Back to Security Advisories
Critical 2026-08-13

EasyApache 4 25.77

cPanel

Maintenance and Security Release We released updated packages for EasyApache 4. This release resolves three PHP vulnerabilities across ea-php82, ea-php83, ea-php84, and ea-php85: a libgd vulnerability (CVE-2026-9672), a SQL injection via backslash breakout in PGSQL (CVE-2026-17543), and a crash via recursive symlink…

Affected Versions

25.77

Maintenance and Security Release We released updated packages for EasyApache 4. This release resolves three PHP vulnerabilities across ea-php82, ea-php83, ea-php84, and ea-php85: a libgd vulnerability (CVE-2026-9672), a SQL injection via backslash breakout in PGSQL (CVE-2026-17543), and a crash via recursive symlink…

EasyApache 4 25.77

2026 August 5

Maintenance and Security Release

We released updated packages for EasyApache 4.

This release resolves three PHP vulnerabilities across ea-php82, ea-php83, ea-php84, and ea-php85: a libgd vulnerability (CVE-2026-9672), a SQL injection via backslash breakout in PGSQL (CVE-2026-17543), and a crash via recursive symlinks in Phar archives (CVE-2026-7260). ea-php84 and ea-php85 also resolve an out-of-bounds write in bccomp() (CVE-2026-17544). ea-nodejs22 updates to v22.23.2, an upstream Security Release resolving ten CVEs. This release also includes a config rebuild performance fix for ea-nginx and an update to ea-nghttp2 (v1.70.0).

For a full list of changes, read the EasyApache 4 change log.

How to Apply the Fix

Update the affected packages on your server to the patched release, then restart the relevant services.

sudo /scripts/upcp --force
More Information

Check your system for vulnerabilities

Size uygun tam düzeltme komutlarını görmek için ürününüzü ve işletim sisteminizi seçin.

Check Your System