Critical WHMCS 8.13.7 Security Update 2026-09-08
Unauthenticated Remote Code Execution (CVE-2026-67399)
Copia de Seguridad
Licencia JetBackup$2Creador de sitios web
Licencia SitePad$2Facturación
Licencia WHMCS$4Instalador automático
Licencia Softaculous$4.00Panel de Control
Licencia cPanel$4.50Licencia DirectAdmin$4.00Licencia Plesk$3.00Revendedor
Licencia DAReseller$1.5Licencia WHMReseller$2Seguridad
Licencia CXS$2Licencia Imunify360$2Licencia KernelCare$2Licencia MailScanner Front-End$1Licencia OSM$2Servidor Web
Licencia LiteSpeed$4.50Sistema Operativo
Licencia CloudLinux$4.5Virtualización
Licencia SolusVM$3Licencia Virtualizor$6Escritorio
Windows 10From $12Windows 11From $12Productividad
Microsoft Access$10Microsoft Outlook$9Microsoft Project$9Microsoft SQL Server$12Microsoft Visio$7Office 2010$35Office 2013$15Office 2016$8Office 2019$8Office 2021$8Office 2024From $8Office 365$10Visual Studio$10Servidor
Windows Server 2012 R2$10Windows Server 2016$10Windows Server 2019$10Windows Server 2022$10Windows Server 2025$10Select your product and operating system to see relevant security advisories and fix commands.
Seleccionado:
La mayoría de las correcciones se aplican actualizando a la última versión. Este es el comando para hacerlo:
Para soluciones más detalladas, consulta a continuación.
Unauthenticated Remote Code Execution (CVE-2026-67399)
Improved security around email previews
Undisclosed Security Fix
Undisclosed Security Fix
Client Area Authorization Bypass (CVE-2026-29204)
Undisclosed Security Fix
Honour parent theme definition for captcha.tpl on Login as Owner link
Correct bulk removal of IPs on Security tab of General Settings
Unauthenticated Remote Code Execution (CVE-2026-67399)
Improved security around email previews
Undisclosed Security Fix
Undisclosed Security Fix
Client Area Authorization Bypass (CVE-2026-29204)
Undisclosed Security Fix
Add clarifying messaging on Integration Links regarding Captcha
The ShortPixel Adaptive Images – WebP, AVIF, CDN, Image Optimization plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.11.5. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to modify configuration options of third-party plugins including ShortPixel Image Optimizer, Autoptimize, WP Rocket, Imagify, and LiteSpeed Cache, as well as the plugin's own API key and account binding. Exploitation requires the respective third-party plugins to be installed, as the impact against those plugins' settings is only reachable when those plugins are present.
The LiteSpeed Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content in all versions up to, and including, 7.8.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. A comment payload crafted exclusively from decimal numeric character references (e.g. ", <, >) placed inside an allowed element such as <code> bypasses WordPress's wp_kses sanitization, as kses does not treat a data-settings="..." substring within text content as an HTML attribute, allowing the malicious payload to reach the vulnerable function. For this to be exploitable, the site must allow users with previously approved comments to write new comments, and the require_name_email setting must be disabled.
The LiteSpeed Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via crafted `` tag attributes in all versions up to, and including, 7.7. This is due to a
A security vulnerability has been discovered in Phusion Passenger's Watchdog API.
A local user's .forward file can trigger unsafe string expansion in Exim's redirect router, allowing command injection under certain pipe transport configurations.
A privilege escalation vulnerability exists in cPanel & WHM's database management functionality.
A vulnerability in the cPanel web server allows manipulation of cpsrvd responses under limited conditions.
WordPress recently announced a few vulnerabilities that were fixed.
Security vulnerabilities tied to the ea-nginx ngx_http_rewrite_module (CVE-2026-9256) have been discovered.
Affected
31.1
An unauthenticated endpoint in cpsrvd was found that could allow the insertion of arbitrary HTTP headers. This affects cPanel & WHM versions 132 and higher.
An unsafe symlink handling error was found that allows a user to chmod an arbitrary file, allowing for denial of service and possible privilege escalation.
Apache HTTP Server: http2: Double Free and possible RCE on early reset (CVE-2026-23918). Double Free and possible RCE vulnerability in Apache HTTP Server with the HTTP/2 protocol.
An authentication bypass security issue has been identified in the cPanel software (including DNSOnly) affecting all versions after 11.40.We would like to thank Sybre Waaijer for helping to identify and responsibly report this vulnerability to us.
An authenticated cPanel account holder with mail-related privileges can create arbitrary files on the server through cPanel's EmailTrack functionality.
A vulnerability was found in the MESSENGER service in the ConfigServer Firewall (CSF) software which could allow for unauthorized code execution.
An authenticated cPanel account holder who is able to add parked or addon domains can create arbitrary files on the server.
Multiple vulnerabilities were found in the ConfigServer Firewall plugin.
Argument injection vulnerability in WP Toolkit before version 6.11.0 as used in cPanel & WHM, allows remote authenticated users to bypass cross-tenant authorization and execute arbitrary wp-toolkit CLI commands as another account.
A combination of two vulnerabilities in the LiteSpeed cPanel plugin allowed an authenticated cPanel user to escalate privileges to root, including on servers running CloudLinux and CageFS.
Security vulnerabilities tied to ea-nginx-njs(CVE-2026-8711) and ea-memcached16(CVE-2026-47783, CVE-2026-47784) have been discovered.
An upstream vulnerability was recently reported for Unbound that affects supported cPanel & WHM versions 126 and higher.
Affected
1.25.1
A security vulnerability was found in the plugin provided by LiteSpeed that allowed unauthorized root access to the server.
A vulnerability has been reported that currently affects cPanel & WHM versions 132 and higher.
This security release addresses vulnerabilities across multiple versions of cPanel & WHM, including fixes for several vulnerabilities rated up to High severity.
It was found that SSL verification was not fully enforced in the DNS Cluster system, which could allow for a malicious server to man-in-the-middle the request and capture credentials. This affects cPanel & WHM versions 126 and higher.
It was found that a low-privilege team user (role=default) can escalate to the owner account's full capabilities through the use of certain UAPI modules. This affects cPanel & WHM versions 110 and higher.
It was found that, as part of the sqloptimizer script, it was possible that a created SQL query could be injected with arbitrary SQL queries. This affects all cPanel & WHM versions.
Through a combination of incorrect dropping of privileges and insufficient path filtering, it was possible to read arbitrary files via certain cpdavd endpoints. This affects cPanel & WHM versions 120 and higher.
The vulnerability, tracked as CVE-2026-45185, aka Dead.Letter, has been described as a use-after-free vulnerability in Exim's binary data transmission (BDAT) message body parsing when a TLS connection is handled by GnuTLS.
A Perl code injection method was found in the create_user API call, relating to the plugin parameter.
An arbitrary file read found was found in the feature::LOADFEATUREFILE adminbin call where it does not adequately validate the feature file name. A relative path may be passed as the argument to this call, causing an arbitrary file to be made world-readable.
Several security vulnerabilities were reported in Exim, impacting versions prior to 4.99.2:
An escalation-of-privilege bug in various modules in Apache HTTP Server 2.4.66 and earlier allows local .htaccess authors to read files with the privileges of the httpd user.
Targeted Security Release For a full list of changes, read the ConfigServer Security & Firewall (CSF) change log.
Affected
16.31-1
Ruby is an extensible, interpreted, object-oriented, scripting language. It has features to process text files and to perform system management tasks. Security Fix(es): * zlib: zlib: Memory corruption via buffer overflow in Zlib::GzipReader (CVE-2026-27820) * net-imap: Net::IMAP: Arbitrary IMAP command inj…
Affected
4.0
Iperf is a tool which can measure maximum TCP bandwidth and tune various parameters and UDP characteristics. Iperf reports bandwidth, delay jitter, and data-gram loss. Security Fix(es): * iperf3: iperf3 server accepts unbounded peer-controlled JSON parameters enabling remote denial of service via resource ex…
USN-8555-1 fixed vulnerabilities in Ubuntu Advantage Tools. On Ubuntu 14.04 LTS only, it was discovered that some machines were unable to enable esm-infra-legacy due to a preemptive apt-helper check. This update fixes the problem. We apologize for the inconvenience. Original advisory details: Bilal Teke discover…
Security and maintenance updates We released updated packages for EasyApache 4. This security release hardens the Phusion Passenger agent API authorization boundary so an empty API account database confers no privileges, resolving a local privilege escalation in the Passenger Watchdog API (SEC-75753). The fix is app…
Affected
25.79
It was discovered that primitive decoders in openCryptoki produced integer underflows when the encoded length was zero. An attacker could possibly use this issue to trigger out-of-bounds reads. (CVE-2026-40253) It was discovered that openCryptoki incorrectly handled symlinks. An attacker in the token-group could po…
The kernel packages contain the Linux kernel, the core of any Linux operating system. Security Fix(es): * kernel: accel/ivpu: Fix signed integer truncation in IPC receive (CVE-2026-53202) * kernel: net/sched: act_api: use RCU with deferred freeing for action lifecycle (CVE-2026-53264) Bug Fix(es) and Enh…
RtabRace (CVE-2026-68138) is a Linux kernel race in the traffic-control subsystem that lets an unprivileged local user corrupt kernel memory. On CloudLinux the reliably reachable result is a host crash, and CloudLinux 8 and CloudLinux 7 Hybrid ship exposed. Here is how to check whether a server is exposed and what t…
BadGarbage (CVE-2026-53361) is a Linux kernel race condition that lets any local user, including a process inside a container, become root on the host. It affects CloudLinux 10 only. CloudLinux 7 through 9 are not affected. There is no runtime mitigation, so the fix is the patched kernel or a KernelCare livepatch. H…
Maintenance and Security Release We released updated packages for EasyApache 4. This release resolves three PHP vulnerabilities across ea-php82, ea-php83, ea-php84, and ea-php85: a libgd vulnerability (CVE-2026-9672), a SQL injection via backslash breakout in PGSQL (CVE-2026-17543), and a crash via recursive symlink…
Affected
25.77
It was discovered that libgit2 incorrectly handled the Git Smart Protocol. A remote attacker could possibly use this issue to cause a denial of service or execute arbitrary code. This issue only affected Ubuntu 14.04 LTS and Ubuntu 16.04 LTS. (CVE-2016-10128) It was discovered that libgit2 incorrectly handled empty…
WordPress 7.0.4 is now available WordPress 7.0.4 is now available which features a security fix. Because this is a security release, it is recommended that you update your sites immediately. You can update to WordPress 7.0.4 by downloading it from WordPress.org, or visiting your site’s Dashboard → Updates and …
Affected
7.0.4
Security fixes This security release resolves several vulnerabilities in CSF (CPANEL-54191, CPANEL-55183, CPANEL-54192, CPANEL-55265). It also includes several firewall reliability fixes for AlmaLinux 10, Debian, and Ubuntu. For a full list of changes, read the ConfigServer Security & Firewall (CSF) change log.
Affected
16.30-1
Faster site publishing Sitejet Builder now downloads website files in parallel when you publish a site. This reduces publish time for large sites. For a full list of changes, read the Sitejet Builder change log.
Affected
4.12.0-1
Introduced the Meridian interface We introduced Meridian, a new goal-based cPanel interface. Meridian organizes common hosting tasks into six purpose-built hubs for Websites, Email, Files, Databases, Security, and Performance. Its Dashboard highlights required actions, suggests relevant next steps, and provides an a…
Security Hotfix We released an updated ea-nginx package family (nginx 1.31.3) for EasyApache 4. This security release resolves three nginx vulnerabilities, including a critical heap buffer overflow in the map directive with regular expressions (CVE-2026-42533) that could allow remote code execution or a worker proce…
Affected
25.74
Maintenance updates We released updated packages for EasyApache 4. This maintenance release includes updates to ea-passenger-src (v6.1.8), ea-ruby27-passenger (v6.1.8), ea-redis62 (v6.2.23), ea-valkey72 (v7.2.14), ea-memcached16 (v1.6.45), and ea-podman (v1.0-23), plus companion rebuilds for ea-apache24-mod-passenge…
Affected
25.76
Stronger two-factor authentication for API requests We’ve added a Security Policy that closes a gap in API authentication: when it’s enabled alongside two-factor authentication (2FA), API requests can no longer skip 2FA protection. Once you turn on both settings, the system handles inbound API requests a…
Maintenance updates We released updated ea-tomcat101, ea-memcached16, ea-apache24-mod_security2, ea-modsec2-rules-owasp-crs, ea-ioncube15, ea-nodejs22, and Phusion Passenger 6.1.7 (ea-passenger-src, ea-ruby27-passenger, ea-apache24-mod-passenger, ea-nginx-passenger) packages for EasyApache 4. This maintenance releas…
Affected
25.73
Maintenance updates We released updated ea-modsec30, ea-modsec30-connector-apache24, and ea-modsec30-rules-owasp-crs packages for EasyApache 4. This maintenance release fixes ModSecurity audit logs silently failing to write across mod_ruid2 user IDs, forces a full Apache restart on package update so the updated libm…
Affected
25.72
Bug fixes This release fixes Comet Backup jobs failing en masse with locked-by-device retention errors on busy servers. The plugin now requests the less-often automatic-retention ruleset for dispatched backups and no longer cancels orphaned in-flight jobs, so overlapping retention passes cannot wedge the device.
Affected
1.5.6
Security hotfix We released updated ea-modsec30 and ea-modsec30-rules-owasp-crs packages for EasyApache 4. This security hotfix updates ea-modsec30 to 3.0.16, addressing two issues: CVE-2026-52747 (the multipart/form-data request body parser invalidly handled r and characters, allowing an unauthenticated WAF rule b…
Affected
25.71
Improved read-only API token enforcement Sitejet Builder UAPI methods are now classified as read-only for cPanel & WHM API token enforcement. For a full list of changes, read the Sitejet Builder change log.
Affected
4.11.0-1
Security and maintenance updates We released updated packages for EasyApache 4. This security release updates PHP 8.2, 8.3, 8.4, and 8.5 to address CVE-2026-14355 (a memory corruption issue in openssl_encrypt with AES-WRAP-PAD) and, for PHP 8.3, CVE-2026-12184 (a TLS setup failure leading to remote DoS). It also upd…
Affected
25.70
Security and maintenance updates We released an updated ea-tomcat101 package for EasyApache 4. This security release updates Apache Tomcat to 10.1.56, addressing six CVEs (CVE-2026-55956, CVE-2026-55955, CVE-2026-55276, CVE-2026-53434, CVE-2026-53404, CVE-2026-50229) with a top severity of Moderate. For a full list …
Affected
25.69
Maintenance updates We released updated packages for EasyApache 4. This maintenance release updates three nginx scripting and header modules: ea-nginx-echo to v0.65 (OOM safety fix), ea-nginx-headers-more to v0.40 (Content-Type charset parsing fix), and ea-nginx-njs to v1.0.0 (major version; includes security harden…
Affected
25.68
Bug fix We released a bug fix update for Site Quality Monitoring. * SQM-227: Fixed an infinite redirect loop and repeated authentication emails when re-opening Site Quality Monitoring from cPanel. For a full list of changes, read the Site Quality Monitoring change log.
Affected
3.2.0-1
Removed Sitejet AI promotional banner We removed the Sitejet AI promotional banner from the cPanel Tools page. This does not change Sitejet Builder functionality. For a full list of changes, read the Sitejet Builder change log.
Affected
4.10.0-1
Security updates We released updated packages for EasyApache 4. This security release updates ea-nginx from v1.31.1 to v1.31.2, addressing two CVEs from the nginx 2026-06-17 advisory: CVE-2026-42055 (Medium: buffer overflow in ngx_http_proxy_v2_module and ngx_http_grpc_module) and CVE-2026-48142 (Low: buffer over-re…
Affected
25.67
Security and maintenance updates We released updated packages for EasyApache 4. This security and maintenance release patches ea-openssl11 to 1.1.1w-8 (CentOS 7 only) with TuxCare/ELS backports addressing five CVEs including four High-severity issues (CVE-2026-45447, CVE-2026-34180, CVE-2026-7383, CVE-2026-9076). It…
Affected
25.66
AWS partner rollout Server Monitoring rollout for the AWS partner. For a full list of changes, read the Server Monitoring change log.
Affected
2.8.0-1
DigitalOcean partner rollout Server Monitoring rollout for the DigitalOcean partner. For a full list of changes, read the Server Monitoring change log.
Affected
2.7.0-1
Security and maintenance updates We released updated packages for EasyApache 4. This security and maintenance release updates ea-apache24 to v2.4.68, which addresses thirteen CVEs in the Apache HTTP Server including two critical mod_http2 issues (CVE-2026-49975, CVE-2026-48913). It also updates the Passenger ecosyst…
Affected
25.65
Google Cloud partner rollout Server Monitoring rollout for the Google Cloud partner. For a full list of changes, read the Server Monitoring change log.
Affected
2.6.0-1
Bug fixes This release fixes an issue where WebPros remote storage did not update after a Comet Backup license change, and enables cloud storage provisioning from the Destinations tab on storage-tier licenses with re-authentication resume.
Affected
1.5.5
Improved permission and domain-ownership validation Improve permission and domain-ownership validation for Sitejet actions. For a full list of changes, read the Sitejet Builder change log.
Affected
4.9.0-1
Bug fixes and improvements This release stops Comet backups from consuming all local disk space during a backup run, fixes restore backup options being hidden in the UI when no backup jobs exist, ensures the outbound User-Agent is not inherited from the parent process, removes the credentials download warning, and …
Affected
1.5.4
Security and maintenance updates We released updated packages for EasyApache 4. This security release patches CVE-2026-49975 in ea-apache24. Attackers can craft malicious HTTP/2 cookie headers that multiply across streams, consuming excessive memory. The fix makes cookie headers count against LimitRequestFields. Not…
Affected
25.64
Hotfix security release We released updated packages for EasyApache 4. This release addresses CVE-2026-9256 (nginx-poolslip), a critical remote code execution vulnerability affecting all nginx versions, fixed in ea-nginx 1.31.1. Phusion Passenger was also updated to version 6.1.3. For a full list of changes, read th…
Affected
25.63
Updated publish/polling access controls Improve Sitejet publish/polling access controls. For a full list of changes, read the Sitejet Builder change log.
Affected
4.8.0-1
Hotfix security release We released updated packages for EasyApache 4. This release addresses CVE-2026-8711 in ea-nginx-njs and CVE-2026-47783, CVE-2026-47784 in ea-memcached16. For a full list of changes, read the EasyApache 4 change log.
Affected
25.62
Maintenance release We released updated packages for EasyApache 4. For a full list of changes, read the EasyApache 4 change log.
Affected
25.61
Bug fixes Fixed regex.custom.pm custom rules silently failing to match log lines (CPANEL-53173). Fixed csf -cf $file no longer retaining newlines in the file (CPANEL-52801). For a full list of changes, read the ConfigServer Security & Firewall (CSF) change log.
Affected
16.20-1
SPA modal notification for new activations SPA modal notification after plugin activation. New partner rollout. For a full list of changes, read the Server Monitoring change log.
Affected
2.5.0-1
Conditional Server Monitoring registration Server Monitoring now only registers in WHM when it has been set up. For a full list of changes, read the Server Monitoring change log.
Affected
2.4.0-1
New "Start Monitoring" onboarding experience We updated the server monitoring setup flow. New servers no longer automatically create anonymous accounts. A new "Start Monitoring" button in the top widget lets users set up monitoring for servers without an anonymous account on demand. For a full li…
Affected
2.3.0-1
Security update We released updated packages for EasyApache 4. This security release addresses CVE-2026-42945 (Critical: heap buffer overflow in ngx_http_rewrite_module) in ea-nginx (v1.30.0 to v1.31.0), along with rebuilds of ea-nginx-echo, ea-nginx-headers-more, ea-nginx-passenger, and ea-nginx-njs against the pat…
Affected
25.60
Security and maintenance updates We released updated packages for EasyApache 4. This security release addresses CVE-2026-43515 and CVE-2026-43512 (Moderate) and five Low-severity CVEs in ea-tomcat101 (v10.1.54 to v10.1.55), and includes a heap buffer overflow fix in ea-apache24-mod_security2 (no CVE assigned) along …
Affected
25.59
Security and maintenance updates We released updated packages for EasyApache 4. This security release addresses CVE-2026-6735, CVE-2026-7259, CVE-2025-14179, CVE-2026-6722, CVE-2026-7261, CVE-2026-7262, CVE-2026-7568, and CVE-2026-7258 in ea-php82, ea-php83, ea-php84, and ea-php85. For a full list of changes, read t…
Affected
25.58
Security and maintenance updates We released updated packages for EasyApache 4. This security release updates ea-apache24 to 2.4.67, addressing 11 CVEs including an important remote code execution vulnerability (CVE-2026-23918 in mod_http2). It also patches ea-libcurl (CentOS 7 only) with 6 security fixes backported…
Affected
25.57
Managesieve LFD alert fix Added managesieve-login to csf.pignore to prevent excessive LFD resource alerts triggered by the Dovecot managesieve plugin (CPANEL-52448). For a full list of changes, read the ConfigServer Security & Firewall (CSF) change log.
Affected
16.18-1
LFD startup and detection fixes Fixed multiple LFD issues: brute-force IMAP/POP3 login failure detection on Dovecot 2.4, LFD not starting after cPanel version upgrades, firewall rules failing to load after package upgrades, and LFD startup crashes when /etc/csf/csf.error is absent. For a full list of changes, read t…
Affected
16.17-1
Annual billing now available for Solo, Admin, and Pro licenses Annual billing is now available for cPanel Solo ($329.49/year), Admin ($395.49/year), and Pro ($593.49/year) licenses in the <a href="https://store.cpanel.net/store/cpanel-licenses" target="_blank">cPanel Store. Annual subscript…
Maintenance updates We released updated packages for EasyApache 4. This maintenance release updates ea-nginx-njs from v0.9.6 to v0.9.7 and marks ea-scl-php54, ea-scl-php55, ea-scl-php56, ea-scl-php70, ea-scl-php71, ea-scl-php72, ea-scl-php73, ea-php74, ea-php80, ea-php81, ea-nodejs16, ea-nodejs18, ea-scl-ruby24, and…
Affected
25.56
Maintenance updates We released updated packages for EasyApache 4. This maintenance release includes an ea-nginx update from v1.29.8 to v1.30.0 with five associated module rebuilds, a libxml2 update from v2.15.2 to v2.15.3, and an nghttp2 update from v1.68.1 to v1.69.0. For a full list of changes, read the EasyApach…
Affected
25.55
Fixed enabling Vulnerability Protection with large vulnerability sets Enabling Vulnerability Protection no longer fails with a STDIN data is corrupted error when a WordPress installation contains a large number of vulnerabilities.
Affected
6.10.1
Security and maintenance updates We released updated packages for EasyApache 4. This security and maintenance release includes a security patch for ea-openssl11 (CVE-2026-28387, CVE-2026-28388, CVE-2026-28389, CVE-2026-28390), version updates for ea-php84 (8.4.19 to 8.4.20) and ea-php85 (8.5.4 to 8.5.5), and an ea-n…
Affected
25.54
Security Risk ratings for WordPress sites and components WP Toolkit now introduces a Security Risk rating for WordPress sites and individual components. This rating helps administrators quickly identify which vulnerable sites or plugins require attention first. As part of this change, the previous Vulnerabilities wi…
Affected
6.10.0
Updated monitoring polling interval DUCKS-5510: We updated the monitoring polling interval for signed and anonymous accounts. We also updated the permissions for the agent360.sh script. For a full list of changes, read the Server Monitoring change log.
Affected
2.2.0-1
Security and maintenance updates We released updated packages for EasyApache 4. This security and maintenance release includes CVE fixes for ea-ruby27-rubygem-rack (CVE-2026-34830, CVE-2026-34785) and ea-modsec2-rules-owasp-crs (CVE-2026-33691), and maintenance updates for ea-tomcat101, ea-re2c, and ea-cpanel-tools.…
Affected
25.53
cPanel & WHM updates now provide ConfigServer Security & Firewall (CSF) WebPros International, LLC has created a fork of CSF (ConfigServer Security & Firewall) for cPanel & WHM. We distribute this new fork of CSF via our update mirrors. cPanel & WHM will migrate any unsupported or outdated versio…
Updated Sitejet default feature list Sitejet Builder no longer enables itself in standalone Nova’s default feature list. For a full list of changes, read the Sitejet Builder change log.
Affected
4.7.1-1
Maintenance updates Package build maintenance updates for Sitejet Builder. For a full list of changes, read the Sitejet Builder change log.
Affected
4.7.0-1
Maintenance updates Package build maintenance updates for Site Quality Monitoring. For a full list of changes, read the Site Quality Monitoring change log.
Affected
3.1.0-1
Maintenance updates Package build maintenance updates for Server Monitoring. For a full list of changes, read the Server Monitoring change log.
Affected
2.1.0-1
Security and maintenance updates We released updated packages for EasyApache 4. This security and maintenance release addresses 6 CVEs in ea-nginx 1.29.7, 7 CVEs in ea-nodejs22 and ea-nodejs20, and 1 CVE in ea-nghttp2 (CVE-2026-27135). It also includes a proxy configuration fix for Apache 2.4.64+ compatibility, ngin…
Affected
25.52
Maintenance and security updates We released updated packages for EasyApache 4. This maintenance and security release includes security backports for ea-libcurl (4 CVEs from curl 8.19.0), version updates for ea-php84, ea-php85, and ea-nginx, and bug fixes for ea-apache24 and ea-cpanel-tools. For a full list of chang…
Affected
25.51
Package removal cleanup fix Fixed an issue where uninstalling cpanel-csf left the CSF plugin entry and LFD service status behind in WHM (CPANEL-51933). Also suppresses harmless errors on missing symlinks during upgrades. For a full list of changes, read the ConfigServer Security & Firewall (CSF) change log.
Affected
16.12-1
Maintenance updates We released updated packages for EasyApache 4. This maintenance release includes bug fixes for ea-nginx and version updates for ea-nginx-njs, ea-memcached16, ea-ruby27-libuv, ea-nodejs22, and ea-nodejs20. For a full list of changes, read the EasyApache 4 change log.
Affected
25.50
Package upgrade behavior fix Fixed an issue where upgrading cpanel-csf would overwrite custom csf-cron entries. For a full list of changes, read the ConfigServer Security & Firewall (CSF) change log.
Affected
16.11-1
The resource-agents packages provide the Pacemaker and RGManager service managers with a set of scripts. These scripts interface with several services to allow operating in a high-availability (HA) environment. Security Fix(es): * urllib3: urllib3: Information disclosure via cross-origin redirects forwarding…
The libtiff3 package provides libtiff 3, an older version of libtiff library for manipulating TIFF (Tagged Image File Format) image format files. This version should be used only if you are unable to use the current version of libtiff. Security Fix(es): * libtiff: libtiff: Heap-based buffer overflow via craf…
Yelp is the help browser for the GNOME desktop. It is designed to help you browse all the documentation on your system in one central tool, including traditional man pages, info pages and documentation written in DocBook. Security Fix(es): * yelp: yelp-xsl: Overly Permissive Content Security Policy in Yelp A…
The libgcrypt library provides general-purpose implementations of various cryptographic algorithms. Security Fix(es): * Libgcrypt: Libgcrypt: Denial of Service and buffer overflow via crafted ECDH ciphertext (CVE-2026-41989) For more details about the security issue(s), including the impact, a CVSS score, …
The kernel-rt packages provide the Real Time Linux Kernel, which enables fine-tuning for systems with extremely high determinism requirements. Security Fix(es): * kernel: xen: AMD Zen 2 Processors: Privilege escalation via improper CPU cache isolation (CVE-2025-54518) Bug Fix(es) and Enhancement(s): *…
The kernel packages contain the Linux kernel, the core of any Linux operating system. Security Fix(es): * kernel: xen: AMD Zen 2 Processors: Privilege escalation via improper CPU cache isolation (CVE-2025-54518) Bug Fix(es) and Enhancement(s): * Kernel crash in bpf_for_each_array_elem() due to missing…
The kernel packages contain the Linux kernel, the core of any Linux operating system. Security Fix(es): * kernel: Linux kernel: Denial of Service due to NULL function pointer race in timer shutdown (CVE-2025-68214) Bug Fix(es) and Enhancement(s): * Possible regression with FM350GL [almalinux-9.8.z] (J…
The kernel packages contain the Linux kernel, the core of any Linux operating system. Security Fix(es): * kernel: ipc: limit next_id allocation to the valid ID range (CVE-2026-52923) * kernel: tipc: fix double-free in tipc_buf_append() (CVE-2026-52993) * kernel: net: sched: UAF via missing handler for TC…
Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language. Security Fix(es): * brace-expansion: Brace-expansion: Denial of Service due to exponential-time complexity (CVE-2026-13149) * tar: Node-tar: Denial of Service via malforme…
FRRouting is free software that manages TCP/IP based routing protocols. It supports BGP4, OSPFv2, OSPFv3, ISIS, RIP, RIPng, PIM, NHRP, PBR, EIGRP and BFD. Security Fix(es): * frr: FRRouting: Denial of Service via crafted BGP UPDATE message (CVE-2026-37460) Bug Fix(es) and Enhancement(s): * Zebra is n…
The sg3_utils packages provide command-line utilities for devices that use the Small Computer System Interface (SCSI) command sets. Security Fix(es): * sg3_utils: sg3_utils: arbitrary command execution via udev property injection in sg_inq --export (CVE-2026-16313) Bug Fix(es) and Enhancement(s): * sg…
Mozilla Thunderbird is a standalone mail and newsgroup client. Security Fix(es): * firefox: thunderbird: Site isolation issue in the DOM: Navigation component (CVE-2026-15719) * firefox: thunderbird: Invalid pointer in the JavaScript: WebAssembly component (CVE-2026-15718) * firefox: thunderbird: Mitigat…
The ldns packages contain a library with the aim to simplify DNS programming in C. All low-level DNS/DNSSEC operations are supported. We also define a higher level API which allows a programmer to (for instance) create or sign packets. Security Fix(es): * ldns: ldns: Off-path poisoning attacks due to insuffi…
The p11-kit packages provide a mechanism to manage PKCS#11 modules. The p11-kit-trust subpackage includes a PKCS#11 trust module that provides certificate anchors and black lists based on configuration files. Security Fix(es): * p11-kit: Stack exhaustion via unbounded recursion in RPC attribute parsing (CVE-…
Yelp is the help browser for the GNOME desktop. It is designed to help you browse all the documentation on your system in one central tool, including traditional man pages, info pages and documentation written in DocBook. Security Fix(es): * yelp: yelp-xsl: Overly Permissive Content Security Policy in Yelp A…
PipeWire is a multimedia server for Linux and other Unix like operating systems. Security Fix(es): * pipewire: PipeWire: Sandbox escape and arbitrary code execution via malicious library loading (CVE-2026-5674) For more details about the security issue(s), including the impact, a CVSS score, acknowledgment…
X.Org X11 libXfont2 runtime library Security Fix(es): * libXfont2: BitmapScaleBitmaps Integer Overflow Heap Buffer Overflow (CVE-2026-56001) * libXfont2: PCF Font Parsing Heap Buffer Overflow (CVE-2026-56002) For more details about the security issue(s), including the impact, a CVSS score, acknowledgment…
The fence-agents packages provide a collection of scripts for handling remote power management for cluster devices. They allow failed or unreachable nodes to be forcibly restarted and removed from the cluster. Security Fix(es): * httplib2: httplib2: Denial of Service via unbounded decompression of HTTP resp…
The GIMP (GNU Image Manipulation Program) is an image composition and editing program. GIMP provides a large image manipulation toolbox, including channel operations and layers, effects, sub-pixel imaging and anti-aliasing, and conversions, all with multi-level undo. Security Fix(es): * gimp: GIMP APNG loade…
The OpenJDK 25 packages provide the OpenJDK 25 Java Runtime Environment and the OpenJDK 25 Java Software Development Kit. Security Fix(es): * JDK: Enhance TLS certificate handling (CVE-2026-46968) * JDK: Improve DTLS handshaking (CVE-2026-46917) * JDK: Enhance JPEG handling (CVE-2026-47010) * JDK: Enha…
Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language. Security Fix(es): * brace-expansion: Brace-expansion: Denial of Service due to exponential-time complexity (CVE-2026-13149) * tar: Node-tar: Denial of Service via malforme…
GStreamer is a streaming media framework based on graphs of filters which operate on media data. The gstreamer1-plugins-bad-free package contains a collection of plug-ins for GStreamer. Security Fix(es): * gstreamer: gstreamer: rfbsrc/librfb Hextile heap out-of-bounds write with 16bpp framebuffer (CVE-2026-5…
Multiple vulnerabilities were found in the ConfigServer Firewall (CSF) plugin. Exploiting the vulnerabilities could allow an attacker to gain root access.
Affected
16.20-1 and earlier
Patched
16.30-1
CentOS 7 / CloudLinux 7
yum clean all
/scripts/update-packages
AlmaLinux / CloudLinux 8/9/10
dnf clean metadata
/scripts/update-packages
A remote code execution vulnerability was discovered in the cPanel email filters interface. Attackers with a low-privilege account could execute commands as root.
Affected
TUI 18.0.42 and earlier
Patched
TUI 18.0.48
CentOS 7 / CloudLinux 7
yum clean all
/scripts/upcp --force
AlmaLinux 9 / CloudLinux 9
dnf clean metadata
/scripts/upcp --force
A vulnerability in CloudLinux LVE Manager allowed environment variable injection via the $HTTP_HOST header, potentially leading to unauthorized access to protected resources.
Affected
7.4 and earlier
Patched
7.5
CloudLinux 7
yum clean all
yum update cl-lve
CloudLinux 9
dnf clean metadata
dnf update cl-lve
A heap buffer overflow was identified in LiteSpeed Web Server HTTP/2 handling. A crafted request could cause a crash or remote code execution.
Affected
6.0.4 and earlier
Patched
6.0.5
CentOS 7
yum clean all
/usr/local/lsws/bin/lshttpd -v
AlmaLinux 9
dnf clean metadata
/usr/local/lsws/bin/lshttpd -v
A privilege escalation flaw in DirectAdmin allowed a user to escalate privileges and gain access to other accounts on the same server.
Affected
1.660 and earlier
Patched
1.661
CentOS 7 / AlmaLinux 9
da-setup da
/usr/local/directadmin/scripts/update.sh
Ubuntu 22.04 / Debian 12
da-setup da
/usr/local/directadmin/scripts/update.sh
A stored cross-site scripting (XSS) vulnerability was found in the WHMCS admin panel, allowing an authenticated user to inject malicious scripts.
Affected
8.7.0 and earlier
Patched
8.7.1
Any supported OS
cd /var/www/html
php composer.phar update whmcs/core
A Linux kernel KVM flaw affecting CloudLinux 7h-10, including servers running no VMs. Checks, mitigation and fix status. The post Zapscape (CVE-2026-64561) KVM guest escape and local root: mitigation and kernel update for CloudLinux appeared first on CloudLinux.
A kernel-level exploit bypass was discovered in Imunify360 active protection, reducing effectiveness of exploit detection on newer kernels.
Affected
5.5.0 and earlier
Patched
5.6.0
CentOS 7 / AlmaLinux 9
yum clean all
yum update imunify360-firewall
Ubuntu 22.04
apt update
apt install --only-upgrade imunify360-firewall
A configuration issue in JetBackup could expose S3 storage credentials in server logs, potentially compromising backup destinations.
Affected
5.3.0 and earlier
Patched
5.3.1
CentOS 7 / AlmaLinux 9
yum clean all
yum update jetbackup
Zapscape (CVE-2026-64561) is a Linux kernel KVM vulnerability enabling guest-to-host escape and local root privilege escalation on CloudLinux 7–10, including hosts running no VMs. Fixed in the August 6, 2026 kernel update.
The fence-agents packages provide a collection of scripts for handling remote power management for cluster devices. They allow failed or unreachable nodes to be forcibly restarted and removed from the cluster. Security Fix(es): * urllib3: urllib3: Information disclosure via cross-origin redirects forwarding…
The kernel-rt packages provide the Real Time Linux Kernel, which enables fine-tuning for systems with extremely high determinism requirements. Security Fix(es): * kernel: ipc: limit next_id allocation to the valid ID range (CVE-2026-52923) Bug Fix(es) and Enhancement(s): * AlmaLinux8.10 - KVM: s390: L…
The kernel packages contain the Linux kernel, the core of any Linux operating system. Security Fix(es): * kernel: ipc: limit next_id allocation to the valid ID range (CVE-2026-52923) Bug Fix(es) and Enhancement(s): * AlmaLinux8.10 - KVM: s390: Limit adapter indicator access to mapped page (JIRA:AlmaLi…
Mozilla Thunderbird is a standalone mail and newsgroup client. Security Fix(es): * firefox: thunderbird: Site isolation issue in the DOM: Navigation component (CVE-2026-15719) * firefox: thunderbird: Invalid pointer in the JavaScript: WebAssembly component (CVE-2026-15718) * firefox: thunderbird: Mitigat…
DBI is a database access Application Programming Interface (API) for the Perl Language. The DBI API Specification defines a set of functions, variables and conventions that provide a consistent database interface independent of the actual database being used. Security Fix(es): * DBI: DBI: Arbitrary code exec…
The ldns packages contain a library with the aim to simplify DNS programming in C. All low-level DNS/DNSSEC operations are supported. We also define a higher level API which allows a programmer to (for instance) create or sign packets. Security Fix(es): * ldns: ldns: Off-path poisoning attacks due to insuffi…
Archive::Tar provides an object oriented mechanism for handling tar files. It provides class methods for quick and easy files handling while also allowing for the creation of tar file objects for custom manipulation. If you have the IO::Zlib module installed, Archive::Tar will also support compressed or gzipped tar …
GLib provides the core application building blocks for libraries and applications written in C. It provides the core object system used in GNOME, the main loop implementation, and a large set of utility functions for strings and common data structures. Security Fix(es): * glib: GLib: Buffer underflow in GVar…
FRRouting is free software that manages TCP/IP based routing protocols. It supports BGP4, OSPFv2, OSPFv3, ISIS, RIP, RIPng, PIM, NHRP, PBR, EIGRP and BFD. Security Fix(es): * frr: FRRouting: Denial of Service via crafted BGP UPDATE message (CVE-2026-37460) For more details about the security issue(s), inc…
Archive::Tar provides an object oriented mechanism for handling tar files. It provides class methods for quick and easy files handling while also allowing for the creation of tar file objects for custom manipulation. If you have the IO::Zlib module installed, Archive::Tar will also support compressed or gzipped tar …
Perl is a high-level programming language that is commonly used for system administration utilities and web programming. Security Fix(es): * perl-Archive-Tar: perl-Archive-Tar: Denial of Service via crafted tar header with large entry size (CVE-2026-9538) For more details about the security issue(s), inclu…
Affected
5.32
The kernel-rt packages provide the Real Time Linux Kernel, which enables fine-tuning for systems with extremely high determinism requirements. Security Fix(es): * kernel: rtnetlink: add missing netlink_ns_capable() check for peer netns (CVE-2026-31692) * kernel: netfilter: ctnetlink: ensure safe access to …
The kernel packages contain the Linux kernel, the core of any Linux operating system. Security Fix(es): * kernel: rtnetlink: add missing netlink_ns_capable() check for peer netns (CVE-2026-31692) * kernel: netfilter: ctnetlink: ensure safe access to master conntrack (CVE-2026-43116) * kernel: fanotify: f…
The kernel packages contain the Linux kernel, the core of any Linux operating system. Security Fix(es): * kernel: xfrm: Duplicate SPI Handling (CVE-2025-39797) * kernel: lib/buildid: use __kernel_read() for sleepable context (CVE-2026-23002) * kernel: futex: Drop CLONE_THREAD requirement for private defa…
Maxim Suhanov discovered that the NTFS file system implementation in the Linux kernel did not properly validate file name length in certain situations, leading to an out-of-bounds read. An attacker could use this to construct a malicious NTFS image that, when mounted and operated on, could expose sensitive informati…
Maxim Suhanov discovered that the NTFS file system implementation in the Linux kernel did not properly validate file name length in certain situations, leading to an out-of-bounds read. An attacker could use this to construct a malicious NTFS image that, when mounted and operated on, could expose sensitive informati…
The unbound packages provide a validating, recursive, and caching DNS or DNSSEC resolver. Security Fix(es): * unbound: Unbound: Denial of Service via excessive EDNS options (CVE-2026-41292) * unbound: Unbound: Cache manipulation via 'ghost domain names' attack (CVE-2026-40622) * unbound: Unbound: Denial…
.NET is a managed-software framework. It implements a subset of the .NET framework APIs and several new APIs, and it includes a CLR implementation. New versions of .NET that address a security vulnerability are now available. The updated versions are .NET SDK 9.0.119 and .NET Runtime 9.0.18. Security Fix(es): …
Affected
9.0
The fence-agents packages provide a collection of scripts for handling remote power management for cluster devices. They allow failed or unreachable nodes to be forcibly restarted and removed from the cluster. Security Fix(es): * httplib2: httplib2: Denial of Service via unbounded decompression of HTTP resp…
.NET is a managed-software framework. It implements a subset of the .NET framework APIs and several new APIs, and it includes a CLR implementation. New versions of .NET that address a security vulnerability are now available. The updated versions are .NET SDK 10.0.110 and .NET Runtime 10.0.10. Security Fix(es)…
Affected
10.0
.NET is a managed-software framework. It implements a subset of the .NET framework APIs and several new APIs, and it includes a CLR implementation. New versions of .NET that address a security vulnerability are now available. The updated versions are .NET SDK 8.0.129 and .NET Runtime 8.0.29. Security Fix(es): …
Affected
8.0
The coreutils packages contain the GNU Core Utilities and represent a combination of the previously used GNU fileutils, sh-utils, and textutils packages. Bug Fix(es) and Enhancement(s): * Fix execution of the downstream tests in coreutils-df-direct.patch and coreutils-i18n.patch [almalinux-8.10.z] (JIRA:Alma…
Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. Python supports interfaces to many system calls and libraries, as well as to various windowing systems. Security Fix(es): * Pillow: …
A service for building customized OS artifacts, such as VM images and OSTree commits, that uses osbuild under the hood. Besides building images for local usage, it can also upload images directly to cloud. It is compatible with composer-cli and cockpit-composer clients. Security Fix(es): * google.golang.org/…
The kernel packages contain the Linux kernel, the core of any Linux operating system. Security Fix(es): * kernel: KVM: x86: Don't (re)check L1 intercepts when completing userspace I/O (CVE-2025-40026) * kernel: dm log: fix out-of-bounds write due to region_count overflow (CVE-2026-53059) * kernel: drm/xe…
The unbound packages provide a validating, recursive, and caching DNS or DNSSEC resolver. Security Fix(es): * unbound: Unbound: Denial of Service via excessive EDNS options (CVE-2026-41292) * unbound: Unbound: Cache manipulation via 'ghost domain names' attack (CVE-2026-40622) * unbound: Unbound: Denial…
.NET is a managed-software framework. It implements a subset of the .NET framework APIs and several new APIs, and it includes a CLR implementation. New versions of .NET that address a security vulnerability are now available. The updated versions are .NET SDK 10.0.110 and .NET Runtime 10.0.10. Security Fix(es)…
Affected
10.0
.NET is a managed-software framework. It implements a subset of the .NET framework APIs and several new APIs, and it includes a CLR implementation. New versions of .NET that address a security vulnerability are now available. The updated versions are .NET SDK 9.0.119 and .NET Runtime 9.0.18. Security Fix(es): …
Affected
9.0
Kernel-based Virtual Machine (KVM) is a full virtualization solution for Linux on a variety of architectures. The qemu-kvm packages provide the user-space component for running virtual machines that use KVM. Security Fix(es): * qemu-kvm: Heap buffer overflow in virtio-blk SCSI request handling (CVE-2026-4891…
.NET is a managed-software framework. It implements a subset of the .NET framework APIs and several new APIs, and it includes a CLR implementation. New versions of .NET that address a security vulnerability are now available. The updated versions are .NET SDK 8.0.129 and .NET Runtime 8.0.29. Security Fix(es): …
Affected
8.0
OpenSSH is an SSH protocol implementation supported by a number of Linux, UNIX, and similar operating systems. It includes the core files necessary for both the OpenSSH client and server. Security Fix(es): * openssh: Local MITM of X11 forwarding via abstract UNIX socket pre-binding in AlmaLinux OpenSSH clien…
Vim (Vi IMproved) is an updated and improved version of the vi editor. Security Fix(es): * vim: Vim: Denial of Service via stack out-of-bounds write in spell_soundfold_sofo() (CVE-2026-57455) * vim: Vim: Arbitrary code execution via malicious docstrings in Python omni-completion (CVE-2026-57456) * vim: V…
It was discovered that OpenSSL incorrectly allocated memory buffers in the SSL/TLS state machine when receiving handshake data. A remote attacker could possibly use this issue to cause OpenSSL to consume excessive memory, leading to a denial of service. This issue is known as the "HollowByte" denial of service.
OpenSSH is an SSH protocol implementation supported by a number of Linux, UNIX, and similar operating systems. It includes the core files necessary for both the OpenSSH client and server. Security Fix(es): * openssh: Local MITM of X11 forwarding via abstract UNIX socket pre-binding in AlmaLinux OpenSSH clien…
Vim (Vi IMproved) is an updated and improved version of the vi editor. Security Fix(es): * vim: Vim: Denial of Service via stack out-of-bounds write in spell_soundfold_sofo() (CVE-2026-57455) * vim: Vim: Arbitrary code execution via malicious docstrings in Python omni-completion (CVE-2026-57456) * vim: V…
OVSwrap (CVE-2026-64531): a Linux kernel flaw giving local root on CloudLinux 9, 10 and CloudLinux for Ubuntu. No kernel fix yet; apply the mitigation. The post OVSwrap (CVE-2026-64531) local root exploit: mitigation for CloudLinux 9, 10, and CloudLinux for Ubuntu appeared first on CloudLinux.
It was discovered that Sinatra did not properly handle header parsing, causing ETag generation to hang when given specific input. A remote attacker could possibly use this issue to cause a denial of service.
Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - ARM64 architecture; - Arm Firmware Framework for ARMv8-A(FFA); (CVE-2026-53354, CVE-2026-64520)
Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - ARM64 architecture; - Arm Firmware Framework for ARMv8-A(FFA); (CVE-2026-53354, CVE-2026-64520)
Maxim Suhanov discovered that the NTFS file system implementation in the Linux kernel did not properly validate file name length in certain situations, leading to an out-of-bounds read. An attacker could use this to construct a malicious NTFS image that, when mounted and operated on, could expose sensitive informati…
It was discovered that a logic flaw existed in the XFRM ESP-in-TCP subsystem in the Linux kernel when handling socket buffer fragments. This flaw is known as Fragnesia. A local attacker could use this to escalate privileges, or possibly escape a container. (CVE-2026-43503) Several security issues were discovered in…
Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language. Security Fix(es): * brace-expansion: Brace-expansion: Denial of Service due to exponential-time complexity (CVE-2026-13149) * tar: Node-tar: Denial of Service via malforme…
Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language. Security Fix(es): * brace-expansion: Brace-expansion: Denial of Service due to exponential-time complexity (CVE-2026-13149) * tar: Node-tar: Denial of Service via malforme…
The libtiff packages contain a library of functions for manipulating Tagged Image File Format (TIFF) files. Security Fix(es): * libtiff: libtiff: Heap-based buffer overflow via crafted PixarLog-compressed TIFF image (CVE-2026-12912) For more details about the security issue(s), including the impact, a CVSS…
GStreamer is a streaming media framework based on graphs of filters which operate on media data. The gstreamer1-plugins-bad-free package contains a collection of plug-ins for GStreamer. Security Fix(es): * gstreamer: gstreamer: rfbsrc/librfb Hextile heap out-of-bounds write with 16bpp framebuffer (CVE-2026-5…
X.Org X11 libXfont2 runtime library Security Fix(es): * libXfont2: BitmapScaleBitmaps Integer Overflow Heap Buffer Overflow (CVE-2026-56001) * libXfont2: PCF Font Parsing Heap Buffer Overflow (CVE-2026-56002) * libXfont2: computeProps Property Buffer Heap Buffer Overflow (CVE-2026-56003) For more detai…
USN-8561-1 fixed vulnerabilities in FreeRDP. Unfortunately, the upgrade to version 3.30.0 introduced a regression in the clipboard functionality. This update fixes the problem. We apologize for the inconvenience. Original advisory details: It was discovered that FreeRDP contained multiple security issues. An at…
It was discovered that Samba's pam_winbind incorrectly handled home directory ownership when mkhomedir was enabled. A local attacker could possibly use this issue to cause a denial of service by triggering a change in ownership of the root directory. (CVE-2026-15779) Arjun Basnet, Douglas Bagnall, and Andrew Tridge…
The kernel-rt packages provide the Real Time Linux Kernel, which enables fine-tuning for systems with extremely high determinism requirements. Security Fix(es): * kernel: ipv6: fix possible UAF in icmpv6_rcv() (CVE-2026-53006) For more details about the security issue(s), including the impact, a CVSS score…
The kernel packages contain the Linux kernel, the core of any Linux operating system. Security Fix(es): * kernel: ipv6: fix possible UAF in icmpv6_rcv() (CVE-2026-53006) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer t…
The System Security Services Daemon (SSSD) service provides a set of daemons to manage access to remote directories and authentication mechanisms. It also provides the Name Service Switch (NSS) and the Pluggable Authentication Modules (PAM) interfaces toward the system, and a pluggable back-end system to connect to …
Dovecot is an IMAP server for Linux and other UNIX-like systems, written primarily with security in mind. It also contains a small POP3 server, and supports e-mail in either the maildir or mbox format. The SQL drivers and authentication plug-ins are provided as subpackages. Security Fix(es): * dovecot: Dove…
Grafana is an open source, feature rich metrics dashboard and graph editor for Graphite, InfluxDB & OpenTSDB. Security Fix(es): * github.com/go-git/go-billy: Billy: Denial of Service via crafted input due to insufficient validation (CVE-2026-44740) Bug Fix(es) and Enhancement(s): * [grafana / alm…
Libreswan is an implementation of IPsec and IKE for Linux. IPsec is the Internet Protocol Security and uses strong cryptography to provide both authentication and encryption services. These services allow you to build secure tunnels through untrusted networks such as virtual private network (VPN). Security Fix(es…
Libreswan is an implementation of IPsec and IKE for Linux. IPsec is the Internet Protocol Security and uses strong cryptography to provide both authentication and encryption services. These services allow you to build secure tunnels through untrusted networks such as virtual private network (VPN). Security Fix(es…
The kernel packages contain the Linux kernel, the core of any Linux operating system. Bug Fix(es) and Enhancement(s): * XFS data corruption using reflink [almalinux-9.8.z] (JIRA:AlmaLinux-193937)
The kernel packages contain the Linux kernel, the core of any Linux operating system. Security Fix(es): * kernel: KVM: x86: Don't (re)check L1 intercepts when completing userspace I/O (CVE-2025-40026) * kernel: xfrm single-frag length not properly limited * kernel: dm log: fix out-of-bounds write due to …
The kernel-rt packages provide the Real Time Linux Kernel, which enables fine-tuning for systems with extremely high determinism requirements. Security Fix(es): * kernel: KVM: x86: Don't (re)check L1 intercepts when completing userspace I/O (CVE-2025-40026) * kernel: xfrm single-frag length not properly …
The java-1.8.0-openjdk packages provide the OpenJDK 8 Java Runtime Environment and the OpenJDK 8 Java Software Development Kit. Security Fix(es): * JDK: Enhance TLS certificate handling (CVE-2026-46968) * JDK: Enhance JPEG handling (CVE-2026-47010) * JDK: Enhance XBM image support (CVE-2026-47021) * JD…
Affected
1.8.0
The OpenJDK 21 packages provide the OpenJDK 21 Java Runtime Environment and the OpenJDK 21 Java Software Development Kit. Security Fix(es): * JDK: Enhance TLS certificate handling (CVE-2026-46968) * JDK: Improve DTLS handshaking (CVE-2026-46917) * JDK: Enhance JPEG handling (CVE-2026-47010) * JDK: Enha…
The java-17-openjdk packages provide the OpenJDK 17 Java Runtime Environment and the OpenJDK 17 Java Software Development Kit. Security Fix(es): * JDK: Enhance TLS certificate handling (CVE-2026-46968) * JDK: Improve DTLS handshaking (CVE-2026-46917) * JDK: Enhance JPEG handling (CVE-2026-47010) * JDK:…
The java-1.8.0-openjdk packages provide the OpenJDK 8 Java Runtime Environment and the OpenJDK 8 Java Software Development Kit. Security Fix(es): * JDK: Enhance TLS certificate handling (CVE-2026-46968) * JDK: Enhance JPEG handling (CVE-2026-47010) * JDK: Enhance XBM image support (CVE-2026-47021) * JD…
Affected
1.8.0
The kernel packages contain the Linux kernel, the core of any Linux operating system. Security Fix(es): * kernel: crypto: af_alg - zero initialize memory allocated via sock_kmalloc (CVE-2025-71113) * kernel: scsi: core: Wake up the error handler when final completions race against each other (CVE-2026-2311…
The java-17-openjdk packages provide the OpenJDK 17 Java Runtime Environment and the OpenJDK 17 Java Software Development Kit. Security Fix(es): * JDK: Enhance TLS certificate handling (CVE-2026-46968) * JDK: Improve DTLS handshaking (CVE-2026-46917) * JDK: Enhance JPEG handling (CVE-2026-47010) * JDK:…
The System Security Services Daemon (SSSD) service provides a set of daemons to manage access to remote directories and authentication mechanisms. It also provides the Name Service Switch (NSS) and the Pluggable Authentication Modules (PAM) interfaces toward the system, and a pluggable back-end system to connect to …
The OpenJDK 21 packages provide the OpenJDK 21 Java Runtime Environment and the OpenJDK 21 Java Software Development Kit. Security Fix(es): * JDK: Enhance TLS certificate handling (CVE-2026-46968) * JDK: Improve DTLS handshaking (CVE-2026-46917) * JDK: Enhance JPEG handling (CVE-2026-47010) * JDK: Enha…
The OpenSSL toolkit provides support for secure communications between machines. This version of OpenSSL package contains only the libraries from the 1.1.1 version and is provided for compatibility with previous releases. Security Fix(es): * openssl: Heap Use-After-Free in OpenSSL PKCS7_verify() (CVE-2026-45…
The libpq package provides the PostgreSQL client library, which allows client programs to connect to PostgreSQL servers. Security Fix(es): * postgresql: PostgreSQL libpq: Buffer overflow allows server superuser to overwrite client stack memory (CVE-2026-6477) For more details about the security issue(s), …
The glibc packages provide the standard C libraries (libc), POSIX thread libraries (libpthread), standard math libraries (libm), and the name service cache daemon (nscd) used by multiple programs on the system. Without these libraries, the Linux system cannot function correctly. Security Fix(es): * glibc: gl…
RefluXFS (CVE-2026-64600) is a Linux kernel Local Privilege Escalation in the XFS filesystem, present in every kernel from v4.11 (April 2017) onward. On an affected host, an unprivileged local user can gain root, with no capabilities, namespaces, or special hardware required. It was discovered by Qualys and publicly…
One of Europe’s largest cloud providers just spent eleven days rebooting the infrastructure behind roughly a million customer VMs to close a single kernel vulnerability. A hard call, executed well, and a preview of the decision every hosting provider will face again. Because there will be a next one. When a cr…
The Public Key Infrastructure (PKI) Core contains fundamental packages required by AlmaLinux Certificate System. Security Fix(es): * jackson-databind: Jackson-databind: Security bypass allows arbitrary code execution (CVE-2026-54513) For more details about the security issue(s), including the impact, a CVS…
Affected
10.6
Access Control Lists (ACLs) are used to define fine-grained discretionary access rights for files and directories. The acl packages contain the getfacl and setfacl utilities needed for manipulating access control lists. Security Fix(es): * acl: Symlink traversal privilege escalation via libacl functions (CVE…
The javapackages-tools packages provide macros and scripts to support Java packaging. Security Fix(es): * org.codehaus.plexus:plexus-utils: Plexus-utils: Directory Traversal in extractFile method (CVE-2025-67030) For more details about the security issue(s), including the impact, a CVSS score, acknowledgme…
The glibc packages provide the standard C libraries (libc), POSIX thread libraries (libpthread), standard math libraries (libm), and the name service cache daemon (nscd) used by multiple programs on the system. Without these libraries, the Linux system cannot function correctly. Security Fix(es): * glibc: gl…
Go Toolset provides the Go programming language tools and libraries. Go is alternatively known as golang. Security Fix(es): * golang: internal/syscall/unix: Root.Chmod can follow symlinks out of the root (CVE-2026-32282) * crypto/tls: golang: Go crypto/tls: Denial of Service via multiple TLS 1.3 key updat…
The httpd packages provide the Apache HTTP Server, a powerful, efficient, and extensible web server. Security Fix(es): * httpd: incomplete fix for CVE-2023-38709 (CVE-2024-42516) * httpd: NULL pointer dereference via specially crafted request (CVE-2026-29169) * httpd: Apache HTTP Server: Heap-based Buffe…
Affected
2.4
Grafana is an open source, feature rich metrics dashboard and graph editor for Graphite, InfluxDB & OpenTSDB. Security Fix(es): * golang: internal/syscall/unix: Root.Chmod can follow symlinks out of the root (CVE-2026-32282) * crypto/tls: golang: Go crypto/tls: Denial of Service via multiple TLS 1.3 k…
The Grafana plugin for Performance Co-Pilot includes datasources for scalable time series from pmseries and Redis, live PCP metrics and bpftrace scripts from pmdabpftrace, as well as several dashboards. Security Fix(es): * golang: internal/syscall/unix: Root.Chmod can follow symlinks out of the root (CVE-202…
Dovecot is an IMAP server for Linux and other UNIX-like systems, written primarily with security in mind. It also contains a small POP3 server, and supports e-mail in either the maildir or mbox format. The SQL drivers and authentication plug-ins are provided as subpackages. Security Fix(es): * dovecot: Dove…
Access Control Lists (ACLs) are used to define fine-grained discretionary access rights for files and directories. The acl packages contain the getfacl and setfacl utilities needed for manipulating access control lists. Security Fix(es): * acl: Symlink traversal privilege escalation via libacl functions (CVE…
The libtiff packages contain a library of functions for manipulating Tagged Image File Format (TIFF) files. Security Fix(es): * libtiff: libtiff: Heap-based buffer overflow via crafted PixarLog-compressed TIFF image (CVE-2026-12912) For more details about the security issue(s), including the impact, a CVSS…
A vulnerability in the Plesk PHP Updater allows an authenticated admin to write files outside the intended directory, leading to remote code execution as the psaserv service user.
Affected
Plesk Obsidian 18.0.63 and earlier
Patched
Plesk Obsidian 18.0.65
AlmaLinux 9 / CloudLinux 9
plesk installer update --select-product-id plesk
plesk sbin packagemng --update
Ubuntu 22.04 / Debian 12
apt update
plesk installer update --select-product-id plesk
Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language. Security Fix(es): * ip-address: ip-address: Cross-site scripting via improper HTML escaping of untrusted input (CVE-2026-42338) * undici: undici: Denial of Service due to …
GLib provides the core application building blocks for libraries and applications written in C. It provides the core object system used in GNOME, the main loop implementation, and a large set of utility functions for strings and common data structures. Security Fix(es): * glib: integer underflow in gio/gdbus…
WebKitGTK is the port of the portable web rendering engine WebKit to the GTK platform. Security Fix(es): * Mozilla: Arbitrary JavaScript execution in PDF.js (CVE-2024-4367) * webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash (CVE-2026-39872) * webkitgtk: webkitgtk: …
The kernel-rt packages provide the Real Time Linux Kernel, which enables fine-tuning for systems with extremely high determinism requirements. Security Fix(es): * kernel: RDMA/mana: Remove user triggerable WARN_ON() in mana_ib_create_qp_rss() (CVE-2026-46117) * kernel: Bluetooth: l2cap: Add missing chan lo…
The kernel packages contain the Linux kernel, the core of any Linux operating system. Security Fix(es): * kernel: RDMA/mana: Remove user triggerable WARN_ON() in mana_ib_create_qp_rss() (CVE-2026-46117) * kernel: Bluetooth: l2cap: Add missing chan lock in l2cap_ecred_reconf_rsp (CVE-2026-53071) Bug Fix(e…
WebKitGTK is the port of the portable web rendering engine WebKit to the GTK platform. Security Fix(es): * Mozilla: Arbitrary JavaScript execution in PDF.js (CVE-2024-4367) * webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash (CVE-2026-39872) * webkitgtk: webkitgtk: …
GLib provides the core application building blocks for libraries and applications written in C. It provides the core object system used in GNOME, the main loop implementation, and a large set of utility functions for strings and common data structures. Security Fix(es): * glib: integer underflow in gio/gdbus…
Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. Python supports interfaces to many system calls and libraries, as well as to various windowing systems. Security Fix(es): * python: …
The httpd packages provide the Apache HTTP Server, a powerful, efficient, and extensible web server. Security Fix(es): * httpd: incomplete fix for CVE-2023-38709 (CVE-2024-42516) * Apache HTTP Server: mod_rewrite: Apache HTTP Server: Privilege Escalation via .htaccess file manipulation (CVE-2026-24072) *…
The Pacemaker cluster resource manager is a collection of technologies working together to maintain data integrity and application availability in the event of failures. Security Fix(es): * pacemaker: Pacemaker: Denial of Service via integer overflow in remote message decompression (CVE-2026-10649) For mo…
Maven is a software project management and comprehension tool. Based on the concept of a project object model (POM), Maven can manage a project's build, reporting and documentation from a central piece of information. Security Fix(es): * org.codehaus.plexus:plexus-utils: Plexus-utils: Directory Traversal in …
Affected
3.8
The hplip packages contain the Hewlett-Packard Linux Imaging and Printing Project (HPLIP), which provides drivers for Hewlett-Packard printers and multi-function peripherals. Security Fix(es): * HPLIP: Incomplete Fix for CVE-2026-8631 (CVE-2026-14544) For more details about the security issue(s), including…
Capstone is a disassembly framework with the target of becoming the ultimate disasm engine for binary analysis and reversing in the security community. Security Fix(es): * capstone: Capstone: Memory corruption via unchecked vsnprintf return (CVE-2025-68114) For more details about the security issue(s), inc…
The general-purpose data-binding functionality and tree-model for Jackson Data Processor. It builds on core streaming parser/generator package, and uses Jackson Annotations for configuration. Security Fix(es): * jackson-databind: Jackson-databind: Security bypass allows arbitrary code execution (CVE-2026-545…
The hplip packages contain the Hewlett-Packard Linux Imaging and Printing Project (HPLIP), which provides drivers for Hewlett-Packard printers and multi-function peripherals. Security Fix(es): * HPLIP: Incomplete Fix for CVE-2026-8631 (CVE-2026-14544) For more details about the security issue(s), including…
The GIMP (GNU Image Manipulation Program) is an image composition and editing program. GIMP provides a large image manipulation toolbox, including channel operations and layers, effects, sub-pixel imaging and anti-aliasing, and conversions, all with multi-level undo. Security Fix(es): * gimp: gimp: Stack buf…
Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language. Security Fix(es): * ip-address: ip-address: Cross-site scripting via improper HTML escaping of untrusted input (CVE-2026-42338) * undici: undici: Denial of Service due to …
The container-tools module contains tools for working with containers, notably podman, buildah, skopeo, and runc. Security Fix(es): * net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME (CVE-2026-33811) * golang.org/x/crypto/ssh: golang: golang.org/x/crypto/ssh: Denial of …
LibreOffice is an open source, community-developed office productivity suite. It includes key desktop applications, such as a word processor, a spreadsheet, a presentation manager, a formula editor, and a drawing program. LibreOffice replaces OpenOffice and provides a similar but enhanced and extended office suite. …
This module implements a Perl interface to the GNOME libxml2 library which provides interfaces for parsing and manipulating XML files. This module allows Perl programmers to make use of the highly capable validating XML parser and the high performance DOM implementation. Security Fix(es): * perl-XML-LibXML: …
The SMB/CIFS protocol is a standard file sharing protocol widely deployed on Microsoft Windows machines. The cifs-utils packages contain tools for mounting shares on Linux using the SMB/CIFS protocol. The tools in this package work in conjunction with support in the kernel to allow one to mount a SMB/CIFS share onto…
Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. Python supports interfaces to many system calls and libraries, as well as to various windowing systems. Security Fix(es): * python: …
Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. Python supports interfaces to many system calls and libraries, as well as to various windowing systems. Security Fix(es): * python: …
Git Large File Storage (LFS) replaces large files such as audio samples, videos, datasets, and graphics with text pointers inside Git, while storing the file contents on a remote server. Security Fix(es): * net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME (CVE-2026-33811)…
The libsolv packages provide a library for resolving package dependencies using a satisfiability algorithm. Security Fix(es): * libsolv: Heap buffer overflow in libsolv repopagestore via unchecked decompression of malicious .solv page data (CVE-2026-48864) For more details about the security issue(s), incl…
The Common UNIX Printing System (CUPS) provides a portable printing layer for Linux, UNIX, and similar operating systems. Security Fix(es): * cups: OpenPrinting CUPS: Shared PostScript queue lets anonymous Print-Job requests reach `lp` code execution over the network (CVE-2026-34980) For more details about…
The libxml2 library is a development toolbox providing the implementation of various XML standards. Security Fix(es): * libxml2: Stack Buffer Overflow in xmllint Interactive Shell Command Handling (CVE-2025-6170) For more details about the security issue(s), including the impact, a CVSS score, acknowledgme…
A crafted virtual domain name injects additional lines into the generated exim configuration, allowing an authenticated user to redirect mail flow for other accounts.
Affected
DirectAdmin 1.678 and earlier
Patched
DirectAdmin 1.679
AlmaLinux 9 / CloudLinux 9
cd /usr/local/directadmin
echo 'action=update&value=current' >> data/task.queue
directadmin --reload
AlmaLinux 8 / CloudLinux 8
cd /usr/local/directadmin
echo 'action=update&value=current' >> data/task.queue
directadmin --reload
CentOS 7 / CloudLinux 7
cd /usr/local/directadmin
echo 'action=update&value=current' >> data/task.queue
directadmin --reload
Ubuntu 22.04 / Debian 12
cd /usr/local/directadmin
echo 'action=update&value=current' >> data/task.queue
directadmin --reload
Ubuntu 20.04 / Debian 11
cd /usr/local/directadmin
echo 'action=update&value=current' >> data/task.queue
directadmin --reload
Maven is a software project management and comprehension tool. Based on the concept of a project object model (POM), Maven can manage a project's build, reporting and documentation from a central piece of information. Security Fix(es): * org.codehaus.plexus:plexus-utils: Plexus-utils: Directory Traversal in …
Affected
3.9
X.Org is an open-source implementation of the X Window System. It provides the basic low-level functionality that full-fledged graphical user interfaces are designed upon. Security Fix(es): * xorg: X11: xserver: X.org: glamor Font Atlas Heap Buffer Overflow (CVE-2026-55999) For more details about the secur…
GhostLock (CVE-2026-43499) is a use-after-free bug in the Linux kernel's futex priority-inheritance code that lets any unprivileged local user become root. Its vulnerable range covers every kernel CloudLinux ships, so all supported versions are affected. There is no runtime mitigation; the fix is the patched kernel …
Bad epoll (CVE-2026-46242) is a use-after-free bug in the Linux kernel's epoll subsystem that lets an unprivileged local user escalate to root. It affects CloudLinux 9 and 10. Patched AlmaLinux kernels are in testing and a KernelCare livepatch is being prepared. Here's how to update. The post Bad epoll (CVE-2026-462…
cpsrvd accepted TLS handshakes that permit protocol downgrade, exposing the Webmail and WHM login sessions to man-in-the-middle interception on affected builds.
Affected
cPanel & WHM 120.0.8 and earlier
Patched
cPanel & WHM 120.0.12
AlmaLinux 9 / CloudLinux 9
dnf clean metadata
/scripts/upcp --force
AlmaLinux 8 / CloudLinux 8
dnf clean metadata
/scripts/upcp --force
CentOS 7 / CloudLinux 7
yum clean all
/scripts/upcp --force
The Plesk Backup Manager fails to sanitize archive paths, allowing a local attacker to read arbitrary files on the server via a crafted backup manifest.
Affected
Plesk Obsidian 18.0.58 and earlier
Patched
Plesk Obsidian 18.0.60
AlmaLinux 9 / CloudLinux 9
plesk installer update --select-product-id plesk
plesk sbin packagemng --update
AlmaLinux 8 / CloudLinux 8
plesk installer update --select-product-id plesk
CentOS 7 / CloudLinux 7
plesk installer update --select-product-id plesk
Ubuntu 22.04 / Debian 12
apt update
plesk installer update --select-product-id plesk
Ubuntu 20.04 / Debian 11
apt update
plesk installer update --select-product-id plesk
Under heavy connection churn, CSF may briefly drop an active port rule before the reload completes, exposing SSH briefly on default configurations.
Affected
CSF 14.20 and earlier
Patched
CSF 14.21
AlmaLinux 9 / CloudLinux 9
cd /etc/csf
csf -u
csf -r
AlmaLinux 8 / CloudLinux 8
cd /etc/csf
csf -u
csf -r
CentOS 7 / CloudLinux 7
cd /etc/csf
csf -u
csf -r
A race condition in CageFS mount setup can expose the host root filesystem to jailed users when a large number of concurrent logins trigger overlapping mount operations.
Affected
CageFS 7.4.1 and earlier
Patched
CageFS 7.4.3
CloudLinux 9
yum update cagefs
/usr/sbin/cagefsctl --force-update
CloudLinux 8
yum update cagefs
/usr/sbin/cagefsctl --force-update
CloudLinux 7
yum update cagefs
/usr/sbin/cagefsctl --force-update
The Mail Sending API allowed a reseller account to issue server-side requests to internal network endpoints, enabling internal port scanning and metadata access.
Affected
cPanel & WHM 120.0.3 and earlier
Patched
cPanel & WHM 120.0.6
AlmaLinux 9 / CloudLinux 9
dnf clean metadata
/scripts/upcp --force
AlmaLinux 8 / CloudLinux 8
dnf clean metadata
/scripts/upcp --force
CentOS 7 / CloudLinux 7
yum clean all
/scripts/upcp --force
Improper header validation on the HTTP/2 stream permits request smuggling against proxied backends, enabling cache poisoning on shared hosting configurations.
Affected
LiteSpeed Web Server 6.2.5 and earlier
Patched
LiteSpeed Web Server 6.2.6
AlmaLinux 9 / CloudLinux 9
dnf update lsws
/usr/local/lsws/bin/lshttpd -r
AlmaLinux 8 / CloudLinux 8
dnf update lsws
/usr/local/lsws/bin/lshttpd -r
CentOS 7 / CloudLinux 7
yum update lsws
/usr/local/lsws/bin/lshttpd -r
Pure-FTPd in DirectAdmin does not enforce login attempt limits when clients reuse the same data connection, allowing accelerated password brute-forcing.
Affected
DirectAdmin 1.671 and earlier
Patched
DirectAdmin 1.672
AlmaLinux 9 / CloudLinux 9
cd /usr/local/directadmin
echo 'action=update&value=current' >> data/task.queue
directadmin --reload
CentOS 7 / CloudLinux 7
cd /usr/local/directadmin
echo 'action=update&value=current' >> data/task.queue
directadmin --reload
Ubuntu 22.04 / Debian 12
cd /usr/local/directadmin
echo 'action=update&value=current' >> data/task.queue
directadmin --reload
A symlink placed inside the quarantine directory is followed by the cleanup job, allowing a compromised account to redirect removal operations to arbitrary files.
Affected
Imunify360 6.12 and earlier
Patched
Imunify360 6.13
AlmaLinux 9 / CloudLinux 9
yum update imunify360-antivirus
/usr/share/immuni360/imunify360-update
AlmaLinux 8 / CloudLinux 8
yum update imunify360-antivirus
/usr/share/immuni360/imunify360-update
CentOS 7 / CloudLinux 7
yum update imunify360-antivirus
/usr/share/immuni360/imunify360-update
Ubuntu 22.04
apt update
apt upgrade imunify360-antivirus
Ubuntu 20.04
apt update
apt upgrade imunify360-antivirus
Password reset tokens in WHMCS were generated with insufficient entropy, allowing brute-force recovery of the reset URL for administrator accounts.
Affected
WHMCS 8.9.0 and earlier
Patched
WHMCS 8.10.1
All Systems
Back up /var/www/html/whmcs
Download the patched release
Run the upgrade wizard at /install/upgrade
JetBackup offsite archives did not verify checksums after upload on interrupted transfers, leaving restore operations with silently corrupted backups.
Affected
JetBackup 5.3.10 and earlier
Patched
JetBackup 5.3.12
AlmaLinux 9 / CloudLinux 9
dnf update jetbackup
jetbackup5 --update
AlmaLinux 8 / CloudLinux 8
dnf update jetbackup
jetbackup5 --update
CentOS 7 / CloudLinux 7
yum update jetbackup
jetbackup5 --update
Ubuntu 22.04
apt update
apt upgrade jetbackup
Ubuntu 20.04
apt update
apt upgrade jetbackup
No advisory found for this selection.