Back to Security Advisories
Critical 2026-08-07

EasyApache 4 25.63 — cPanel & WHM Update

cPanel

Hotfix security release We released updated packages for EasyApache 4. This release addresses CVE-2026-9256 (nginx-poolslip), a critical remote code execution vulnerability affecting all nginx versions, fixed in ea-nginx 1.31.1. Phusion Passenger was also updated to version 6.1.3. For a full list of changes, read th…

Affected Versions

25.63

Hotfix security release We released updated packages for EasyApache 4. This release addresses CVE-2026-9256 (nginx-poolslip), a critical remote code execution vulnerability affecting all nginx versions, fixed in ea-nginx 1.31.1. Phusion Passenger was also updated to version 6.1.3. For a full list of changes, read th…

EasyApache 4 25.63

2026 May 22

Hotfix security release

We released updated packages for EasyApache 4. This release addresses CVE-2026-9256 (nginx-poolslip), a critical remote code execution vulnerability affecting all nginx versions, fixed in ea-nginx 1.31.1. Phusion Passenger was also updated to version 6.1.3.

For a full list of changes, read the EasyApache 4 change log.

How to Apply the Fix

Update the affected packages on your server to the patched release, then restart the relevant services.

sudo /scripts/upcp --force
More Information

Check your system for vulnerabilities

Select your product and operating system to see the exact fix commands that apply to you.

Check Your System