Back to Security Advisories
Critical 2026-08-07

EasyApache 4 25.71 — cPanel & WHM Update

cPanel

Security hotfix We released updated ea-modsec30 and ea-modsec30-rules-owasp-crs packages for EasyApache 4. This security hotfix updates ea-modsec30 to 3.0.16, addressing two issues: CVE-2026-52747 (the multipart/form-data request body parser invalidly handled r and characters, allowing an unauthenticated WAF rule b…

Affected Versions

25.71

Security hotfix We released updated ea-modsec30 and ea-modsec30-rules-owasp-crs packages for EasyApache 4. This security hotfix updates ea-modsec30 to 3.0.16, addressing two issues: CVE-2026-52747 (the multipart/form-data request body parser invalidly handled r and characters, allowing an unauthenticated WAF rule b…

EasyApache 4 25.71

2026 July 13

Security hotfix

We released updated ea-modsec30 and ea-modsec30-rules-owasp-crs packages for EasyApache 4.

This security hotfix updates ea-modsec30 to 3.0.16, addressing two issues: CVE-2026-52747 (the multipart/form-data request body parser invalidly handled r and n characters, allowing an unauthenticated WAF rule bypass) and CVE-2026-52761 (wrong behavior in utf8toUnicode on i386 architecture).

For a full list of changes, read the EasyApache 4 change log.

How to Apply the Fix

Update the affected packages on your server to the patched release, then restart the relevant services.

sudo /scripts/upcp --force
More Information

Check your system for vulnerabilities

Select your product and operating system to see the exact fix commands that apply to you.

Check Your System