Back to Security Advisories
High 2026-08-07

EasyApache 4 25.59 — cPanel & WHM Update

cPanel

Security and maintenance updates We released updated packages for EasyApache 4. This security release addresses CVE-2026-43515 and CVE-2026-43512 (Moderate) and five Low-severity CVEs in ea-tomcat101 (v10.1.54 to v10.1.55), and includes a heap buffer overflow fix in ea-apache24-mod_security2 (no CVE assigned) along …

Affected Versions

25.59

Security and maintenance updates We released updated packages for EasyApache 4. This security release addresses CVE-2026-43515 and CVE-2026-43512 (Moderate) and five Low-severity CVEs in ea-tomcat101 (v10.1.54 to v10.1.55), and includes a heap buffer overflow fix in ea-apache24-mod_security2 (no CVE assigned) along …

EasyApache 4 25.59

2026 May 13

Security and maintenance updates

We released updated packages for EasyApache 4.

This security release addresses CVE-2026-43515 and CVE-2026-43512 (Moderate) and five Low-severity CVEs in ea-tomcat101 (v10.1.54 to v10.1.55), and includes a heap buffer overflow fix in ea-apache24-mod_security2 (no CVE assigned) along with updates to ea-valkey72, ea-redis62, ea-nginx-njs, ea-wappspector, and ea-apache24-mod_lsapi.

For a full list of changes, read the EasyApache 4 change log.

How to Apply the Fix

Update the affected packages on your server to the patched release, then restart the relevant services.

sudo /scripts/upcp --force
More Information

Check your system for vulnerabilities

Select your product and operating system to see the exact fix commands that apply to you.

Check Your System