Volver a los avisos de seguridad

Security: CVE-2026-33278 cpanel-unbound 1.25.1 Security Release – May 21, 2026

An upstream vulnerability was recently reported for Unbound that affects supported cPanel & WHM versions 126 and higher.

Critical 9.8 CVSS
cPanel

Versiones afectadas

1.25.1

CMD de actualización por defecto

yum update cpanel-unbound

Lo que esto significa bajo una licencia de SharedLicense

Your SharedLicense license itself is not affected — this is a vulnerability in cPanel software, not in licensing. Licenses continue to work during and after the update; there is no need to re-issue or re-activate anything. If you resell cPanel under your own brand, patch client servers too — unpatched installs put your reputation at risk, not your license.

Situation

An upstream vulnerability was recently reported for Unbound that affects supported cPanel & WHM versions 126 and higher.

Impact

We have pushed out an update, including the updated package for the following cPanel & WHM versions: 

  • 11.126.0.63 and higher
  • 11.134.0.30 and higher
  • 11.136.0.14 and higher

We have also pushed out an update for the following WP Squared version:

  • 11.138.1.1 and higher

Note: All further versions of cPanel are patched for this issue as well. Please see the latest changelogs for version information of each cPanel branch:
https://docs.cpanel.net/changelogs/

Call to Action

  1. Update the cPanel version on the server to one of the versions listed above. This can be done with the following:

    # /scripts/upcp –force

  2. Once completed, verify the cPanel version with the following to ensure the update was successful.

    # /usr/local/cpanel/cpanel -V

Preguntas frecuentes

What is CVE-2026-33278?
NLnet Labs Unbound 1.19.1 up to and including version 1.25.0 has a vulnerability in the DNSSEC validator that enables denial of service and possible remote code execution as a result of deep copying a data structure and erroneously overwriting a destination pointer. An adversary can exploit the vulnerability by controlling a malicious signed zone and querying a vulnerable Unbound. When DS sub-queries need to suspend validation due to NSEC3 computational budget exhaustion (introduced in Unbound 1.19.1), Unbound deep-copies response messages to preserve them across memory region teardown. A struct-assignment bug overwrites the destination's pointer with the source's pointer. After the sub-query region is freed, the resumed validator dereferences this dangling pointer, triggering a crash or potentially enabling arbitrary code execution. Unbound 1.25.1 contains a patch with a fix to preserve the correct pointer when deep copying the data structure.
Is CVE-2026-33278 being exploited in the wild?
No confirmed exploitation is recorded. The EPSS model estimates a 1.27% probability of exploitation within the next 30 days — patch on your normal schedule.
How do I fix CVE-2026-33278?
Update cPanel to the patched release.Then confirm the running version matches the patched release listed above.

Comprueba tu sistema en busca de vulnerabilidades

Selecciona tu producto y sistema operativo para ver los comandos de corrección exactos que se aplican a ti.

Comprueba tu sistema