Back to Security Advisories

EasyApache 4 25.70 — cPanel & WHM Update

Security and maintenance updates We released updated packages for EasyApache 4. This security release updates PHP 8.2, 8.3, 8.4, and 8.5 to address CVE-2026-14355 (a memory corruption issue in openssl_encrypt with AES-WRAP-PAD) and, for PHP 8.3, CVE-2026-12184 (a TLS setup failure leading to remote DoS). It also upd…

High
cPanel

Affected Versions

25.70

Security and maintenance updates We released updated packages for EasyApache 4. This security release updates PHP 8.2, 8.3, 8.4, and 8.5 to address CVE-2026-14355 (a memory corruption issue in openssl_encrypt with AES-WRAP-PAD) and, for PHP 8.3, CVE-2026-12184 (a TLS setup failure leading to remote DoS). It also upd…

EasyApache 4 25.70

2026 July 8

Security and maintenance updates

We released updated packages for EasyApache 4.

This security release updates PHP 8.2, 8.3, 8.4, and 8.5 to address CVE-2026-14355 (a memory corruption issue in openssl_encrypt with AES-WRAP-PAD) and, for PHP 8.3, CVE-2026-12184 (a TLS setup failure leading to remote DoS). It also updates ea-libcurl to backport 13 CVEs from the curl 8.21.0 security advisory.

For a full list of changes, read the EasyApache 4 change log.

How to Apply the Fix

Update the affected packages on your server to the patched release, then restart the relevant services.

sudo /scripts/upcp --force

Check your system for vulnerabilities

Size uygun tam düzeltme komutlarını görmek için ürününüzü ve işletim sisteminizi seçin.

Check Your System