Back to Security Advisories
Critical 2026-08-07

EasyApache 4 25.65 — cPanel & WHM Update

cPanel

Security and maintenance updates We released updated packages for EasyApache 4. This security and maintenance release updates ea-apache24 to v2.4.68, which addresses thirteen CVEs in the Apache HTTP Server including two critical mod_http2 issues (CVE-2026-49975, CVE-2026-48913). It also updates the Passenger ecosyst…

Affected Versions

25.65

Security and maintenance updates We released updated packages for EasyApache 4. This security and maintenance release updates ea-apache24 to v2.4.68, which addresses thirteen CVEs in the Apache HTTP Server including two critical mod_http2 issues (CVE-2026-49975, CVE-2026-48913). It also updates the Passenger ecosyst…

EasyApache 4 25.65

2026 June 10

Security and maintenance updates

We released updated packages for EasyApache 4.

This security and maintenance release updates ea-apache24 to v2.4.68, which addresses thirteen CVEs in the Apache HTTP Server including two critical mod_http2 issues (CVE-2026-49975, CVE-2026-48913). It also updates the Passenger ecosystem (ea-passenger-src, ea-apache24-mod-passenger, ea-nginx-passenger, ea-ruby27-passenger) to v6.1.4, ea-apache24-mod-qos to v11.79, ea-php84 to v8.4.22, and ea-php85 to v8.5.7.

For a full list of changes, read the EasyApache 4 change log.

How to Apply the Fix

Update the affected packages on your server to the patched release, then restart the relevant services.

sudo /scripts/upcp --force
More Information

Check your system for vulnerabilities

Select your product and operating system to see the exact fix commands that apply to you.

Check Your System