Güvenlik Danışarlıklarına Dön

Security: EasyApache4 v25.62 Security Release – May 21, 2026

Security vulnerabilities tied to ea-nginx-njs(CVE-2026-8711) and ea-memcached16(CVE-2026-47783, CVE-2026-47784) have been discovered.

High 8.1 CVSS
CloudLinux cPanel

Varsayılan Güncelleme Komutu

WHM → EasyApache 4 → Update, or: yum update 'ea-*'

SharedLicense lisansı altında bunun anlamı

Your SharedLicense license itself is not affected — this is a vulnerability in CloudLinux, cPanel software, not in licensing. Licenses continue to work during and after the update; there is no need to re-issue or re-activate anything. If you resell CloudLinux, cPanel under your own brand, patch client servers too — unpatched installs put your reputation at risk, not your license.

Situation

Security vulnerabilities tied to ea-nginx-njs(CVE-2026-8711) and ea-memcached16(CVE-2026-47783, CVE-2026-47784) have been discovered.

Impact

We are releasing a security update for EasyApache4 (v25.62) to update ea-nginx-njs to v0.9.9 and ea-memcached16 to v1.6.42 to address these vulnerabilities.

Note: Please see the latest EasyApache4 changelogs for version information:
https://docs.cpanel.net/changelogs/easyapache-4-change-log-25/ 

Call to Action

You can confirm if these packages are installed and updated to the new versions with the following commands:

CloudLinux / AlmaLinux

# dnf list installed ea-nginx-njs
# dnf list installed ea-memcached16

If they are installed, but are not updated, you can use the following command to proceed with that update:

# dnf update

Ubuntu

# apt policy ea-niginx-njs
# apt policy ea-memcached16

If they are installed, there will be a specified version in the “Installed” field, as shown below:

CONFIG_TEXT: # apt policy ea-nginx-njs
ea-nginx-njs:
Installed: 0.9.8-2+4.1.cpanel
Candidate: 0.9.8-2+4.1.cpanel

If the Candidate field is greater then the Installed field you have an update pending as shown here:

CONFIG_TEXT: # apt policy ea-memcached16
ea-memcached16:
Installed: 1.6.39-1+2.1.cpanel
Candidate: 1.6.41-1+4.1.cpanel

If the Installed field shows “(none)” the package is not installed.

If they are installed, but have not updated, you can use the following command to perform the update and upgrade:

# apt update && apt upgrade

Sıkça Sorulan Sorular

What is CVE-2026-8711?
NGINX JavaScript has a vulnerability when the js_fetch_proxy directive is configured with at least one client-controlled NGINX variable (for example, $http_*, $arg_*, $cookie_*) and a location invoking the ngx.fetch() operation from NGINX JavaScript. An unauthenticated attacker can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Is CVE-2026-8711 being exploited in the wild?
No confirmed exploitation is recorded. The EPSS model estimates a 9.69% probability of exploitation within the next 30 days — patch on your normal schedule.
How do I fix CVE-2026-8711?
Update CloudLinux, cPanel to the patched release.Then confirm the running version matches the patched release listed above.
Why does this advisory list several CVEs?
One vendor release fixed multiple vulnerabilities. This advisory covers CVE-2026-8711, CVE-2026-47783, CVE-2026-47784 — updating to the patched release resolves all of them at once.

Sisteminizi güvenlik açıkları açısından kontrol edin

Size uygun tam düzeltme komutlarını görmek için ürününüzü ve işletim sisteminizi seçin.

Sisteminizi Kontrol Edin