Back to Security Advisories
Medium 2026-08-07

EasyApache 4 25.72 — cPanel & WHM Update

cPanel

Maintenance updates We released updated ea-modsec30, ea-modsec30-connector-apache24, and ea-modsec30-rules-owasp-crs packages for EasyApache 4. This maintenance release fixes ModSecurity audit logs silently failing to write across mod_ruid2 user IDs, forces a full Apache restart on package update so the updated libm…

Affected Versions

25.72

Maintenance updates We released updated ea-modsec30, ea-modsec30-connector-apache24, and ea-modsec30-rules-owasp-crs packages for EasyApache 4. This maintenance release fixes ModSecurity audit logs silently failing to write across mod_ruid2 user IDs, forces a full Apache restart on package update so the updated libm…

EasyApache 4 25.72

2026 July 14

Maintenance updates

We released updated ea-modsec30, ea-modsec30-connector-apache24, and ea-modsec30-rules-owasp-crs packages for EasyApache 4.

This maintenance release fixes ModSecurity audit logs silently failing to write across mod_ruid2 user IDs, forces a full Apache restart on package update so the updated libmodsecurity module loads, and updates OWASP CRS to 3.3.10 to fix the rule set not blocking attacks (anomaly scoring was not being applied).

For a full list of changes, read the EasyApache 4 change log.

How to Apply the Fix

Update the affected packages on your server to the patched release, then restart the relevant services.

sudo /scripts/upcp --force
More Information

Check your system for vulnerabilities

Select your product and operating system to see the exact fix commands that apply to you.

Check Your System