the ConfigServer Security & Firewall (CSF) change log.
Betroffen
16.11-1
The resource-agents packages provide the Pacemaker and RGManager service managers with a set of scripts. These scripts interface with several services to allow operating in a high-availability (HA) environment. Security Fix(es): * urllib3: urllib3: Information disclosure via cross-origin redirects forwarding…
EL8+ (AlmaLinux/CloudLinux/Rocky)
sudo dnf update
The libtiff3 package provides libtiff 3, an older version of libtiff library for manipulating TIFF (Tagged Image File Format) image format files. This version should be used only if you are unable to use the current version of libtiff. Security Fix(es): * libtiff: libtiff: Heap-based buffer overflow via craf…
EL8+ (AlmaLinux/CloudLinux/Rocky)
sudo dnf update
Yelp is the help browser for the GNOME desktop. It is designed to help you browse all the documentation on your system in one central tool, including traditional man pages, info pages and documentation written in DocBook. Security Fix(es): * yelp: yelp-xsl: Overly Permissive Content Security Policy in Yelp A…
EL8+ (AlmaLinux/CloudLinux/Rocky)
sudo dnf update
The libgcrypt library provides general-purpose implementations of various cryptographic algorithms. Security Fix(es): * Libgcrypt: Libgcrypt: Denial of Service and buffer overflow via crafted ECDH ciphertext (CVE-2026-41989) For more details about the security issue(s), including the impact, a CVSS score, …
EL8+ (AlmaLinux/CloudLinux/Rocky)
sudo dnf update
The kernel-rt packages provide the Real Time Linux Kernel, which enables fine-tuning for systems with extremely high determinism requirements. Security Fix(es): * kernel: xen: AMD Zen 2 Processors: Privilege escalation via improper CPU cache isolation (CVE-2025-54518) Bug Fix(es) and Enhancement(s): *…
EL8+ (AlmaLinux/CloudLinux/Rocky)
sudo dnf update
The kernel packages contain the Linux kernel, the core of any Linux operating system. Security Fix(es): * kernel: xen: AMD Zen 2 Processors: Privilege escalation via improper CPU cache isolation (CVE-2025-54518) Bug Fix(es) and Enhancement(s): * Kernel crash in bpf_for_each_array_elem() due to missing…
EL8+ (AlmaLinux/CloudLinux/Rocky)
sudo dnf update
The kernel packages contain the Linux kernel, the core of any Linux operating system. Security Fix(es): * kernel: Linux kernel: Denial of Service due to NULL function pointer race in timer shutdown (CVE-2025-68214) Bug Fix(es) and Enhancement(s): * Possible regression with FM350GL [almalinux-9.8.z] (J…
EL8+ (AlmaLinux/CloudLinux/Rocky)
sudo dnf update
The kernel packages contain the Linux kernel, the core of any Linux operating system. Security Fix(es): * kernel: ipc: limit next_id allocation to the valid ID range (CVE-2026-52923) * kernel: tipc: fix double-free in tipc_buf_append() (CVE-2026-52993) * kernel: net: sched: UAF via missing handler for TC…
EL8+ (AlmaLinux/CloudLinux/Rocky)
sudo dnf update
Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language. Security Fix(es): * brace-expansion: Brace-expansion: Denial of Service due to exponential-time complexity (CVE-2026-13149) * tar: Node-tar: Denial of Service via malforme…
EL8+ (AlmaLinux/CloudLinux/Rocky)
sudo dnf update
FRRouting is free software that manages TCP/IP based routing protocols. It supports BGP4, OSPFv2, OSPFv3, ISIS, RIP, RIPng, PIM, NHRP, PBR, EIGRP and BFD. Security Fix(es): * frr: FRRouting: Denial of Service via crafted BGP UPDATE message (CVE-2026-37460) Bug Fix(es) and Enhancement(s): * Zebra is n…
EL8+ (AlmaLinux/CloudLinux/Rocky)
sudo dnf update
The sg3_utils packages provide command-line utilities for devices that use the Small Computer System Interface (SCSI) command sets. Security Fix(es): * sg3_utils: sg3_utils: arbitrary command execution via udev property injection in sg_inq --export (CVE-2026-16313) Bug Fix(es) and Enhancement(s): * sg…
EL8+ (AlmaLinux/CloudLinux/Rocky)
sudo dnf update
Mozilla Thunderbird is a standalone mail and newsgroup client. Security Fix(es): * firefox: thunderbird: Site isolation issue in the DOM: Navigation component (CVE-2026-15719) * firefox: thunderbird: Invalid pointer in the JavaScript: WebAssembly component (CVE-2026-15718) * firefox: thunderbird: Mitigat…
EL8+ (AlmaLinux/CloudLinux/Rocky)
sudo dnf update
The ldns packages contain a library with the aim to simplify DNS programming in C. All low-level DNS/DNSSEC operations are supported. We also define a higher level API which allows a programmer to (for instance) create or sign packets. Security Fix(es): * ldns: ldns: Off-path poisoning attacks due to insuffi…
EL8+ (AlmaLinux/CloudLinux/Rocky)
sudo dnf update
The p11-kit packages provide a mechanism to manage PKCS#11 modules. The p11-kit-trust subpackage includes a PKCS#11 trust module that provides certificate anchors and black lists based on configuration files. Security Fix(es): * p11-kit: Stack exhaustion via unbounded recursion in RPC attribute parsing (CVE-…
EL8+ (AlmaLinux/CloudLinux/Rocky)
sudo dnf update
Yelp is the help browser for the GNOME desktop. It is designed to help you browse all the documentation on your system in one central tool, including traditional man pages, info pages and documentation written in DocBook. Security Fix(es): * yelp: yelp-xsl: Overly Permissive Content Security Policy in Yelp A…
EL8+ (AlmaLinux/CloudLinux/Rocky)
sudo dnf update
PipeWire is a multimedia server for Linux and other Unix like operating systems. Security Fix(es): * pipewire: PipeWire: Sandbox escape and arbitrary code execution via malicious library loading (CVE-2026-5674) For more details about the security issue(s), including the impact, a CVSS score, acknowledgment…
EL8+ (AlmaLinux/CloudLinux/Rocky)
sudo dnf update
X.Org X11 libXfont2 runtime library Security Fix(es): * libXfont2: BitmapScaleBitmaps Integer Overflow Heap Buffer Overflow (CVE-2026-56001) * libXfont2: PCF Font Parsing Heap Buffer Overflow (CVE-2026-56002) For more details about the security issue(s), including the impact, a CVSS score, acknowledgment…
EL8+ (AlmaLinux/CloudLinux/Rocky)
sudo dnf update
The fence-agents packages provide a collection of scripts for handling remote power management for cluster devices. They allow failed or unreachable nodes to be forcibly restarted and removed from the cluster. Security Fix(es): * httplib2: httplib2: Denial of Service via unbounded decompression of HTTP resp…
EL8+ (AlmaLinux/CloudLinux/Rocky)
sudo dnf update
The GIMP (GNU Image Manipulation Program) is an image composition and editing program. GIMP provides a large image manipulation toolbox, including channel operations and layers, effects, sub-pixel imaging and anti-aliasing, and conversions, all with multi-level undo. Security Fix(es): * gimp: GIMP APNG loade…
EL8+ (AlmaLinux/CloudLinux/Rocky)
sudo dnf update
The OpenJDK 25 packages provide the OpenJDK 25 Java Runtime Environment and the OpenJDK 25 Java Software Development Kit. Security Fix(es): * JDK: Enhance TLS certificate handling (CVE-2026-46968) * JDK: Improve DTLS handshaking (CVE-2026-46917) * JDK: Enhance JPEG handling (CVE-2026-47010) * JDK: Enha…
EL8+ (AlmaLinux/CloudLinux/Rocky)
sudo dnf update
Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language. Security Fix(es): * brace-expansion: Brace-expansion: Denial of Service due to exponential-time complexity (CVE-2026-13149) * tar: Node-tar: Denial of Service via malforme…
EL8+ (AlmaLinux/CloudLinux/Rocky)
sudo dnf update
GStreamer is a streaming media framework based on graphs of filters which operate on media data. The gstreamer1-plugins-bad-free package contains a collection of plug-ins for GStreamer. Security Fix(es): * gstreamer: gstreamer: rfbsrc/librfb Hextile heap out-of-bounds write with 16bpp framebuffer (CVE-2026-5…
EL8+ (AlmaLinux/CloudLinux/Rocky)
sudo dnf update
Multiple vulnerabilities were found in the ConfigServer Firewall (CSF) plugin. Exploiting the vulnerabilities could allow an attacker to gain root access.
Betroffen
16.20-1 and earlier
Gepatcht
16.30-1
CentOS 7 / CloudLinux 7
yum clean all
/scripts/update-packages
AlmaLinux / CloudLinux 8/9/10
dnf clean metadata
/scripts/update-packages
A remote code execution vulnerability was discovered in the cPanel email filters interface. Attackers with a low-privilege account could execute commands as root.
Betroffen
TUI 18.0.42 and earlier
Gepatcht
TUI 18.0.48
CentOS 7 / CloudLinux 7
yum clean all
/scripts/upcp --force
AlmaLinux 9 / CloudLinux 9
dnf clean metadata
/scripts/upcp --force
A vulnerability in CloudLinux LVE Manager allowed environment variable injection via the $HTTP_HOST header, potentially leading to unauthorized access to protected resources.
Betroffen
7.4 and earlier
Gepatcht
7.5
CloudLinux 7
yum clean all
yum update cl-lve
CloudLinux 9
dnf clean metadata
dnf update cl-lve
A heap buffer overflow was identified in LiteSpeed Web Server HTTP/2 handling. A crafted request could cause a crash or remote code execution.
Betroffen
6.0.4 and earlier
Gepatcht
6.0.5
CentOS 7
yum clean all
/usr/local/lsws/bin/lshttpd -v
AlmaLinux 9
dnf clean metadata
/usr/local/lsws/bin/lshttpd -v
A privilege escalation flaw in DirectAdmin allowed a user to escalate privileges and gain access to other accounts on the same server.
Betroffen
1.660 and earlier
Gepatcht
1.661
CentOS 7 / AlmaLinux 9
da-setup da
/usr/local/directadmin/scripts/update.sh
Ubuntu 22.04 / Debian 12
da-setup da
/usr/local/directadmin/scripts/update.sh
A stored cross-site scripting (XSS) vulnerability was found in the WHMCS admin panel, allowing an authenticated user to inject malicious scripts.
Betroffen
8.7.0 and earlier
Gepatcht
8.7.1
Any supported OS
cd /var/www/html
php composer.phar update whmcs/core
A Linux kernel KVM flaw affecting CloudLinux 7h-10, including servers running no VMs. Checks, mitigation and fix status. The post Zapscape (CVE-2026-64561) KVM guest escape and local root: mitigation and kernel update for CloudLinux appeared first on CloudLinux.
EL7 (CentOS/CloudLinux 7)
sudo yum update
EL8+ (AlmaLinux/CloudLinux/Rocky)
sudo dnf update
Debian/Ubuntu
sudo apt update && sudo apt upgrade
A kernel-level exploit bypass was discovered in Imunify360 active protection, reducing effectiveness of exploit detection on newer kernels.
Betroffen
5.5.0 and earlier
Gepatcht
5.6.0
CentOS 7 / AlmaLinux 9
yum clean all
yum update imunify360-firewall
Ubuntu 22.04
apt update
apt install --only-upgrade imunify360-firewall
A configuration issue in JetBackup could expose S3 storage credentials in server logs, potentially compromising backup destinations.
Betroffen
5.3.0 and earlier
Gepatcht
5.3.1
CentOS 7 / AlmaLinux 9
yum clean all
yum update jetbackup
Zapscape (CVE-2026-64561) is a Linux kernel KVM vulnerability enabling guest-to-host escape and local root privilege escalation on CloudLinux 7–10, including hosts running no VMs. Fixed in the August 6, 2026 kernel update.
EL7 (CentOS/CloudLinux 7)
sudo yum update
EL8+ (AlmaLinux/CloudLinux/Rocky)
sudo dnf update
Debian/Ubuntu
sudo apt update && sudo apt upgrade
Yes another local privilege escalation vulnerability was recently publicly announced - dirtyfrag.io. Mitigation does not require server reboot, only making sure kernel modules esp4, esp6 and rxrpc are disabled. Code: : > /etc/modprobe.d/dirtyfrag.conf echo 'install esp4 /bin/false' &…
WordPress 7.0.3 is now available WordPress 7.0.3 is now available which features several security fixes. Because this is a security release, it is recommended that you update your sites immediately. You can update to WordPress 7.0.3 by downloading it from WordPress.org, or visiting your site’s Dashboard …
Betroffen
7.0.3
The fence-agents packages provide a collection of scripts for handling remote power management for cluster devices. They allow failed or unreachable nodes to be forcibly restarted and removed from the cluster. Security Fix(es): * urllib3: urllib3: Information disclosure via cross-origin redirects forwarding…
EL8+ (AlmaLinux/CloudLinux/Rocky)
sudo dnf update
The kernel-rt packages provide the Real Time Linux Kernel, which enables fine-tuning for systems with extremely high determinism requirements. Security Fix(es): * kernel: ipc: limit next_id allocation to the valid ID range (CVE-2026-52923) Bug Fix(es) and Enhancement(s): * AlmaLinux8.10 - KVM: s390: L…
EL8+ (AlmaLinux/CloudLinux/Rocky)
sudo dnf update
The kernel packages contain the Linux kernel, the core of any Linux operating system. Security Fix(es): * kernel: ipc: limit next_id allocation to the valid ID range (CVE-2026-52923) Bug Fix(es) and Enhancement(s): * AlmaLinux8.10 - KVM: s390: Limit adapter indicator access to mapped page (JIRA:AlmaLi…
EL8+ (AlmaLinux/CloudLinux/Rocky)
sudo dnf update
Mozilla Thunderbird is a standalone mail and newsgroup client. Security Fix(es): * firefox: thunderbird: Site isolation issue in the DOM: Navigation component (CVE-2026-15719) * firefox: thunderbird: Invalid pointer in the JavaScript: WebAssembly component (CVE-2026-15718) * firefox: thunderbird: Mitigat…
EL8+ (AlmaLinux/CloudLinux/Rocky)
sudo dnf update
DBI is a database access Application Programming Interface (API) for the Perl Language. The DBI API Specification defines a set of functions, variables and conventions that provide a consistent database interface independent of the actual database being used. Security Fix(es): * DBI: DBI: Arbitrary code exec…
EL8+ (AlmaLinux/CloudLinux/Rocky)
sudo dnf update
The ldns packages contain a library with the aim to simplify DNS programming in C. All low-level DNS/DNSSEC operations are supported. We also define a higher level API which allows a programmer to (for instance) create or sign packets. Security Fix(es): * ldns: ldns: Off-path poisoning attacks due to insuffi…
EL8+ (AlmaLinux/CloudLinux/Rocky)
sudo dnf update
Archive::Tar provides an object oriented mechanism for handling tar files. It provides class methods for quick and easy files handling while also allowing for the creation of tar file objects for custom manipulation. If you have the IO::Zlib module installed, Archive::Tar will also support compressed or gzipped tar …
EL8+ (AlmaLinux/CloudLinux/Rocky)
sudo dnf update
GLib provides the core application building blocks for libraries and applications written in C. It provides the core object system used in GNOME, the main loop implementation, and a large set of utility functions for strings and common data structures. Security Fix(es): * glib: GLib: Buffer underflow in GVar…
EL8+ (AlmaLinux/CloudLinux/Rocky)
sudo dnf update
FRRouting is free software that manages TCP/IP based routing protocols. It supports BGP4, OSPFv2, OSPFv3, ISIS, RIP, RIPng, PIM, NHRP, PBR, EIGRP and BFD. Security Fix(es): * frr: FRRouting: Denial of Service via crafted BGP UPDATE message (CVE-2026-37460) For more details about the security issue(s), inc…
EL8+ (AlmaLinux/CloudLinux/Rocky)
sudo dnf update
Archive::Tar provides an object oriented mechanism for handling tar files. It provides class methods for quick and easy files handling while also allowing for the creation of tar file objects for custom manipulation. If you have the IO::Zlib module installed, Archive::Tar will also support compressed or gzipped tar …
EL8+ (AlmaLinux/CloudLinux/Rocky)
sudo dnf update
Perl is a high-level programming language that is commonly used for system administration utilities and web programming. Security Fix(es): * perl-Archive-Tar: perl-Archive-Tar: Denial of Service via crafted tar header with large entry size (CVE-2026-9538) For more details about the security issue(s), inclu…
Betroffen
5.32
EL8+ (AlmaLinux/CloudLinux/Rocky)
sudo dnf update
The kernel-rt packages provide the Real Time Linux Kernel, which enables fine-tuning for systems with extremely high determinism requirements. Security Fix(es): * kernel: rtnetlink: add missing netlink_ns_capable() check for peer netns (CVE-2026-31692) * kernel: netfilter: ctnetlink: ensure safe access to …
EL8+ (AlmaLinux/CloudLinux/Rocky)
sudo dnf update
The kernel packages contain the Linux kernel, the core of any Linux operating system. Security Fix(es): * kernel: rtnetlink: add missing netlink_ns_capable() check for peer netns (CVE-2026-31692) * kernel: netfilter: ctnetlink: ensure safe access to master conntrack (CVE-2026-43116) * kernel: fanotify: f…
EL8+ (AlmaLinux/CloudLinux/Rocky)
sudo dnf update
The kernel packages contain the Linux kernel, the core of any Linux operating system. Security Fix(es): * kernel: xfrm: Duplicate SPI Handling (CVE-2025-39797) * kernel: lib/buildid: use __kernel_read() for sleepable context (CVE-2026-23002) * kernel: futex: Drop CLONE_THREAD requirement for private defa…
EL8+ (AlmaLinux/CloudLinux/Rocky)
sudo dnf update
Maxim Suhanov discovered that the NTFS file system implementation in the Linux kernel did not properly validate file name length in certain situations, leading to an out-of-bounds read. An attacker could use this to construct a malicious NTFS image that, when mounted and operated on, could expose sensitive informati…
Debian/Ubuntu
sudo apt update && sudo apt upgrade
Maxim Suhanov discovered that the NTFS file system implementation in the Linux kernel did not properly validate file name length in certain situations, leading to an out-of-bounds read. An attacker could use this to construct a malicious NTFS image that, when mounted and operated on, could expose sensitive informati…
Debian/Ubuntu
sudo apt update && sudo apt upgrade
The unbound packages provide a validating, recursive, and caching DNS or DNSSEC resolver. Security Fix(es): * unbound: Unbound: Denial of Service via excessive EDNS options (CVE-2026-41292) * unbound: Unbound: Cache manipulation via 'ghost domain names' attack (CVE-2026-40622) * unbound: Unbound: Denial…
EL8+ (AlmaLinux/CloudLinux/Rocky)
sudo dnf update
.NET is a managed-software framework. It implements a subset of the .NET framework APIs and several new APIs, and it includes a CLR implementation. New versions of .NET that address a security vulnerability are now available. The updated versions are .NET SDK 9.0.119 and .NET Runtime 9.0.18. Security Fix(es): …
Betroffen
9.0
EL8+ (AlmaLinux/CloudLinux/Rocky)
sudo dnf update
The fence-agents packages provide a collection of scripts for handling remote power management for cluster devices. They allow failed or unreachable nodes to be forcibly restarted and removed from the cluster. Security Fix(es): * httplib2: httplib2: Denial of Service via unbounded decompression of HTTP resp…
EL8+ (AlmaLinux/CloudLinux/Rocky)
sudo dnf update
.NET is a managed-software framework. It implements a subset of the .NET framework APIs and several new APIs, and it includes a CLR implementation. New versions of .NET that address a security vulnerability are now available. The updated versions are .NET SDK 10.0.110 and .NET Runtime 10.0.10. Security Fix(es)…
Betroffen
10.0
EL8+ (AlmaLinux/CloudLinux/Rocky)
sudo dnf update
.NET is a managed-software framework. It implements a subset of the .NET framework APIs and several new APIs, and it includes a CLR implementation. New versions of .NET that address a security vulnerability are now available. The updated versions are .NET SDK 8.0.129 and .NET Runtime 8.0.29. Security Fix(es): …
Betroffen
8.0
EL8+ (AlmaLinux/CloudLinux/Rocky)
sudo dnf update
The coreutils packages contain the GNU Core Utilities and represent a combination of the previously used GNU fileutils, sh-utils, and textutils packages. Bug Fix(es) and Enhancement(s): * Fix execution of the downstream tests in coreutils-df-direct.patch and coreutils-i18n.patch [almalinux-8.10.z] (JIRA:Alma…
Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. Python supports interfaces to many system calls and libraries, as well as to various windowing systems. Security Fix(es): * Pillow: …
EL8+ (AlmaLinux/CloudLinux/Rocky)
sudo dnf update
A service for building customized OS artifacts, such as VM images and OSTree commits, that uses osbuild under the hood. Besides building images for local usage, it can also upload images directly to cloud. It is compatible with composer-cli and cockpit-composer clients. Security Fix(es): * google.golang.org/…
EL8+ (AlmaLinux/CloudLinux/Rocky)
sudo dnf update
The kernel packages contain the Linux kernel, the core of any Linux operating system. Security Fix(es): * kernel: KVM: x86: Don't (re)check L1 intercepts when completing userspace I/O (CVE-2025-40026) * kernel: dm log: fix out-of-bounds write due to region_count overflow (CVE-2026-53059) * kernel: drm/xe…
EL8+ (AlmaLinux/CloudLinux/Rocky)
sudo dnf update
The unbound packages provide a validating, recursive, and caching DNS or DNSSEC resolver. Security Fix(es): * unbound: Unbound: Denial of Service via excessive EDNS options (CVE-2026-41292) * unbound: Unbound: Cache manipulation via 'ghost domain names' attack (CVE-2026-40622) * unbound: Unbound: Denial…
EL8+ (AlmaLinux/CloudLinux/Rocky)
sudo dnf update
.NET is a managed-software framework. It implements a subset of the .NET framework APIs and several new APIs, and it includes a CLR implementation. New versions of .NET that address a security vulnerability are now available. The updated versions are .NET SDK 10.0.110 and .NET Runtime 10.0.10. Security Fix(es)…
Betroffen
10.0
EL8+ (AlmaLinux/CloudLinux/Rocky)
sudo dnf update
.NET is a managed-software framework. It implements a subset of the .NET framework APIs and several new APIs, and it includes a CLR implementation. New versions of .NET that address a security vulnerability are now available. The updated versions are .NET SDK 9.0.119 and .NET Runtime 9.0.18. Security Fix(es): …
Betroffen
9.0
EL8+ (AlmaLinux/CloudLinux/Rocky)
sudo dnf update
Kernel-based Virtual Machine (KVM) is a full virtualization solution for Linux on a variety of architectures. The qemu-kvm packages provide the user-space component for running virtual machines that use KVM. Security Fix(es): * qemu-kvm: Heap buffer overflow in virtio-blk SCSI request handling (CVE-2026-4891…
EL8+ (AlmaLinux/CloudLinux/Rocky)
sudo dnf update
.NET is a managed-software framework. It implements a subset of the .NET framework APIs and several new APIs, and it includes a CLR implementation. New versions of .NET that address a security vulnerability are now available. The updated versions are .NET SDK 8.0.129 and .NET Runtime 8.0.29. Security Fix(es): …
Betroffen
8.0
EL8+ (AlmaLinux/CloudLinux/Rocky)
sudo dnf update
OpenSSH is an SSH protocol implementation supported by a number of Linux, UNIX, and similar operating systems. It includes the core files necessary for both the OpenSSH client and server. Security Fix(es): * openssh: Local MITM of X11 forwarding via abstract UNIX socket pre-binding in AlmaLinux OpenSSH clien…
EL8+ (AlmaLinux/CloudLinux/Rocky)
sudo dnf update
Vim (Vi IMproved) is an updated and improved version of the vi editor. Security Fix(es): * vim: Vim: Denial of Service via stack out-of-bounds write in spell_soundfold_sofo() (CVE-2026-57455) * vim: Vim: Arbitrary code execution via malicious docstrings in Python omni-completion (CVE-2026-57456) * vim: V…
EL8+ (AlmaLinux/CloudLinux/Rocky)
sudo dnf update
It was discovered that OpenSSL incorrectly allocated memory buffers in the SSL/TLS state machine when receiving handshake data. A remote attacker could possibly use this issue to cause OpenSSL to consume excessive memory, leading to a denial of service. This issue is known as the "HollowByte" denial of service.
Debian/Ubuntu
sudo apt update && sudo apt upgrade
OpenSSH is an SSH protocol implementation supported by a number of Linux, UNIX, and similar operating systems. It includes the core files necessary for both the OpenSSH client and server. Security Fix(es): * openssh: Local MITM of X11 forwarding via abstract UNIX socket pre-binding in AlmaLinux OpenSSH clien…
EL8+ (AlmaLinux/CloudLinux/Rocky)
sudo dnf update
Vim (Vi IMproved) is an updated and improved version of the vi editor. Security Fix(es): * vim: Vim: Denial of Service via stack out-of-bounds write in spell_soundfold_sofo() (CVE-2026-57455) * vim: Vim: Arbitrary code execution via malicious docstrings in Python omni-completion (CVE-2026-57456) * vim: V…
EL8+ (AlmaLinux/CloudLinux/Rocky)
sudo dnf update
OVSwrap (CVE-2026-64531): a Linux kernel flaw giving local root on CloudLinux 9, 10 and CloudLinux for Ubuntu. No kernel fix yet; apply the mitigation. The post OVSwrap (CVE-2026-64531) local root exploit: mitigation for CloudLinux 9, 10, and CloudLinux for Ubuntu appeared first on CloudLinux.
EL8+ (AlmaLinux/CloudLinux/Rocky)
sudo dnf update
EL7 (CentOS/CloudLinux 7)
sudo yum update
Debian/Ubuntu
sudo apt update && sudo apt upgrade
It was discovered that Sinatra did not properly handle header parsing, causing ETag generation to hang when given specific input. A remote attacker could possibly use this issue to cause a denial of service.
Debian/Ubuntu
sudo apt update && sudo apt upgrade
Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - ARM64 architecture; - Arm Firmware Framework for ARMv8-A(FFA); (CVE-2026-53354, CVE-2026-64520)
Debian/Ubuntu
sudo apt update && sudo apt upgrade
Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - ARM64 architecture; - Arm Firmware Framework for ARMv8-A(FFA); (CVE-2026-53354, CVE-2026-64520)
Debian/Ubuntu
sudo apt update && sudo apt upgrade
Maxim Suhanov discovered that the NTFS file system implementation in the Linux kernel did not properly validate file name length in certain situations, leading to an out-of-bounds read. An attacker could use this to construct a malicious NTFS image that, when mounted and operated on, could expose sensitive informati…
Debian/Ubuntu
sudo apt update && sudo apt upgrade
It was discovered that a logic flaw existed in the XFRM ESP-in-TCP subsystem in the Linux kernel when handling socket buffer fragments. This flaw is known as Fragnesia. A local attacker could use this to escalate privileges, or possibly escape a container. (CVE-2026-43503) Several security issues were discovered in…
Debian/Ubuntu
sudo apt update && sudo apt upgrade
Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language. Security Fix(es): * brace-expansion: Brace-expansion: Denial of Service due to exponential-time complexity (CVE-2026-13149) * tar: Node-tar: Denial of Service via malforme…
EL8+ (AlmaLinux/CloudLinux/Rocky)
sudo dnf update
Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language. Security Fix(es): * brace-expansion: Brace-expansion: Denial of Service due to exponential-time complexity (CVE-2026-13149) * tar: Node-tar: Denial of Service via malforme…
EL8+ (AlmaLinux/CloudLinux/Rocky)
sudo dnf update
The libtiff packages contain a library of functions for manipulating Tagged Image File Format (TIFF) files. Security Fix(es): * libtiff: libtiff: Heap-based buffer overflow via crafted PixarLog-compressed TIFF image (CVE-2026-12912) For more details about the security issue(s), including the impact, a CVSS…
EL8+ (AlmaLinux/CloudLinux/Rocky)
sudo dnf update
GStreamer is a streaming media framework based on graphs of filters which operate on media data. The gstreamer1-plugins-bad-free package contains a collection of plug-ins for GStreamer. Security Fix(es): * gstreamer: gstreamer: rfbsrc/librfb Hextile heap out-of-bounds write with 16bpp framebuffer (CVE-2026-5…
EL8+ (AlmaLinux/CloudLinux/Rocky)
sudo dnf update
X.Org X11 libXfont2 runtime library Security Fix(es): * libXfont2: BitmapScaleBitmaps Integer Overflow Heap Buffer Overflow (CVE-2026-56001) * libXfont2: PCF Font Parsing Heap Buffer Overflow (CVE-2026-56002) * libXfont2: computeProps Property Buffer Heap Buffer Overflow (CVE-2026-56003) For more detai…
EL8+ (AlmaLinux/CloudLinux/Rocky)
sudo dnf update
USN-8561-1 fixed vulnerabilities in FreeRDP. Unfortunately, the upgrade to version 3.30.0 introduced a regression in the clipboard functionality. This update fixes the problem. We apologize for the inconvenience. Original advisory details: It was discovered that FreeRDP contained multiple security issues. An at…
Debian/Ubuntu
sudo apt update && sudo apt upgrade
It was discovered that Samba's pam_winbind incorrectly handled home directory ownership when mkhomedir was enabled. A local attacker could possibly use this issue to cause a denial of service by triggering a change in ownership of the root directory. (CVE-2026-15779) Arjun Basnet, Douglas Bagnall, and Andrew Tridge…
Debian/Ubuntu
sudo apt update && sudo apt upgrade
The kernel-rt packages provide the Real Time Linux Kernel, which enables fine-tuning for systems with extremely high determinism requirements. Security Fix(es): * kernel: ipv6: fix possible UAF in icmpv6_rcv() (CVE-2026-53006) For more details about the security issue(s), including the impact, a CVSS score…
EL8+ (AlmaLinux/CloudLinux/Rocky)
sudo dnf update
The kernel packages contain the Linux kernel, the core of any Linux operating system. Security Fix(es): * kernel: ipv6: fix possible UAF in icmpv6_rcv() (CVE-2026-53006) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer t…
EL8+ (AlmaLinux/CloudLinux/Rocky)
sudo dnf update
The System Security Services Daemon (SSSD) service provides a set of daemons to manage access to remote directories and authentication mechanisms. It also provides the Name Service Switch (NSS) and the Pluggable Authentication Modules (PAM) interfaces toward the system, and a pluggable back-end system to connect to …
EL8+ (AlmaLinux/CloudLinux/Rocky)
sudo dnf update
Dovecot is an IMAP server for Linux and other UNIX-like systems, written primarily with security in mind. It also contains a small POP3 server, and supports e-mail in either the maildir or mbox format. The SQL drivers and authentication plug-ins are provided as subpackages. Security Fix(es): * dovecot: Dove…
EL8+ (AlmaLinux/CloudLinux/Rocky)
sudo dnf update
Grafana is an open source, feature rich metrics dashboard and graph editor for Graphite, InfluxDB & OpenTSDB. Security Fix(es): * github.com/go-git/go-billy: Billy: Denial of Service via crafted input due to insufficient validation (CVE-2026-44740) Bug Fix(es) and Enhancement(s): * [grafana / alm…
EL8+ (AlmaLinux/CloudLinux/Rocky)
sudo dnf update
Libreswan is an implementation of IPsec and IKE for Linux. IPsec is the Internet Protocol Security and uses strong cryptography to provide both authentication and encryption services. These services allow you to build secure tunnels through untrusted networks such as virtual private network (VPN). Security Fix(es…
EL8+ (AlmaLinux/CloudLinux/Rocky)
sudo dnf update
Libreswan is an implementation of IPsec and IKE for Linux. IPsec is the Internet Protocol Security and uses strong cryptography to provide both authentication and encryption services. These services allow you to build secure tunnels through untrusted networks such as virtual private network (VPN). Security Fix(es…
EL8+ (AlmaLinux/CloudLinux/Rocky)
sudo dnf update
The kernel packages contain the Linux kernel, the core of any Linux operating system. Bug Fix(es) and Enhancement(s): * XFS data corruption using reflink [almalinux-9.8.z] (JIRA:AlmaLinux-193937)
The kernel packages contain the Linux kernel, the core of any Linux operating system. Security Fix(es): * kernel: KVM: x86: Don't (re)check L1 intercepts when completing userspace I/O (CVE-2025-40026) * kernel: xfrm single-frag length not properly limited * kernel: dm log: fix out-of-bounds write due to …
EL8+ (AlmaLinux/CloudLinux/Rocky)
sudo dnf update
The kernel-rt packages provide the Real Time Linux Kernel, which enables fine-tuning for systems with extremely high determinism requirements. Security Fix(es): * kernel: KVM: x86: Don't (re)check L1 intercepts when completing userspace I/O (CVE-2025-40026) * kernel: xfrm single-frag length not properly …
EL8+ (AlmaLinux/CloudLinux/Rocky)
sudo dnf update
The java-1.8.0-openjdk packages provide the OpenJDK 8 Java Runtime Environment and the OpenJDK 8 Java Software Development Kit. Security Fix(es): * JDK: Enhance TLS certificate handling (CVE-2026-46968) * JDK: Enhance JPEG handling (CVE-2026-47010) * JDK: Enhance XBM image support (CVE-2026-47021) * JD…
Betroffen
1.8.0
EL8+ (AlmaLinux/CloudLinux/Rocky)
sudo dnf update
The OpenJDK 21 packages provide the OpenJDK 21 Java Runtime Environment and the OpenJDK 21 Java Software Development Kit. Security Fix(es): * JDK: Enhance TLS certificate handling (CVE-2026-46968) * JDK: Improve DTLS handshaking (CVE-2026-46917) * JDK: Enhance JPEG handling (CVE-2026-47010) * JDK: Enha…
EL8+ (AlmaLinux/CloudLinux/Rocky)
sudo dnf update
The java-17-openjdk packages provide the OpenJDK 17 Java Runtime Environment and the OpenJDK 17 Java Software Development Kit. Security Fix(es): * JDK: Enhance TLS certificate handling (CVE-2026-46968) * JDK: Improve DTLS handshaking (CVE-2026-46917) * JDK: Enhance JPEG handling (CVE-2026-47010) * JDK:…
EL8+ (AlmaLinux/CloudLinux/Rocky)
sudo dnf update
The java-1.8.0-openjdk packages provide the OpenJDK 8 Java Runtime Environment and the OpenJDK 8 Java Software Development Kit. Security Fix(es): * JDK: Enhance TLS certificate handling (CVE-2026-46968) * JDK: Enhance JPEG handling (CVE-2026-47010) * JDK: Enhance XBM image support (CVE-2026-47021) * JD…
Betroffen
1.8.0
EL8+ (AlmaLinux/CloudLinux/Rocky)
sudo dnf update
The kernel packages contain the Linux kernel, the core of any Linux operating system. Security Fix(es): * kernel: crypto: af_alg - zero initialize memory allocated via sock_kmalloc (CVE-2025-71113) * kernel: scsi: core: Wake up the error handler when final completions race against each other (CVE-2026-2311…
EL8+ (AlmaLinux/CloudLinux/Rocky)
sudo dnf update
The java-17-openjdk packages provide the OpenJDK 17 Java Runtime Environment and the OpenJDK 17 Java Software Development Kit. Security Fix(es): * JDK: Enhance TLS certificate handling (CVE-2026-46968) * JDK: Improve DTLS handshaking (CVE-2026-46917) * JDK: Enhance JPEG handling (CVE-2026-47010) * JDK:…
EL8+ (AlmaLinux/CloudLinux/Rocky)
sudo dnf update
The System Security Services Daemon (SSSD) service provides a set of daemons to manage access to remote directories and authentication mechanisms. It also provides the Name Service Switch (NSS) and the Pluggable Authentication Modules (PAM) interfaces toward the system, and a pluggable back-end system to connect to …
EL8+ (AlmaLinux/CloudLinux/Rocky)
sudo dnf update
The OpenJDK 21 packages provide the OpenJDK 21 Java Runtime Environment and the OpenJDK 21 Java Software Development Kit. Security Fix(es): * JDK: Enhance TLS certificate handling (CVE-2026-46968) * JDK: Improve DTLS handshaking (CVE-2026-46917) * JDK: Enhance JPEG handling (CVE-2026-47010) * JDK: Enha…
EL8+ (AlmaLinux/CloudLinux/Rocky)
sudo dnf update
The OpenSSL toolkit provides support for secure communications between machines. This version of OpenSSL package contains only the libraries from the 1.1.1 version and is provided for compatibility with previous releases. Security Fix(es): * openssl: Heap Use-After-Free in OpenSSL PKCS7_verify() (CVE-2026-45…
EL8+ (AlmaLinux/CloudLinux/Rocky)
sudo dnf update
The libpq package provides the PostgreSQL client library, which allows client programs to connect to PostgreSQL servers. Security Fix(es): * postgresql: PostgreSQL libpq: Buffer overflow allows server superuser to overwrite client stack memory (CVE-2026-6477) For more details about the security issue(s), …
EL8+ (AlmaLinux/CloudLinux/Rocky)
sudo dnf update
The glibc packages provide the standard C libraries (libc), POSIX thread libraries (libpthread), standard math libraries (libm), and the name service cache daemon (nscd) used by multiple programs on the system. Without these libraries, the Linux system cannot function correctly. Security Fix(es): * glibc: gl…
EL8+ (AlmaLinux/CloudLinux/Rocky)
sudo dnf update
RefluXFS (CVE-2026-64600) is a Linux kernel Local Privilege Escalation in the XFS filesystem, present in every kernel from v4.11 (April 2017) onward. On an affected host, an unprivileged local user can gain root, with no capabilities, namespaces, or special hardware required. It was discovered by Qualys and publicly…
EL8+ (AlmaLinux/CloudLinux/Rocky)
sudo dnf update
Debian/Ubuntu
sudo apt update && sudo apt upgrade
One of Europe’s largest cloud providers just spent eleven days rebooting the infrastructure behind roughly a million customer VMs to close a single kernel vulnerability. A hard call, executed well, and a preview of the decision every hosting provider will face again. Because there will be a next one. When a cr…
This is a security release. It addresses GCVE-25-2026-07-45-1 and GCVE-25-2026-07-45-3 . ref.: https://exim.org/static/doc/security/EXIM-Security-2026-06-22.1/EXIM-Security-2026-06-22.1.txt https://exim.org/static/doc/security/EXIM-Security-2026-06-22.3/EXIM-Security-2026-06-22.3.txt
Betroffen
4.99.5
The Public Key Infrastructure (PKI) Core contains fundamental packages required by AlmaLinux Certificate System. Security Fix(es): * jackson-databind: Jackson-databind: Security bypass allows arbitrary code execution (CVE-2026-54513) For more details about the security issue(s), including the impact, a CVS…
Betroffen
10.6
EL8+ (AlmaLinux/CloudLinux/Rocky)
sudo dnf update
Access Control Lists (ACLs) are used to define fine-grained discretionary access rights for files and directories. The acl packages contain the getfacl and setfacl utilities needed for manipulating access control lists. Security Fix(es): * acl: Symlink traversal privilege escalation via libacl functions (CVE…
EL8+ (AlmaLinux/CloudLinux/Rocky)
sudo dnf update
The javapackages-tools packages provide macros and scripts to support Java packaging. Security Fix(es): * org.codehaus.plexus:plexus-utils: Plexus-utils: Directory Traversal in extractFile method (CVE-2025-67030) For more details about the security issue(s), including the impact, a CVSS score, acknowledgme…
EL8+ (AlmaLinux/CloudLinux/Rocky)
sudo dnf update
The glibc packages provide the standard C libraries (libc), POSIX thread libraries (libpthread), standard math libraries (libm), and the name service cache daemon (nscd) used by multiple programs on the system. Without these libraries, the Linux system cannot function correctly. Security Fix(es): * glibc: gl…
EL8+ (AlmaLinux/CloudLinux/Rocky)
sudo dnf update
Go Toolset provides the Go programming language tools and libraries. Go is alternatively known as golang. Security Fix(es): * golang: internal/syscall/unix: Root.Chmod can follow symlinks out of the root (CVE-2026-32282) * crypto/tls: golang: Go crypto/tls: Denial of Service via multiple TLS 1.3 key updat…
EL8+ (AlmaLinux/CloudLinux/Rocky)
sudo dnf update
The httpd packages provide the Apache HTTP Server, a powerful, efficient, and extensible web server. Security Fix(es): * httpd: incomplete fix for CVE-2023-38709 (CVE-2024-42516) * httpd: NULL pointer dereference via specially crafted request (CVE-2026-29169) * httpd: Apache HTTP Server: Heap-based Buffe…
Betroffen
2.4
EL8+ (AlmaLinux/CloudLinux/Rocky)
sudo dnf update
Grafana is an open source, feature rich metrics dashboard and graph editor for Graphite, InfluxDB & OpenTSDB. Security Fix(es): * golang: internal/syscall/unix: Root.Chmod can follow symlinks out of the root (CVE-2026-32282) * crypto/tls: golang: Go crypto/tls: Denial of Service via multiple TLS 1.3 k…
EL8+ (AlmaLinux/CloudLinux/Rocky)
sudo dnf update
The Grafana plugin for Performance Co-Pilot includes datasources for scalable time series from pmseries and Redis, live PCP metrics and bpftrace scripts from pmdabpftrace, as well as several dashboards. Security Fix(es): * golang: internal/syscall/unix: Root.Chmod can follow symlinks out of the root (CVE-202…
EL8+ (AlmaLinux/CloudLinux/Rocky)
sudo dnf update
Dovecot is an IMAP server for Linux and other UNIX-like systems, written primarily with security in mind. It also contains a small POP3 server, and supports e-mail in either the maildir or mbox format. The SQL drivers and authentication plug-ins are provided as subpackages. Security Fix(es): * dovecot: Dove…
EL8+ (AlmaLinux/CloudLinux/Rocky)
sudo dnf update
Access Control Lists (ACLs) are used to define fine-grained discretionary access rights for files and directories. The acl packages contain the getfacl and setfacl utilities needed for manipulating access control lists. Security Fix(es): * acl: Symlink traversal privilege escalation via libacl functions (CVE…
EL8+ (AlmaLinux/CloudLinux/Rocky)
sudo dnf update
The libtiff packages contain a library of functions for manipulating Tagged Image File Format (TIFF) files. Security Fix(es): * libtiff: libtiff: Heap-based buffer overflow via crafted PixarLog-compressed TIFF image (CVE-2026-12912) For more details about the security issue(s), including the impact, a CVSS…
EL8+ (AlmaLinux/CloudLinux/Rocky)
sudo dnf update
A vulnerability in the Plesk PHP Updater allows an authenticated admin to write files outside the intended directory, leading to remote code execution as the psaserv service user.
Betroffen
Plesk Obsidian 18.0.63 and earlier
Gepatcht
Plesk Obsidian 18.0.65
AlmaLinux 9 / CloudLinux 9
plesk installer update --select-product-id plesk
plesk sbin packagemng --update
Ubuntu 22.04 / Debian 12
apt update
plesk installer update --select-product-id plesk
Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language. Security Fix(es): * ip-address: ip-address: Cross-site scripting via improper HTML escaping of untrusted input (CVE-2026-42338) * undici: undici: Denial of Service due to …
EL8+ (AlmaLinux/CloudLinux/Rocky)
sudo dnf update
GLib provides the core application building blocks for libraries and applications written in C. It provides the core object system used in GNOME, the main loop implementation, and a large set of utility functions for strings and common data structures. Security Fix(es): * glib: integer underflow in gio/gdbus…
EL8+ (AlmaLinux/CloudLinux/Rocky)
sudo dnf update
WebKitGTK is the port of the portable web rendering engine WebKit to the GTK platform. Security Fix(es): * Mozilla: Arbitrary JavaScript execution in PDF.js (CVE-2024-4367) * webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash (CVE-2026-39872) * webkitgtk: webkitgtk: …
EL8+ (AlmaLinux/CloudLinux/Rocky)
sudo dnf update
The kernel-rt packages provide the Real Time Linux Kernel, which enables fine-tuning for systems with extremely high determinism requirements. Security Fix(es): * kernel: RDMA/mana: Remove user triggerable WARN_ON() in mana_ib_create_qp_rss() (CVE-2026-46117) * kernel: Bluetooth: l2cap: Add missing chan lo…
EL8+ (AlmaLinux/CloudLinux/Rocky)
sudo dnf update
The kernel packages contain the Linux kernel, the core of any Linux operating system. Security Fix(es): * kernel: RDMA/mana: Remove user triggerable WARN_ON() in mana_ib_create_qp_rss() (CVE-2026-46117) * kernel: Bluetooth: l2cap: Add missing chan lock in l2cap_ecred_reconf_rsp (CVE-2026-53071) Bug Fix(e…
EL8+ (AlmaLinux/CloudLinux/Rocky)
sudo dnf update
WebKitGTK is the port of the portable web rendering engine WebKit to the GTK platform. Security Fix(es): * Mozilla: Arbitrary JavaScript execution in PDF.js (CVE-2024-4367) * webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash (CVE-2026-39872) * webkitgtk: webkitgtk: …
EL8+ (AlmaLinux/CloudLinux/Rocky)
sudo dnf update
GLib provides the core application building blocks for libraries and applications written in C. It provides the core object system used in GNOME, the main loop implementation, and a large set of utility functions for strings and common data structures. Security Fix(es): * glib: integer underflow in gio/gdbus…
EL8+ (AlmaLinux/CloudLinux/Rocky)
sudo dnf update
Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. Python supports interfaces to many system calls and libraries, as well as to various windowing systems. Security Fix(es): * python: …
EL8+ (AlmaLinux/CloudLinux/Rocky)
sudo dnf update
The httpd packages provide the Apache HTTP Server, a powerful, efficient, and extensible web server. Security Fix(es): * httpd: incomplete fix for CVE-2023-38709 (CVE-2024-42516) * Apache HTTP Server: mod_rewrite: Apache HTTP Server: Privilege Escalation via .htaccess file manipulation (CVE-2026-24072) *…
EL8+ (AlmaLinux/CloudLinux/Rocky)
sudo dnf update
The Pacemaker cluster resource manager is a collection of technologies working together to maintain data integrity and application availability in the event of failures. Security Fix(es): * pacemaker: Pacemaker: Denial of Service via integer overflow in remote message decompression (CVE-2026-10649) For mo…
EL8+ (AlmaLinux/CloudLinux/Rocky)
sudo dnf update
Changes with nginx 1.31.3 15 Jul 2026 *) Security: heap buffer overflow might occur in a worker process when using the map directive with regex matching if the map variable was included in a string expression after a capture affected by this map; a sim…
Betroffen
1.31.3
Maven is a software project management and comprehension tool. Based on the concept of a project object model (POM), Maven can manage a project's build, reporting and documentation from a central piece of information. Security Fix(es): * org.codehaus.plexus:plexus-utils: Plexus-utils: Directory Traversal in …
Betroffen
3.8
EL8+ (AlmaLinux/CloudLinux/Rocky)
sudo dnf update
The hplip packages contain the Hewlett-Packard Linux Imaging and Printing Project (HPLIP), which provides drivers for Hewlett-Packard printers and multi-function peripherals. Security Fix(es): * HPLIP: Incomplete Fix for CVE-2026-8631 (CVE-2026-14544) For more details about the security issue(s), including…
EL8+ (AlmaLinux/CloudLinux/Rocky)
sudo dnf update
Capstone is a disassembly framework with the target of becoming the ultimate disasm engine for binary analysis and reversing in the security community. Security Fix(es): * capstone: Capstone: Memory corruption via unchecked vsnprintf return (CVE-2025-68114) For more details about the security issue(s), inc…
EL8+ (AlmaLinux/CloudLinux/Rocky)
sudo dnf update
The general-purpose data-binding functionality and tree-model for Jackson Data Processor. It builds on core streaming parser/generator package, and uses Jackson Annotations for configuration. Security Fix(es): * jackson-databind: Jackson-databind: Security bypass allows arbitrary code execution (CVE-2026-545…
EL8+ (AlmaLinux/CloudLinux/Rocky)
sudo dnf update
The hplip packages contain the Hewlett-Packard Linux Imaging and Printing Project (HPLIP), which provides drivers for Hewlett-Packard printers and multi-function peripherals. Security Fix(es): * HPLIP: Incomplete Fix for CVE-2026-8631 (CVE-2026-14544) For more details about the security issue(s), including…
EL8+ (AlmaLinux/CloudLinux/Rocky)
sudo dnf update
The GIMP (GNU Image Manipulation Program) is an image composition and editing program. GIMP provides a large image manipulation toolbox, including channel operations and layers, effects, sub-pixel imaging and anti-aliasing, and conversions, all with multi-level undo. Security Fix(es): * gimp: gimp: Stack buf…
EL8+ (AlmaLinux/CloudLinux/Rocky)
sudo dnf update
Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language. Security Fix(es): * ip-address: ip-address: Cross-site scripting via improper HTML escaping of untrusted input (CVE-2026-42338) * undici: undici: Denial of Service due to …
EL8+ (AlmaLinux/CloudLinux/Rocky)
sudo dnf update
The container-tools module contains tools for working with containers, notably podman, buildah, skopeo, and runc. Security Fix(es): * net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME (CVE-2026-33811) * golang.org/x/crypto/ssh: golang: golang.org/x/crypto/ssh: Denial of …
EL8+ (AlmaLinux/CloudLinux/Rocky)
sudo dnf update
LibreOffice is an open source, community-developed office productivity suite. It includes key desktop applications, such as a word processor, a spreadsheet, a presentation manager, a formula editor, and a drawing program. LibreOffice replaces OpenOffice and provides a similar but enhanced and extended office suite. …
EL8+ (AlmaLinux/CloudLinux/Rocky)
sudo dnf update
This module implements a Perl interface to the GNOME libxml2 library which provides interfaces for parsing and manipulating XML files. This module allows Perl programmers to make use of the highly capable validating XML parser and the high performance DOM implementation. Security Fix(es): * perl-XML-LibXML: …
EL8+ (AlmaLinux/CloudLinux/Rocky)
sudo dnf update
The SMB/CIFS protocol is a standard file sharing protocol widely deployed on Microsoft Windows machines. The cifs-utils packages contain tools for mounting shares on Linux using the SMB/CIFS protocol. The tools in this package work in conjunction with support in the kernel to allow one to mount a SMB/CIFS share onto…
EL8+ (AlmaLinux/CloudLinux/Rocky)
sudo dnf update
Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. Python supports interfaces to many system calls and libraries, as well as to various windowing systems. Security Fix(es): * python: …
EL8+ (AlmaLinux/CloudLinux/Rocky)
sudo dnf update
Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. Python supports interfaces to many system calls and libraries, as well as to various windowing systems. Security Fix(es): * python: …
EL8+ (AlmaLinux/CloudLinux/Rocky)
sudo dnf update
Git Large File Storage (LFS) replaces large files such as audio samples, videos, datasets, and graphics with text pointers inside Git, while storing the file contents on a remote server. Security Fix(es): * net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME (CVE-2026-33811)…
EL8+ (AlmaLinux/CloudLinux/Rocky)
sudo dnf update
The libsolv packages provide a library for resolving package dependencies using a satisfiability algorithm. Security Fix(es): * libsolv: Heap buffer overflow in libsolv repopagestore via unchecked decompression of malicious .solv page data (CVE-2026-48864) For more details about the security issue(s), incl…
EL8+ (AlmaLinux/CloudLinux/Rocky)
sudo dnf update
The Common UNIX Printing System (CUPS) provides a portable printing layer for Linux, UNIX, and similar operating systems. Security Fix(es): * cups: OpenPrinting CUPS: Shared PostScript queue lets anonymous Print-Job requests reach `lp` code execution over the network (CVE-2026-34980) For more details about…
EL8+ (AlmaLinux/CloudLinux/Rocky)
sudo dnf update
The libxml2 library is a development toolbox providing the implementation of various XML standards. Security Fix(es): * libxml2: Stack Buffer Overflow in xmllint Interactive Shell Command Handling (CVE-2025-6170) For more details about the security issue(s), including the impact, a CVSS score, acknowledgme…
EL8+ (AlmaLinux/CloudLinux/Rocky)
sudo dnf update
A crafted virtual domain name injects additional lines into the generated exim configuration, allowing an authenticated user to redirect mail flow for other accounts.
Betroffen
DirectAdmin 1.678 and earlier
Gepatcht
DirectAdmin 1.679
AlmaLinux 9 / CloudLinux 9
cd /usr/local/directadmin
echo 'action=update&value=current' >> data/task.queue
directadmin --reload
AlmaLinux 8 / CloudLinux 8
cd /usr/local/directadmin
echo 'action=update&value=current' >> data/task.queue
directadmin --reload
CentOS 7 / CloudLinux 7
cd /usr/local/directadmin
echo 'action=update&value=current' >> data/task.queue
directadmin --reload
Ubuntu 22.04 / Debian 12
cd /usr/local/directadmin
echo 'action=update&value=current' >> data/task.queue
directadmin --reload
Ubuntu 20.04 / Debian 11
cd /usr/local/directadmin
echo 'action=update&value=current' >> data/task.queue
directadmin --reload
Maven is a software project management and comprehension tool. Based on the concept of a project object model (POM), Maven can manage a project's build, reporting and documentation from a central piece of information. Security Fix(es): * org.codehaus.plexus:plexus-utils: Plexus-utils: Directory Traversal in …
Betroffen
3.9
EL8+ (AlmaLinux/CloudLinux/Rocky)
sudo dnf update
X.Org is an open-source implementation of the X Window System. It provides the basic low-level functionality that full-fledged graphical user interfaces are designed upon. Security Fix(es): * xorg: X11: xserver: X.org: glamor Font Atlas Heap Buffer Overflow (CVE-2026-55999) For more details about the secur…
EL8+ (AlmaLinux/CloudLinux/Rocky)
sudo dnf update
Security updates 1.6.17 and 1.7.2 released Free and open source webmail software for the masses, written in PHP roundcube.net Security updates 1.6.17 and 1.7.2 releasedPublished: 05 July 2026 Tags: releases updates security We just …
Betroffen
1.7.2
GhostLock (CVE-2026-43499) is a use-after-free bug in the Linux kernel's futex priority-inheritance code that lets any unprivileged local user become root. Its vulnerable range covers every kernel CloudLinux ships, so all supported versions are affected. There is no runtime mitigation; the fix is the patched kernel …
EL8+ (AlmaLinux/CloudLinux/Rocky)
sudo dnf update
EL7 (CentOS/CloudLinux 7)
sudo yum update
Debian/Ubuntu
sudo apt update && sudo apt upgrade
Bad epoll (CVE-2026-46242) is a use-after-free bug in the Linux kernel's epoll subsystem that lets an unprivileged local user escalate to root. It affects CloudLinux 9 and 10. Patched AlmaLinux kernels are in testing and a KernelCare livepatch is being prepared. Here's how to update. The post Bad epoll (CVE-2026-462…
EL8+ (AlmaLinux/CloudLinux/Rocky)
sudo dnf update
EL7 (CentOS/CloudLinux 7)
sudo yum update
Debian/Ubuntu
sudo apt update && sudo apt upgrade
cpsrvd accepted TLS handshakes that permit protocol downgrade, exposing the Webmail and WHM login sessions to man-in-the-middle interception on affected builds.
Betroffen
cPanel & WHM 120.0.8 and earlier
Gepatcht
cPanel & WHM 120.0.12
AlmaLinux 9 / CloudLinux 9
dnf clean metadata
/scripts/upcp --force
AlmaLinux 8 / CloudLinux 8
dnf clean metadata
/scripts/upcp --force
CentOS 7 / CloudLinux 7
yum clean all
/scripts/upcp --force
The Plesk Backup Manager fails to sanitize archive paths, allowing a local attacker to read arbitrary files on the server via a crafted backup manifest.
Betroffen
Plesk Obsidian 18.0.58 and earlier
Gepatcht
Plesk Obsidian 18.0.60
AlmaLinux 9 / CloudLinux 9
plesk installer update --select-product-id plesk
plesk sbin packagemng --update
AlmaLinux 8 / CloudLinux 8
plesk installer update --select-product-id plesk
CentOS 7 / CloudLinux 7
plesk installer update --select-product-id plesk
Ubuntu 22.04 / Debian 12
apt update
plesk installer update --select-product-id plesk
Ubuntu 20.04 / Debian 11
apt update
plesk installer update --select-product-id plesk
Under heavy connection churn, CSF may briefly drop an active port rule before the reload completes, exposing SSH briefly on default configurations.
Betroffen
CSF 14.20 and earlier
Gepatcht
CSF 14.21
AlmaLinux 9 / CloudLinux 9
cd /etc/csf
csf -u
csf -r
AlmaLinux 8 / CloudLinux 8
cd /etc/csf
csf -u
csf -r
CentOS 7 / CloudLinux 7
cd /etc/csf
csf -u
csf -r
Changes with nginx 1.31.2 17 Jun 2026 *) Security: use-after-free might occur when using HTTP/3 and processing a specially crafted QUIC session, allowing an attacker to cause worker process memory corruption or segmentation fault in a worker process (C…
Betroffen
1.31.2
A race condition in CageFS mount setup can expose the host root filesystem to jailed users when a large number of concurrent logins trigger overlapping mount operations.
Betroffen
CageFS 7.4.1 and earlier
Gepatcht
CageFS 7.4.3
CloudLinux 9
yum update cagefs
/usr/sbin/cagefsctl --force-update
CloudLinux 8
yum update cagefs
/usr/sbin/cagefsctl --force-update
CloudLinux 7
yum update cagefs
/usr/sbin/cagefsctl --force-update
Security updates 1.6.16 and 1.7.1 released We just published security updates to the 1.6 LTS and 1.7 versions of Roundcube Webmail. They both contain fixes for recently reported security vulnerabilities. Security fixes Fix stored XSS/HTML/CSS injection in subject field of the draft restore dialog Fix CSS injection…
Betroffen
1.7.1
We recommend all DirectAdmin using Nginx to upgrade to the latest version 1.30.1 or 1.31.0. This release fixes the CVE-2026-42945 vulnerability. NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when the rewrite directive is foll…
Betroffen
1.30.1
The Mail Sending API allowed a reseller account to issue server-side requests to internal network endpoints, enabling internal port scanning and metadata access.
Betroffen
cPanel & WHM 120.0.3 and earlier
Gepatcht
cPanel & WHM 120.0.6
AlmaLinux 9 / CloudLinux 9
dnf clean metadata
/scripts/upcp --force
AlmaLinux 8 / CloudLinux 8
dnf clean metadata
/scripts/upcp --force
CentOS 7 / CloudLinux 7
yum clean all
/scripts/upcp --force
A vulnerability was recently discovered in the Linux Kernel named "Dirty Frag", which allows for Local Privilege Escalation (LPE) to the root user. "Dirty Frag" is a similar exploit to the recent "Copy/Fail" (CVE-2026-31431) vulnerability disclosed recently, and is a continuation of a previous vulnerability…
Improper header validation on the HTTP/2 stream permits request smuggling against proxied backends, enabling cache poisoning on shared hosting configurations.
Betroffen
LiteSpeed Web Server 6.2.5 and earlier
Gepatcht
LiteSpeed Web Server 6.2.6
AlmaLinux 9 / CloudLinux 9
dnf update lsws
/usr/local/lsws/bin/lshttpd -r
AlmaLinux 8 / CloudLinux 8
dnf update lsws
/usr/local/lsws/bin/lshttpd -r
CentOS 7 / CloudLinux 7
yum update lsws
/usr/local/lsws/bin/lshttpd -r
A new local privilege escalation vulnerability named CopyFail CVE-2026-31431 was recently disclosed. It affects almost all of the systems and allows local user to get root access on the system. The Linux distribution maintainers are busy with releasing hot-fixes. We are sharing an immediate mitigation for server ad…
Pure-FTPd in DirectAdmin does not enforce login attempt limits when clients reuse the same data connection, allowing accelerated password brute-forcing.
Betroffen
DirectAdmin 1.671 and earlier
Gepatcht
DirectAdmin 1.672
AlmaLinux 9 / CloudLinux 9
cd /usr/local/directadmin
echo 'action=update&value=current' >> data/task.queue
directadmin --reload
CentOS 7 / CloudLinux 7
cd /usr/local/directadmin
echo 'action=update&value=current' >> data/task.queue
directadmin --reload
Ubuntu 22.04 / Debian 12
cd /usr/local/directadmin
echo 'action=update&value=current' >> data/task.queue
directadmin --reload
A symlink placed inside the quarantine directory is followed by the cleanup job, allowing a compromised account to redirect removal operations to arbitrary files.
Betroffen
Imunify360 6.12 and earlier
Gepatcht
Imunify360 6.13
AlmaLinux 9 / CloudLinux 9
yum update imunify360-antivirus
/usr/share/immuni360/imunify360-update
AlmaLinux 8 / CloudLinux 8
yum update imunify360-antivirus
/usr/share/immuni360/imunify360-update
CentOS 7 / CloudLinux 7
yum update imunify360-antivirus
/usr/share/immuni360/imunify360-update
Ubuntu 22.04
apt update
apt upgrade imunify360-antivirus
Ubuntu 20.04
apt update
apt upgrade imunify360-antivirus
SymptomsSecurity Advisor notifications occur frequently during cPanel updates.CONFIG_TEXT: Detected 4 processes that are running outdated executables: 1230540 1230901 1231293 1231304 CauseThe Security Advisor uses the DNF core plugin "needs-restarting" to detect if processes may need a restart. If the system clock s…
Password reset tokens in WHMCS were generated with insufficient entropy, allowing brute-force recovery of the reset URL for administrator accounts.
Betroffen
WHMCS 8.9.0 and earlier
Gepatcht
WHMCS 8.10.1
All Systems
Back up /var/www/html/whmcs
Download the patched release
Run the upgrade wizard at /install/upgrade
WordPress 6.9.2 is now available This is a security release that features several fixes. Because this is a security release, it is recommended that you update your sites immediately. You can download WordPress 6.9.2 from WordPress.org, or visit your WordPress Dashboard, click “Updates”, and then click “Upda…
Betroffen
6.9.2
JetBackup offsite archives did not verify checksums after upload on interrupted transfers, leaving restore operations with silently corrupted backups.
Betroffen
JetBackup 5.3.10 and earlier
Gepatcht
JetBackup 5.3.12
AlmaLinux 9 / CloudLinux 9
dnf update jetbackup
jetbackup5 --update
AlmaLinux 8 / CloudLinux 8
dnf update jetbackup
jetbackup5 --update
CentOS 7 / CloudLinux 7
yum update jetbackup
jetbackup5 --update
Ubuntu 22.04
apt update
apt upgrade jetbackup
Ubuntu 20.04
apt update
apt upgrade jetbackup
As of July 2025, the WordPress Security Team will no longer provide security updates for WordPress versions 4.1 through 4.6. These versions were first released nine or more years ago and over 99% of WordPress installations run a more recent version. The chances this will affect your site, or sites, is very small.…
Betroffen
4.1
Kein Warnhinweis für diese Auswahl gefunden.