Sayfa
cPanel ve WHM Değişiklik Günlüğü
Latest Release
cPanel v138.0.1 · 2026-08-24
Release Notes by Version
Security updates, bug fixes, and improvements for every cPanel & WHM release.
138.0.1 · 2026-08-24
- [Security] Security hardening. Reverting to an earlier version removes these improvements.
- [Security] HTTP Basic authentication is no longer accepted on the cPanel interface (ports 2082 and 2083) by default. Use an API token for scripted calls, or re-enable the WHM Tweak Settings option “Allow HTTP Basic authentication to the cPanel interface”. In cpanel.config this is the reverse boolean skiphttpauth: skiphttpauth=0 accepts Basic authentication, skiphttpauth=1 refuses it. WHM, Webmail and Web Disk are unaffected.
- [Security] WebPros single sign-on now authenticates with PKCE instead of a client secret. Linked WebPros accounts must sign in to WebPros once more.
- Fixed CPANEL-52740: Prevent Sieve links from appearing as email folders.
- Fixed CPANEL-53496: Fixed a case where clearing the name service cache could cause a WHM API call to report a failure for an operation that had already succeeded.
- Fixed CPANEL-55077: Sync the system clock before regenerating default SSL certificates when preparing a server from a snapshot, to avoid certificates being stamped with an incorrect validity start date.
- Fixed CPANEL-55298: Report a WebPros Dashboard connection that was established before the WHM plugin shipped, instead of showing the server as not connected.
- Fixed CPANEL-55601: Apply expedited package security updates within the hour instead of waiting for the next daily update.
- Fixed CPANEL-55860: Fix the “Change Language” interface ignoring the “Change” button when clicked during page load.
- Fixed CPANEL-55886: Fix a failure to load libunbound on servers running an OpenSSL older than 3.4.
- Fixed CPANEL-55968: Fix the MariaDB repository baseurl after MariaDB removed the CentOS 8 path from archive.mariadb.org, and repair existing repository files that still point at it.
138.0.0 · 2026-07-27
- First build of 11.138.0.
- Fixed CPANEL-53942: Prevent Apple touch icon requests from being recorded as failed cPanel logins.
- Fixed CPANEL-54035: Fixed a bug where undoing the deletion of an email account left an address that could not be used or removed, and undoing the creation of one left its mailbox on disk or removed a mailbox it had not created. Fixed a bug where restoring a deleted email account recreated its mailbox with permissions that stopped it receiving mail.
- Fixed CPANEL-54681: Fix an intermittent failure enabling WebPros ID on new installs.
- Implemented CPANEL-55322: MCP access over the WebPros bearer path now requires the MCP Connection feature, so hosts can restrict MCP access per package.
- Implemented CPANEL-55323: Surface MCP key management in the WebPros Dashboard connection panel, and replace the WHM Plugins entry for connecting to the WebPros Dashboard with a connection widget in the WHM header.
- Fixed CPANEL-55546: Fixed a bug where supplying a port stopped the API from removing an SSH host key.
- Fixed CPANEL-55553: Fixed a bug where undoing a Web Disk password or permissions change could revert the other one.
- Fixed CPANEL-55566: Upgrade cpanel-perl to add plugin specific library path.
- Fixed CPANEL-55594: Prevent logger-free package operations from crashing on lock waits.
- Fixed CPANEL-55673: Update cpanel-pdns to 5.1.4 to fix CVE-2026-52682.
- Fixed CPANEL-55726: Update cpanel-clamav to 1.5.4, addressing CVE-2026-20337, CVE-2026-20338, CVE-2026-20339, CVE-2026-20345, CVE-2026-20346, CVE-2026-20347, CVE-2026-20348, and CVE-2025-8088.
- Fixed CPANEL-55735: Update cpanel-perl-542 to 5.42.0-6.cp130 to fix CVE-2026-15534.
- Fixed CPANEL-55786: Update Roundcube to 1.6.18, addressing the 2026-08-09 upstream Roundcube security advisory (CVE-2026-74997, CVE-2026-74998, and CVE-2026-75002).
- Fixed CPANEL-54035: Extended the API rollback framework to cover BoxTrapper, Mime, and Image Manager operations, and made a data-destroying undo opt-in.
- Fixed CPANEL-55256: Correct the UAPI documentation for Fileman::upload_files, which documented no parameters, no request body, and the wrong response.
- Fixed CPANEL-55498: Update cpanel-unbound to 1.26.0.
- Fixed CPANEL-54104: Prevent scoped session checks from retaining unknown service values.
- Fixed CPANEL-54269: Restore missing YUM repository variables during nightly maintenance so that the cpanel-plugins repository resolves correctly.
- Fixed CPANEL-54318: Upgrade Archive-Tar to 3.12 to address CVE-2026-42496 and CVE-2026-42497.
- Fixed CPANEL-54568: Add a WHM button that opens a connected server in the WebPros Dashboard.
- Fixed CPANEL-54917: Team users that have no roles are now reported when you create or edit them, and the UAPI Team::add_team_user function now rejects the "role" parameter in favor of "roles".
- Fixed CPANEL-47103: Updated ClamAV to 1.5.3, which serves the clamd socket from /run/clamav/clamd.sock.
- Fixed CPANEL-48643: Fix KVM detection for SeaBIOS VMs with custom system vendor.
- Fixed CPANEL-54035: Added an API-level backup and rollback framework for write operations (off by default).
- Fixed CPANEL-55239: Update cpanel-pdns to 5.1.3 to fix CVE-2026-33257 and CVE-2026-33260.
- Fixed CPANEL-55287: Display the daily cPanel update schedule correctly in Configure cPanel Cron Jobs.
- Fixed CPANEL-55373: Update cpanel-php84 to 8.4.24.
- Fixed CPANEL-55379: Stop logging a spurious "pre-auth floor clamped low" warning to the cPanel error log on servers using the default password hashing configuration.
- Fixed CPANEL-55380: Stop /scripts/upcp from resetting the SECURITY_UPDATES setting in /etc/cpupdate.conf back to hourly.
- Fixed CPANEL-55401: Improved server-side analytics event handling to align with account consent settings.
- Fixed DUCKS-5818: Add UAPI functions for parked, addon and subdomain management and for document root lookups.
- [Security] Various security issues were resolved in this release.
- [Security] Targeted Security Release
- Fixed CPANEL-36289: Fixed an issue where accounts could become stuck in a state where they could not be suspended or unsuspended due to inconsistent suspension detection between suspendacct and unsuspendacct.
- Fixed CPANEL-38968: Remove deprecated Ruby on Rails and RubyGems features from WHM Feature Manager and cPanel Jupiter UI.
- Fixed CPANEL-40337: Fix account transfers incorrectly writing the source server’s IP address into vhost files when the account’s main domain was renamed before the transfer.
- Fixed CPANEL-43104: Fix incorrect SPF term classification for include mechanisms whose domain ends with the letter ‘a’ or other mechanism keywords.
- Fixed CPANEL-43136: Fix Security Advisor to properly detect Imunify360, ImunifyAV, and ImunifyAV+ when market provider is disabled.
- Fixed CPANEL-43163: Make the Forwarders interface search both the Email Address and Forward To columns.
- Fixed CPANEL-44000: scripts/cpdig now will print DNS errors if encountered.
- Fixed CPANEL-45401: Remove remaining ICQ/OSCAR related code from the product.
- Fixed CPANEL-45602: Fix alignment of search result dropdown from header.
- Fixed CPANEL-45640: Improve set_service_proxy_backends API documentation with code samples for the optional general, service_group, and service_group_backend parameters.
- Fixed CPANEL-46159: Fix race condition that allowed a truncated Apache httpd.conf to be published during concurrent AutoSSL and userdata updates, taking all virtual hosts offline. Add pre-publication structural validation and structured log labels to identify which rebuild layer failed.
- Fixed CPANEL-46555: Fix SMTP restriction firewall rules on AlmaLinux 9 and CloudLinux 9 to use native nftables syntax, preventing nftables service failure on reboot.
- Fixed CPANEL-46970: Improved error messaging for package max_email_per_hour validation.
- Fixed CPANEL-48069: Allow PHP error logging directives (error_log, log_errors, error_log_mode) to be configured in MultiPHP INI Editor Basic Mode.
- Fixed CPANEL-48069: Automatically configure PHP error logging to ~/logs/php.error.log for all newly created domains.
- Fixed CPANEL-48147: Keep account details visible during WHM account removal confirmation.
- Fixed CPANEL-48464: Team manager now enforces the system-configured minimum password strength when creating or editing team users.
- Fixed CPANEL-49089: Switch the Ubuntu MariaDB package repository from the non-responsive dlm.mariadb.com mirror to archive.mariadb.org, and repair existing servers still configured to use it.
- Fixed CPANEL-49142: Fix a false 2FA-removed notice sent to Team Users when an unrelated email account is deleted.
- Fixed CPANEL-49208: Fixed /scripts/restorepkg –newuser restoring MySQL/MariaDB and PostgreSQL databases and database users with the previous account’s prefix, along with a related PostgreSQL rename failure that also affected the account-rename (mvacct) flow.
- Fixed CPANEL-49466: Issue AutoSSL certificates for the autoconfig proxy subdomain when autodiscover proxy subdomains are enabled.
- Fixed CPANEL-49595: Mailing Lists Manage button is now disabled with an explanatory tooltip when the Webmail feature is turned off, and attempting to access the login page directly shows a clear error instead of looping indefinitely.
- Fixed CPANEL-49647: Fixed a 500 error when a cPanel user with the “Limit logins to verified IP addresses” security policy authenticates via an API token.
- Fixed CPANEL-49684: Snapshot preparation now removes and regenerates the WebPros ID OpenID Connect configuration.
- Fixed CPANEL-49688: Change the configuration of Exim filters which use the “Fail With Message” action so that bounced messages which match the filter are discarded only when they originate from a remote server, and that local bounce messages are neither failed nor discarded.
- Fixed CPANEL-49826: Fix GPG key export passphrase detection on servers with non-English locales.
- Fixed CPANEL-49888: Fix redirect status for addon domains whose backing subdomain shares a document root with the main domain.
- Fixed CPANEL-49976: Set JAVA_HOME for the cpanel-dovecot-solr service on EL10 platforms where Java 11 is unavailable and a newer Java runtime is used instead.
- Fixed CPANEL-49979: Fix “Enable DMARC” checkbox becoming permanently locked when switching packages on WHM » Create a New Account. Fix the “zone template” link appearing on servers where no zone template defines a DMARC record. Fix zone template DMARC detection failing to read records from template files.
- Fixed CPANEL-50075: Fix false validation error for custom Exim routers that use redirect_router or pass_router referencing routers in the full config template.
- Fixed CPANEL-50134: Allow Team user password invitation to work when the API log is enabled.
- Fixed CPANEL-50301: Fix bug in Cpanel::RPM::Versions::Pkgr where children of the locker PID would destroy the lockfile out from under a parent on exit.
- Fixed CPANEL-50517: Extend phpMyAdmin import subprocess timeout to cover phpMyAdmin 5.x routing URLs so ZIP database imports are not killed by the default timeout.
- Fixed CPANEL-50532: Updated Trademarks pages to reflect WebPros International, L.L.C. ownership with improved layout and current third-party trademark attributions.
- Fixed CPANEL-50741: Fix WHM app search ranking so shorter app names no longer appear above longer ones when both match the search term equally.
- Fixed CPANEL-50744: Fixed manage disk usage in Roundcube with sieve scripts present.
- Fixed CPANEL-50812: Add WHM API 1 OpenAPI documentation for disable_mail_sni, enable_mail_sni, and rebuildinstalledssldb.
- Fixed CPANEL-50819: Add OpenAPI documentation for the Branding::include UAPI endpoint.
- Fixed CPANEL-50820: Add OpenAPI documentation for the DNS::fetch_cpanel_generated_domains UAPI endpoint.
- Fixed CPANEL-50822: Add OpenAPI documentation for the Market UAPI functions create_shopping_cart_non_ssl, get_build_cart_url, get_completion_url, get_license_info, and get_product_info.
- Fixed CPANEL-50844: Fix performance issue with granting cPanel support access in WHM on AlmaLinux 9.
- Fixed CPANEL-50845: Fix account backup failure when userdata directory contains subdirectories.
- Fixed CPANEL-50873: Fix HTML editor in File Manager to correctly render linked stylesheets and relative URLs when editing website pages.
- Fixed CPANEL-51089: Fix a crash in listaccts when hosting package files are invalid or corrupt.
- Fixed CPANEL-51267: Add a no_forward_outbound_spam_action setting in WHM Tweak Settings to choose whether forwarded spam is rejected with a bounce (fail) or silently dropped (blackhole/discard) to reduce backscatter.
- Fixed CPANEL-51513: Respect httpd_deferred_restart_time during bulk account removal to avoid redundant Apache PHP-FPM restarts.
- Fixed CPANEL-51591: Fix vacation autoresponse emails being bounced by providers like Gmail due to an empty envelope sender (-f <>) causing SPF/DKIM failures.
- Fixed CPANEL-51656: Fixed section navigation links in WHM View Mail Statistics Summary that failed to scroll to their target sections.
- Fixed CPANEL-51692: Prevent SSL certificates which advertise coverage for names which contain spaces from being expressed in the Dovecot configuration, something which breaks the service.
- Fixed CPANEL-51731: Fixed an issue where AutoSSL could not validate service domains that are subdomains of an account’s main domain, by adding wildcard DNS DCV as a fallback method.
- Fixed CPANEL-51788: Fix chkservd not reading mail service logs, which could cause Eximstats and Track Delivery to stop updating.
- Fixed CPANEL-51799: WHM pages for PFILE groups now always include the docs breadcrumb navigation element, even when a dedicated menu template is absent.
- Fixed CPANEL-51799: Fix docs-link in WHM when a group template file is missing.
- Fixed CPANEL-51880: Fix issue where SSL verification failure did not block reissue attempt for 200 day SSL certificates.
- Fixed CPANEL-51898: Implement “set_primary_domain_docroot” WHM API call to allow changing a user’s primary domain’s document root, and “SubDomain::changedocroot” UAPI call to allow changing all other domains’ document roots.
- Fixed CPANEL-51923: Reduce AutoSSL notification spam by sending a single digest email when multiple domains fail certificate renewal, instead of one email per domain.
- Fixed CPANEL-51999: Add a directory browser modal to the Application Manager registration form so users can select an application path by browsing their home directory instead of typing the path manually.
- Fixed CPANEL-52003: Fix spurious Failed to read PID smaps emails.
- Fixed CPANEL-52014: Don’t update securetmp unnecessarily in TweakSettings.
- Fixed CPANEL-52028: Show Hostname, Operating System, cPanel Version, and Load Averages in the WHM home Statistics card on mobile-sized viewports.
- Fixed CPANEL-52092: Add ability to rename primary, addon, and alias domains from the Domains interface in cPanel.
- Fixed CPANEL-52092: Add primary domain rename rollback guard, cross-filesystem mail migration safety, AutoSSL success log, promoted Cpanel::Park public API, happy-path addon rename coverage, plus three bug fixes from sandbox testing (primary rename auth context, parked-rename topdomain, lock-fh double-close warning).
- Fixed CPANEL-52110: Redesign the WHM Initial Setup Wizard’s Legal step as a single-column page that links to the current End User License Agreement, Technical Support Agreement, Pricing and Term Agreement, and Privacy Policy on cPanel.net, and persist acceptance to an audit record at /var/cpanel/activate/eula_acceptance.json capturing the accepting user, timestamp, remote IP, agreement version, and agreement URLs.
- Fixed CPANEL-52115: Hide the “Explore Account” option from the welcome modal starting point screen to reduce confusion for trial users.
- Fixed CPANEL-52129: Fix incorrect SQL quoting of column name in backup metadata database schema index definition.
- Fixed CPANEL-52132: Fix CPANEL-52132 - SwapIP will skip temp domains in DNS.
- Fixed CPANEL-52152: Setup MySQL yumrepos to use the 2025 GPG signing key, as that is not expired.
- Fixed CPANEL-52164: Fix uninitialized-value warnings in Cpanel::CachedDataStore when the datastore file disappears between stat calls during disk cache validation.
- Fixed CPANEL-52172: Update the list of Ubuntu 24.04 kernels which require additional packages in order to support disk quotas.
- Fixed CPANEL-52182: Bump rpm.versions for update to cpanel-geoipfree-data.
- Fixed CPANEL-52185: The MultiPHP Manager outdated PHP banner now includes a description explaining that outdated PHP versions no longer receive security updates and recommends PHP ELS. The More Info link is positioned inline with the description instead of pushed to the far right.
- Fixed CPANEL-52224: CPAN updates, addressing CVE-2026-4177, CVE-2006-10002, CVE-2006-10003.
- Fixed CPANEL-52244: Improve WHM frontend build performance by filtering minification targets to git-tracked files only.
- Fixed CPANEL-52282: Fix initial setup wizard crash when analytics system_id file is missing.
- Fixed CPANEL-52327: Fix Apache rebuild warnings and repeated survey prompts caused by root’s scoped userdata directory.
- Fixed CPANEL-52340: Update cpanel-roundcubemail to 1.6.15.
- Fixed CPANEL-52359: Fix “Use of uninitialized value in exit” warning in scripts/apachelimits.
- Fixed CPANEL-52361: Do not promote PHP ELS on servers that have an immunify360 license.
- Fixed CPANEL-52412: Fix “Apply DMARC Policy” so it no longer overwrites existing DMARC records, and ensure it uses the server’s configured default policy rather than the hardcoded fallback.
- Fixed CPANEL-52428: Fix cPanel MultiPHP Manager failing to display installed PHP versions with an out of date ea-cpanel-tools package.
- Fixed CPANEL-52430: Fix an error that could appear in the cPanel interface when the AutoSSL problems database is inaccessible.
- Fixed CPANEL-52440: Track AI App Builder tier usage in license reporting.
- Fixed CPANEL-52455: Fix SPF +include validation and prevent error alerts from disappearing on the Email Deliverability page.
- Fixed CPANEL-52466: Suppress PHP “Outdated” and “Secured” status labels on CloudLinux and Imunify360 servers where PHP packages are still hardened by the vendor.
- Fixed CPANEL-52502: Add flag for managing ssl controls in unified ssl interface.
- Fixed CPANEL-52514: Fix spurious “uninitialized value” warning in in-product survey new-user check when the related configuration keys are absent.
- Fixed CPANEL-52549: Fix issue with TLS wizard making unnecessary API calls.
- Fixed CPANEL-52565: Fix calendar-multiget href resolution when REPORT URL lacks trailing slash.
- Fixed CPANEL-52608: Fix PHP-FPM service management on CloudLinux to start, stop, restart, and monitor alt-php FPM services alongside EA4.
- Fixed CPANEL-52610: Update cpanel-php84 to 8.4.20.
- Fixed CPANEL-52623: Use atomic writes when creating the Exim virgin config and the repquota cache to prevent truncated files if the process is interrupted.
- Fixed CPANEL-52693: Fix PHP-FPM detection for alt-phpNN packages on Ubuntu so that PHP-FPM can be enabled via the WHM MultiPHP Manager interface and the WHMAPI1 php_set_vhost_versions call.
- Fixed CPANEL-52731: Fix the MultiPHP INI Editor to display the correct PHP version for domains that inherit the system default.
- Fixed CPANEL-52742: Restored accounts now preserve the “inherit” PHP version setting after the next update.
- Fixed CPANEL-52755: Fix Munin Apache graph not appearing after upgrade.
- Fixed CPANEL-52787: Fix issue where www was not automatically included with parent domain in Let’s Encrypt Certificate requests from TLS Wizard interface.
- Fixed CPANEL-52897: Add the ability to disable temporary domains via a server-wide configuration setting.
- Fixed CPANEL-52911: Fix webmail not redirecting to inbox when survey URL is missing from server configuration.
- Fixed CPANEL-52942: If cPanel attempts to upgrade to a later major version, ensure that it first upgrades to the most recent release of the current major version.
- Fixed CPANEL-52994: Prevent incorrect removal of TuxCare ELS PHP packages on servers licensed for Imunify360.
- Fixed CPANEL-53011: Update cpanel-exim to 4.99.2 Fixes: CVE-2026-40684, CVE-2026-40685, CVE-2026-40686, and CVE-2026-40687.
- Fixed CPANEL-53017: Include missing package names in update blocker message.
- Fixed CPANEL-53042: [BugFix] Fixed incorrect MySQL Tools Community repo baseurl for AlmaLinux 10 that caused 404 errors during MySQL 8.4 installation.
- Fixed CPANEL-53094: Fix domain rename rollback order, lock handling, UI refresh, banner accuracy, validation accuracy, localization, and accessibility.
- Fixed CPANEL-53131: Add directory browser to Passenger Application Manager.
- Fixed CPANEL-53139: Fixed an issue where the persistent template worker could silently lose its socket optimization after an unexpected exit, causing login page rendering to fall back to the slower fork path until the next service restart.
- Fixed CPANEL-53150: Improve accessibility of the Passenger Application Manager directory browser.
- Fixed CPANEL-53199: Update cpanel-php to 8.4.21. Fixes: CVE-2026-7263, CVE-2026-6735, CVE-2026-7259, CVE-2026-6104, CVE-2025-14179, CVE-2026-6722, CVE-2026-7261, CVE-2026-7262, CVE-2026-7568, and CVE-2026-7258.
- Fixed CPANEL-53200: Restoring accounts on PowerDNS servers no longer restarts the DNS server once per account, avoiding brief authoritative-DNS outages during bulk restores such as disaster recovery.
- Fixed CPANEL-53207: Stop logging spurious chmod and cache permission warnings, and avoid a fatal error, when reading scoped userdata files as a cPanel user.
- Fixed CPANEL-53233: Add the pre-installed [asis,WP Dashboard] WHM plugin for connecting a server to the [asis,WebPros] Dashboard.
- Fixed CPANEL-53234: Fix WHM inaccessibility caused by ELOOP errors from kmod-lve on CloudLinux 8 by handling the error gracefully.
- Fixed CPANEL-53257: Fix performance regressions in loading the main cPanel page.
- Fixed CPANEL-53305: Update cpanel-exim to 4.99.3 Security release addressing Exim-Security-2026-05-01.1 (CVE not yet assigned).
- Fixed CPANEL-53384: Update cpanel-perl-xml-libxml to 2.0213-3.cp130.
- Fixed CPANEL-53415: Fix issue where scoped sessions that are generated after login are considered valid for xfer to another service.
- Fixed CPANEL-53448: Update PowerDNS to version 4.9.14.
- Fixed CPANEL-53485: Update cpanel-unbound to 1.25.1 Fixes: CVE-2026-33278,CVE-2026-42944, CVE-2026-42959, CVE-2026-32792, CVE-2026-40622, CVE-2026-41292, CVE-2026-42534, CVE-2026-42923, CVE-2026-42960, CVE-2026-44390 and CVE-2026-44608.
- Fixed CPANEL-53489: Route Mixpanel analytics traffic through a configurable proxy URL that defaults to https://uat.webpros.com.
- Fixed CPANEL-53501: Fixed spurious uninitialized-value warnings when reading a directory.
- Fixed CPANEL-53504: Updated PowerDNS to v.5.0.5.
- Fixed CPANEL-53536: Validate MySQL database user credentials in unprivileged code instead of through a root-privileged admin call.
- Fixed CPANEL-53550: Update cpanel-roundcubemail to 1.6.16.
- Fixed CPANEL-53554: Renaming an addon or alias domain now migrates its custom DNS records and subdomains. Fixed Rename and Remove links missing on domains created in the same session without a page reload.
- Fixed CPANEL-53567: Fixed a bug where renaming an addon domain to match an already-renamed document root failed and removed the domain.
- Fixed CPANEL-53577: Fixed a bug where renaming a cPanel account’s primary domain (registered or temporary) failed with an internal error.
- Fixed CPANEL-53577: none (review fixes for unshipped-module rename fix).
- Fixed CPANEL-53601: Bump cpanel-perl-542-template-toolkit to 3.106-1.cp130 to resolve CVE-2026-5090.
- Fixed CPANEL-53666: Update cpanel-exim to 4.99.4. Contains fix for CVE-2026-48840.
- Fixed CPANEL-53672: Fix File Manager’s “Empty Trash” API1 action so it is correctly disabled for demo-mode accounts.
- Fixed CPANEL-53675: Block writes to NVData and Personalization UAPI in demo mode.
- Fixed CPANEL-53675: Block writes to NVData API2 set and setall in demo mode.
- Fixed CPANEL-53678: Add an x-readonly extension to the cPanel API OpenAPI specifications that identifies which operations are read-only.
- Fixed CPANEL-53684: Fixed infinite 2FA prompt loop when accessing cPanel accounts via WHM List Accounts with root 2FA enabled.
- Fixed CPANEL-53688: Fix login page showing legacy theme after account removal when the public contact directory has restrictive permissions.
- Fixed CPANEL-53688: Fixed an issue where the presence of a file at /var/cpanel/public_contact could cause the legacy login theme to appear instead of the configured default theme.
- Fixed CPANEL-53688: Fixed unset() and rename() to repair /var/cpanel/public_contact directory permissions when the directory already exists at wrong mode.
- Fixed CPANEL-53696: Fixed an intermittent cPHulk service startup failure under systemd.
- Fixed CPANEL-53708: Sanitize dest_principal path in _schedule_event_locally.
- Fixed CPANEL-53710: Validate cPHulk brute-force block-command arguments to prevent a reported account or address from being parsed as a command-line option.
- Fixed CPANEL-53711: Harden deprecated accesshash checks against leaking secret information via timing side-channel.
- Fixed CPANEL-53713: Harden cpsrvd session-scope enforcement so off-scope sessions fail closed.
- Fixed CPANEL-53791: Update PHP to 8.4.22.
- Fixed CPANEL-53893: Fixed a case where common mail providers such as Gmail could deliver duplicate inbound messages when the SMTP delay for unknown hosts was enabled.
- Fixed CPANEL-53904: Update the DBI module in cPanel Perl to 1.648 to address CVE-2026-9698.
- Fixed CPANEL-53945: Reverted the FPM-conversion change that preserved the “inherit” PHP version setting (CPANEL-52742).
- Fixed CPANEL-53964: Fixed a permission error that could break remote backups and cause login warnings by preventing fix_userdata_perms from removing the execute bit from userdata scope directories.
- Fixed CPANEL-53986: Fix Dynamic DNS updates, webmail access, and client IP logging returning 127.0.0.1 for requests forwarded by Apache or nginx over kept-alive backend connections.
- Fixed CPANEL-53994: Correct invalid default, example, and array schema values in the cPanel API OpenAPI specifications.
- Fixed CPANEL-54005,CPANEL-54088: Fix service proxy subdomain access on mod_ruid2 systems.
- Fixed CPANEL-54030: Add read_only UAPI tokens.
- Fixed CPANEL-54051: Add the x-readonly extension to the Domain rename_domain and LogManager error-log cPanel API OpenAPI specifications that identifies which operations are read-only.
- Fixed CPANEL-54135: Speed up the Jupiter Tools page for accounts with many SSL certificates.
- Fixed CPANEL-54157: Fixed the firewall failing to load on boot on AlmaLinux 10 and CloudLinux 10, caused by nftables.service being unable to reload cPanel’s saved ruleset.
- Fixed CPANEL-54223: Fixed an issue where the DAV UAPI calendar/contacts configuration call did not verify that the requesting user had access to the requested account.
- Fixed CPANEL-54224: Update cpanel-dovecot to 2.4.4-3.cp132 to fix an anvil process consuming 100% CPU after a configuration reload, and to rebuild the Dovecot configuration after package installation so the Pigeonhole sieve plugins stay in sync with the base package on upgrade.
- Fixed CPANEL-54234: Update cpanel-dovecot to 2.4.4. Fixes: CVE-2026-27851, CVE-2026-33603, CVE-2026-40020, and CVE-2026-42006.
- Fixed CPANEL-54239: Bump rpm.versions for cpanel-pdns to 5.0.6-1.cp138.
- Fixed CPANEL-54240: Bump rpm.versions for cpanel-pdns to 4.9.16-1.cp130.
- Fixed CPANEL-54329: Fix a race during upgrades that could leave Dovecot running with a stale, ABI-mismatched plugin configuration.
- Fixed CPANEL-54330: Fix a blank page in WHM’s Transfer Tool after scanning a remote server for account transfer.
- Fixed CPANEL-54365: Fix intermittent authentication failures during account transfer mail synchronization (MailSync).
- Fixed CPANEL-54376: Update cpanel-php84 to 8.4.23.
- Fixed CPANEL-54382: Add UAPI Fileman functions to move, copy, rename, delete, and trash or restore files and directories.
- Fixed CPANEL-54385: Fix an error that could occur when saving the selected language on the Change Language page.
- Fixed CPANEL-54397: Fixed an issue where Git Version Control’s Update from Remote could silently report a repository as up-to-date without checking the remote, when the repository was set up by pointing cPanel at an already-existing git clone. Also fixed related gaps where a dead remote could silently drop an unrelated repository rename, leak raw internal error output to the API caller, or cause a targeted branch-list request to return an empty list instead of an error.
- Fixed CPANEL-54423: Update cpanel-roundcubemail to 1.6.17 Fixes CVE-2026-54432 and CVE-2026-54433.
- Fixed CPANEL-54553: Automatically install the AI App Builder plugin when a server is licensed for it.
- Fixed CPANEL-54607: Add externally_as_user_json to run UAPI with params via STDIN.
- Fixed CPANEL-54912: Ensure every UAPI and WHM API OpenAPI operationId is unique within its specification.
- Fixed CPANEL-55009: Install the AI App Builder plugin immediately when a license refresh first grants the entitlement.
- Fixed CPANEL-55034: Fix OKF conformance for the DNS clustering security surface doc page.
- Fixed CPANEL-55040: Update rpm.versions for cpanel-unbound 1.25.2-1.cp132.
- Fixed CPANEL-55073: Bump rpm.versions for cpanel-geoipfree-data update.
- Fixed CPANEL-55120: Fix bug in setting up AI assistant link.
- Fixed CPANEL-55129: Prevent the domain-search redirect confirmation from being clipped into a nested scroll area on small screens.
- Fixed CPANEL-55141: Configure the WebPros External Authentication provider by default.
- Fixed CPANEL-55141: Fix WebPros ID configuration not being restored on instances cloned from a snapshot until the next upcp run.
- Fixed CPANEL-55166: Fix WebPros account linking dropping back to the login screen for cPanel users who reach cPanel through a registered/vanity domain.
- Fixed CPANEL-55167: Correct UAPI documentation for email account, CalDAV user, and User Manager password operations.
- Fixed DUCKS-5434: Fix feature-list rule validation for the default feature list to properly expand sparse entries and delegate to the shared validation module.
- Fixed DUCKS-5951: Fix UAPI DNS::ensure_domains_reside_only_locally returning false success on sandbox installs.
- Fixed DUCKS-6347: Add plugin-driven feature offers (Meridian theme and package extensions) to the WHM package form.
- Fixed DUCKS-6607: Require the MCP scopes on a WebPros bearer token used for UAPI.
- Fixed WPX-5311: Build i_cp_* locales from the WP Squared theme database on WP Squared servers.
- Fixed WPX-6297: Convert hardcoded product checks in domain and proxy configuration to use ProductConfig for better extensibility.
- Fixed WPX-7760: The get_user_email_forward_destination and set_user_email_forward_destination WHM API functions no longer require the Receive Mail role.
- Fixed WPX-8981: Fixed an issue where notification emails sent for WP Squared sites on temporary preview domains (*.wpsquared.site) had an undeliverable sender address. The system hostname is now used as the sender domain in that case.
- Fixed WPX-9699: PHP-FPM is now correctly enabled on “2 GB” cloud instances that report less than 2048 MB of RAM.
- Fixed WPX-9945: Fix SSL certificate handling during account recreation when the same domain’s certificate was still pending deletion.
- Fixed WPX-9998: Fix temporary domain creation failing when the system user owns the IP-based root domain.
- Fixed WPX-10014: Retry failed ImunifyAV and Imunify360 background installations with exponential backoff.
- Fixed WPX-10230: Fix AutoSSL problem reporting so that domains blocked before DCV (e.g., unresolvable domains) now appear in get_autossl_problems.
- Fixed WPX-10484,WPX-10485,WPX-10486: Fix spurious warnings during fresh installs related to TweakSettings post_action callbacks, DNS status code passthrough, and DKIM setup guard.
- Fixed WPX-10520: Fix cPanel configuration changes not being visible inside CageFS environments until a manual update.
- Fixed WPX-10809: Fix cpsrvd SSE task-log endpoint returning an empty response.
- Fixed WPX-10815: Fixed an issue where CloudLinux was reported as disabled on servers running the new CloudLinux Network client, which no longer provides the spacewalk-channel utility.
- Implemented CPANEL-47230: cPanel & WHM now uses HTTPS when syncing updates from a host that supports SSL.
- Implemented CPANEL-48721: Add KernelCare support for AlmaLinux 10.
- Implemented CPANEL-49309: Add domain name recommendations and purchase integration.
- Implemented CPANEL-50277: Add standalone Sitejet experience.
- Implemented CPANEL-51845: Enable cron for running bin/process_ssl_reissue and fix various issues exposed during testing of certificate reissuance.
- Implemented CPANEL-52298: Update SVCB API Specs for Existing Go Links.
- Implemented CPANEL-52538: Display the server’s IPv4 and IPv6 addresses in the Statistics section on the WHM home page.
- Implemented CPANEL-52713: Add the ability to set ‘description’ in WHM Plugin configuration.
- Implemented CPANEL-52929: Add panel_ini script for command-line panel.ini management.
- Implemented CPANEL-53164: Remove sqloptimizer entry from root’s crontab.
- Implemented CPANEL-53350: Add /scripts/is_update_available utility that exits 0 when a cPanel & WHM update is available for the configured tier.
- Implemented CPANEL-53412: Reduce the work the hourly security update check performs by skipping the TIERS.json signature download and verification when the file has not changed on the mirror.
- Implemented CPANEL-53412: WHM servers now apply current-major security releases within an hour by default, independent of the normal update schedule. Control this with the new Security Updates option in WHM Update Preferences or the SECURITY_UPDATES key in /etc/cpupdate.conf.
- Implemented CPANEL-53595: Remove cpaddons from the product.
- Implemented CPANEL-54190: Bump Net::ACME2 to 0.41 to fix LetsEncrypt Key.
- Implemented CPANEL-54259: Fix Server-Sent Events stream corruption caused by a handler error after the response headers were sent.
- Implemented CPANEL-54303: Add WebPros bearer JWT authentication for UAPI.
- Implemented CPANEL-54466: Provision the AI Assistant gateway token from the user’s WebPros sign-in.
- Implemented CPANEL-54566: cPanel now registers servers linked to a WebPros Account with the centralized Dashboard MCP service and authorizes MCP bearer tokens by the mcp:cpanel scope.
- Implemented CPANEL-54877: Ship compiled whm.openapi.json and cpanel.openapi.json API specification bundles.
- Implemented CPANEL-54935: Point the WP Dashboard connection at the current dashboard.webpros.com URLs.
- Implemented WPX-3635: Add UAPI functions to view and list PHP error logs.
- Implemented WPX-10242: Allow WP2 task-queue and backup binaries to call admin modules.
- [Security] Various security issues were resolved in this release.
136.0.36 · 2026-08-24
- [Security] Security hardening. Reverting to an earlier version removes these improvements.
- [Security] HTTP Basic authentication is no longer accepted on the cPanel interface (ports 2082 and 2083) by default. Use an API token for scripted calls, or re-enable the WHM Tweak Settings option “Allow HTTP Basic authentication to the cPanel interface”. In cpanel.config this is the reverse boolean skiphttpauth: skiphttpauth=0 accepts Basic authentication, skiphttpauth=1 refuses it. WHM, Webmail and Web Disk are unaffected.
- Fixed CPANEL-52740: Prevent Sieve links from appearing as email folders.
- Fixed CPANEL-53496: Fixed a case where clearing the name service cache could cause a WHM API call to report a failure for an operation that had already succeeded.
- Fixed CPANEL-55077: Sync the system clock before regenerating default SSL certificates when preparing a server from a snapshot, to avoid certificates being stamped with an incorrect validity start date.
- Fixed CPANEL-55594: Prevent logger-free package operations from crashing on lock waits.
- Fixed CPANEL-55601: Apply expedited package security updates within the hour instead of waiting for the next daily update.
- Fixed CPANEL-55886: Fix a failure to load libunbound on servers running an OpenSSL older than 3.4.
- Fixed CPANEL-55968: Fix the MariaDB repository baseurl after MariaDB removed the CentOS 8 path from archive.mariadb.org, and repair existing repository files that still point at it.
136.0.35 · 2026-08-17
- Fixed CPANEL-53942: Prevent Apple touch icon requests from being recorded as failed cPanel logins.
- Fixed CPANEL-54681: Fix an intermittent failure enabling WebPros ID on new installs.
- Fixed CPANEL-55566: Upgrade cpanel-perl to add plugin specific library path.
- Fixed CPANEL-55675: Update cpanel-pdns to 4.9.17 to fix CVE-2026-52682.
- Fixed CPANEL-55726: Update cpanel-clamav to 1.5.4, addressing CVE-2026-20337, CVE-2026-20338, CVE-2026-20339, CVE-2026-20345, CVE-2026-20346, CVE-2026-20347, CVE-2026-20348, and CVE-2025-8088.
- Fixed CPANEL-55735: Update cpanel-perl-542 to 5.42.0-6.cp130 to fix CVE-2026-15534.
- Fixed CPANEL-55786: Update Roundcube to 1.6.18, addressing the 2026-08-09 upstream Roundcube security advisory (CVE-2026-74997, CVE-2026-74998, and CVE-2026-75002).
136.0.33 · 2026-08-06
- Fixed CPANEL-48643: Fix KVM detection for SeaBIOS VMs with custom system vendor.
- Fixed CPANEL-54104: Prevent scoped session checks from retaining unknown service values.
- Fixed CPANEL-54269: Restore missing YUM repository variables during nightly maintenance so that the cpanel-plugins repository resolves correctly.
- Fixed CPANEL-54318: Upgrade Archive-Tar to 3.12 to address CVE-2026-42496 and CVE-2026-42497.
- Fixed CPANEL-54917: Team users that have no roles are now reported when you create or edit them, and the UAPI Team::add_team_user function now rejects the ‘role’ parameter in favor of ‘roles’.
- Fixed CPANEL-55040: Update rpm.versions for cpanel-unbound 1.25.2-1.cp132.
- Fixed CPANEL-55041: Update phpMyAdmin to 5.2.3.
- Fixed CPANEL-55287: Display the daily cPanel update schedule correctly in Configure cPanel Cron Jobs.
- Fixed CPANEL-55330: Remove the WP Dashboard plugin from cPanel & WHM v136.
- Fixed CPANEL-55373: Update cpanel-php84 to 8.4.24.
- Fixed CPANEL-55379: Stop logging a spurious “pre-auth floor clamped low” warning to the cPanel error log on servers using the default password hashing configuration.
- Fixed CPANEL-55380: Stop /scripts/upcp from resetting the SECURITY_UPDATES setting in /etc/cpupdate.conf back to hourly.
- Fixed CPANEL-55385: Reject IP ranges whose endpoints are not addresses.
- Fixed CPANEL-55498: Update cpanel-unbound to 1.26.0.
136.0.32 · 2026-07-29
- [Security] Targeted Security Release
136.0.31 · 2026-07-23
- Fixed CPANEL-49142: Fixed a false two-factor authentication removed notice sent to Team Users when an unrelated email account is deleted.
- Fixed CPANEL-49208: Fixed /scripts/restorepkg –newuser restoring MySQL/MariaDB and PostgreSQL databases and database users with the previous account’s prefix, along with a related PostgreSQL rename failure that also affected the account-rename (mvacct) flow.
- Fixed CPANEL-49976: Set JAVA_HOME for the cpanel-dovecot-solr service on EL10 platforms where Java 11 is unavailable and a newer Java runtime is used instead.
- Fixed CPANEL-50517: Extended the phpMyAdmin import subprocess timeout to cover phpMyAdmin 5.x routing URLs so ZIP database imports are not killed by the default timeout.
- Implemented CPANEL-53233: Added the pre-installed WP Dashboard WHM plugin for connecting a server to the WebPros Dashboard.
- Improved CPANEL-54190: Updated Net::ACME2 to 0.41 to fix a Let’s Encrypt key issue caused by disabling PKCS#1 v1.5 padding.
- Fixed CPANEL-54314: Fixed a permission error that could break remote backups and cause login warnings by preventing fix_userdata_perms from removing the execute bit from userdata scope directories.
- Fixed CPANEL-54365: Fixed intermittent authentication failures during account transfer mail synchronization (MailSync).
- Fixed CPANEL-54376: Updated cpanel-php84 to 8.4.23.
- Implemented CPANEL-54385: Fixed an error that could occur when saving the selected language on the Change Language page.
- Fixed CPANEL-54397: Fixed an issue where Git Version Control’s Update from Remote could silently report a repository as up-to-date without checking the remote, when the repository was set up by pointing cPanel at an already-existing git clone. Also fixed related gaps where a dead remote could silently drop an unrelated repository rename, leak raw internal error output to the API caller, or cause a targeted branch-list request to return an empty list instead of an error.
- Implemented CPANEL-54553: Automatically install the AI App Builder plugin when a server is licensed for it.
- Fixed CPANEL-54603: Updated cpanel-perl-542-yaml-syck to 1.47, fixing four memory-safety CVEs (CVE-2026-57075, CVE-2026-57076, CVE-2026-57077, CVE-2026-13713) in YAML parsing of untrusted input.
- Fixed CPANEL-54607: Added externally_as_user_json to run UAPI calls with parameters via STDIN.
- Fixed CPANEL-54912: Ensured every UAPI and WHM API OpenAPI operationId is unique within its specification.
- Improved CPANEL-54935: Updated the WP Dashboard connection to use the current dashboard.webpros.com URLs.
- Implemented CPANEL-55009: Install the AI App Builder plugin immediately when a license refresh first grants the entitlement.
136.0.29 · 2026-07-14
- [Security] Security Updates: CPANEL-52803, CPANEL-54228
- Fixed CPANEL-54417: Update cpanel-roundcubemail to 1.6.17. Fixes: CVE-2026-54432 and CVE-2026-54433.
136.0.28 · 2026-07-08
- [Security] Security Updates: CPANEL-47220, CPANEL-54227, CPANEL-54229
136.0.27 · 2026-07-02
- Fixed CPANEL-54330: Fix a blank page in WHM’s Transfer Tool after scanning a remote server for account transfer.
136.0.26 · 2026-07-01
- Fixed CPANEL-49466: Issue AutoSSL certificates for the autoconfig proxy subdomain when autodiscover proxy subdomains are enabled.
- Fixed CPANEL-49491: Cpanel/Logd.pm - Ignore ~/tmp/stats.conf when the administrator has not granted the user permission to configure their own web statistics software.
- Fixed CPANEL-49595: Mailing Lists Manage button is now disabled with an explanatory tooltip when the Webmail feature is turned off, and attempting to access the login page directly shows a clear error instead of looping indefinitely.
- Fixed CPANEL-49647: Fixed a 500 error when a cPanel user with the ‘Limit logins to verified IP addresses’ security policy authenticates via an API token.
- Fixed CPANEL-49826: Fix GPG key export passphrase detection on servers with non-English locales.
- Fixed CPANEL-49888: Fix redirect status for addon domains whose backing subdomain shares a document root with the main domain.
- Fixed CPANEL-53207: Stop logging spurious chmod and cache permission warnings, and avoid a fatal error, when reading scoped userdata files as a cPanel user.
- Fixed CPANEL-53696: Fixed an intermittent cPHulk service startup failure under systemd.
- Fixed CPANEL-54135: Speed up the Jupiter Tools page for accounts with many SSL certificates.
- Fixed CPANEL-54234: Update cpanel-dovecot to 2.4.4. Fixes: CVE-2026-27851, CVE-2026-33603, CVE-2026-40020, and CVE-2026-42006.
- Fixed CPANEL-54240: Bump rpm.versions for cpanel-pdns to 4.9.16-1.cp130.
136.0.25 · 2026-06-24
- Fixed CPANEL-53234: Fix WHM inaccessibility caused by ELOOP errors from kmod-lve on CloudLinux 8 by handling the error gracefully.
- Fixed CPANEL-53675: Block writes to NVData and Personalization UAPI in demo mode.
- Fixed CPANEL-53675: Block writes to NVData API2 set and setall in demo mode.
- Fixed CPANEL-53678: Add an x-readonly extension to the cPanel API OpenAPI specifications that identifies which operations are read-only.
- Fixed CPANEL-53688: Fix login page showing legacy theme after account removal when the public contact directory has restrictive permissions.
- Fixed CPANEL-53688: Fixed unset() and rename() to repair /var/cpanel/public_contact directory permissions when the directory already exists at wrong mode.
- Fixed CPANEL-53710: Validate cPHulk brute-force block-command arguments to prevent a reported account or address from being parsed as a command-line option.
- Fixed CPANEL-53712: Harden additional authentication checks against leaking secret information via timing side-channels.
- Fixed CPANEL-53713: Harden cpsrvd session-scope enforcement so off-scope sessions fail closed.
- Fixed CPANEL-53791: Update PHP to 8.4.22.
- Fixed CPANEL-54157: Fixed the firewall failing to load on boot on AlmaLinux 10 and CloudLinux 10, caused by nftables.service being unable to reload cPanel’s saved ruleset.
- Implemented CPANEL-51845: Enable cron for running bin/process_ssl_reissue and fix various issues exposed during testing of certificate reissuance.
- Implemented CPANEL-53412: Reduce the work the hourly security update check performs by skipping the TIERS.json signature download and verification when the file has not changed on the mirror.
- Implemented CPANEL-53412: WHM servers now apply current-major security releases within an hour by default, independent of the normal update schedule. Control this with the new Security Updates option in WHM Update Preferences or the SECURITY_UPDATES key in /etc/cpupdate.conf.
136.0.24 · 2026-06-18
- Fixed CPANEL-54005: Fix service proxy subdomain access on mod_ruid2 systems.
136.0.23 · 2026-06-12
- Fixed CPANEL-53901: Restore the WHM Apache Status page after upgrading to v136 by regenerating the Apache server status key during the update.
- Fixed CPANEL-53986: Restore the correct client IP address on proxied connections so that Dynamic DNS, webmail, and access logs no longer report 127.0.0.1.
136.0.22 · 2026-06-11
- Fixed CPANEL-52942: If cPanel attempts to upgrade to a later major version, ensure that it first upgrades to the most recent release of the current major version.
- Fixed CPANEL-53956: Fix proxy issues.
136.0.21 · 2026-06-11
- Fixed CPANEL-52132: Fixed an issue where changing the IP address of a cPanel account with a temporary domain did not update the DNS zones for the account’s domains.
- Fixed CPANEL-53691: Fixed extra 2FA prompt when entering a user’s cPanel via WHM.
- Fixed WPX-10809: Fixed an issue where the cpsrvd SSE task-log endpoint returned an empty response.
136.0.20 · 2026-06-10
- Fixed CPANEL-49089: Switch the Ubuntu MariaDB package repository from the non-responsive dlm.mariadb.com mirror to archive.mariadb.org, and repair affected servers.
- Fixed CPANEL-50075: Fix false validation error for custom Exim routers using redirect_router or pass_router.
- Fixed CPANEL-51880: Fix issue where SSL verification failure did not block reissue attempt for 200-day SSL certificates.
- Fixed CPANEL-52742: Restored accounts now preserve the “inherit” PHP version setting after the next update.
- Fixed CPANEL-53025: Add xfer_secure_ssl Tweak Setting to enforce SSL peer verification for WHM-to-WHM account transfers and remote access-hash retrieval.
- Fixed CPANEL-53200: Restoring accounts on PowerDNS servers no longer restarts the DNS server once per account, avoiding brief authoritative-DNS outages during bulk restores.
- Fixed CPANEL-53240: PHP ELS promotions now check the partner’s Manage2 Sales Option before displaying. Partners can suppress the promotion, redirect its purchase link to their own store, or keep the default cPanel Store link.
- Fixed CPANEL-53257: Fix performance regression in loading the main cPanel page.
- Fixed CPANEL-53501: Fixed spurious uninitialized-value warnings when reading a directory.
- Fixed CPANEL-53595: Remove cPAddons from the product.
- Fixed CPANEL-53580: Remove the obsolete cpaddons_report.pl cron entry left behind after cPAddons removal, which caused spurious nightly “No such file or directory” email alerts.
- Fixed CPANEL-53688: Fixed an issue where a file at /var/cpanel/public_contact could cause the legacy login theme to appear instead of the configured default theme.
- Fixed CPANEL-53893: Fixed a case where common mail providers such as Gmail could deliver duplicate inbound messages when the SMTP delay for unknown hosts was enabled.
- Fixed CPANEL-53904: Update the DBI module in cPanel Perl to 1.648. Addresses CVE-2026-9698.
136.0.19 · 2026-06-02
- Fixed CPANEL-53042: Fixed incorrect MySQL Tools Community repo baseurl for AlmaLinux 10 that caused 404 errors during MySQL 8.4 installation.
- Fixed CPANEL-53684: Resolved an issue where root accounts with 2FA enabled could enter an infinite authentication loop when accessing cPanel accounts. Note: a single 2FA verification prompt when logging into a cPanel account from WHM is expected and required.
136.0.18 · 2026-06-01
- Fixed CPANEL-53550: Update cpanel-roundcubemail to 1.6.16.
- Fixed CPANEL-53601: Bump cpanel-perl-542-template-toolkit to 3.106-1.cp130 to resolve CVE-2026-5090.
- Fixed CPANEL-53666: Update cpanel-exim to 4.99.4. Contains fix for CVE-2026-48840.
136.0.16 · 2026-05-28
- Fixed CPANEL-40337: Fix account transfers incorrectly writing the source server’s IP address into vhost files when the account’s main domain was renamed before the transfer.
- Fixed CPANEL-51898: Implement “set_primary_domain_docroot” WHM API call to allow changing a user’s primary domain’s document root, and “SubDomain::changedocroot” UAPI call to allow changing all other domains’ document roots.
- Fixed CPANEL-52608: Fix PHP-FPM service management on CloudLinux to start, stop, restart, and monitor alt-php FPM services alongside EA4.
- Fixed CPANEL-52693: Fix PHP-FPM detection for alt-phpNN packages on Ubuntu so that PHP-FPM can be enabled via the WHM MultiPHP Manager interface and the WHMAPI1 php_set_vhost_versions call.
- Fixed CPANEL-52994: Prevent incorrect removal of TuxCare ELS PHP packages on servers licensed for Imunify360.
- Fixed CPANEL-53131: Add directory browser to Passenger Application Manager.
- Fixed CPANEL-53140: Fixed an issue where the persistent template worker could silently lose its socket optimization after an unexpected exit, causing login page rendering to fall back to the slower fork path until the next service restart.
- Fixed CPANEL-53448: Update PowerDNS to version 4.9.14.
- Implemented CPANEL-53164: Remove sqloptimizer entry from root’s crontab.
136.0.14 · 2026-05-21
- Fixed CPANEL-53485: Update cpanel-unbound to 1.25.1. Fixes: CVE-2026-33278, CVE-2026-42944, CVE-2026-42959, CVE-2026-32792, CVE-2026-40622, CVE-2026-41292, CVE-2026-42534, CVE-2026-42923, CVE-2026-42960, CVE-2026-44390, and CVE-2026-44608.
136.0.13 · 2026-05-20
- [Security] Targeted Security Release
136.0.12 · 2026-05-14
- [Security] Targeted Security Release
136.0.10 · 2026-05-13
- [Security] Targeted Security Release
136.0.9 · 2026-05-08
- Fixed [Security]: An arbitrary file read was found in the feature::LOADFEATUREFILE adminbin call where it does not adequately validate the feature file name. A relative path may be passed as the argument to this call, causing an arbitrary file to be made world-readable. (CVE-2026-29201)
- Fixed [Security]: A Perl code injection method was found in the create_user API call, relating to the plugin parameter. (CVE-2026-29202)
- Fixed [Security]: An unsafe symlink handling error was found that allows a user to chmod an arbitrary file, allowing for denial of service and possible privilege escalation. (CVE-2026-29203)
136.0.7 · 2026-05-03
- Fixed CPANEL-53011: Update cpanel-exim to 4.99.2 Fixes: CVE-2026-40684, CVE-2026-40685, CVE-2026-40686, and CVE-2026-40687.
- Fixed CPANEL-53017: Include missing package names in update blocker message.
136.0.5 · 2026-04-28
- Fixed [Security] CPANEL-52908: Fix an issue with session loading and saving.
136.0.4 · 2026-04-23
- Fixed CPANEL-50812: Add WHM API 1 OpenAPI documentation for disable_mail_sni, enable_mail_sni, and rebuildinstalledssldb.
- Fixed CPANEL-50819: Add OpenAPI documentation for the Branding::include UAPI endpoint.
- Fixed CPANEL-50820: Add OpenAPI documentation for the DNS::fetch_cpanel_generated_domains UAPI endpoint.
- Fixed CPANEL-50822: Add OpenAPI documentation for the Market UAPI functions create_shopping_cart_non_ssl, get_build_cart_url, get_completion_url, get_license_info, and get_product_info.
- Fixed CPANEL-52003: Fix spurious Failed to read PID smaps emails.
- Fixed CPANEL-52014: Don’t update securetmp unnecessarily in TweakSettings.
- Fixed CPANEL-52152: Setup MySQL yumrepos to use the 2025 GPG signing key, as that is not expired.
- Fixed CPANEL-52172: Update the list of Ubuntu 24.04 kernels which require additional packages in order to support disk quotas.
- Fixed CPANEL-52440: Track AI App Builder tier usage in license reporting.
- Fixed CPANEL-52466: Suppress PHP “Outdated” and “Secured” status labels on CloudLinux and Imunify360 servers where PHP packages are still hardened by the vendor.
- Fixed CPANEL-52549: Fix issue with TLS wizard making unnecessary API calls.
- Fixed CPANEL-52610: Update cpanel-php84 to 8.4.20.
- Fixed CPANEL-52787: Fix issue where www was not automatically included with parent domain in Let’s Encrypt Certificate requests from TLS Wizard interface.
- Implemented CPANEL-48721: Add KernelCare support for AlmaLinux 10.
136.0.2 · 2026-04-14
- Fixed CPANEL-46159: Fix race condition that allowed a truncated Apache httpd.conf to be published during concurrent AutoSSL and userdata updates, taking all virtual hosts offline. Add pre-publication structural validation and structured log labels to identify which rebuild layer failed.
- Fixed CPANEL-49979: Fix “Enable DMARC” checkbox becoming permanently locked when switching packages on WHM » Create a New Account. Fix the “zone template” link appearing on servers where no zone template defines a DMARC record. Fix zone template DMARC detection failing to read records from template files.
- Fixed CPANEL-49988: Require the force DNS flag when root creates an account using a domain that is a subdomain of another user’s domain.
- Fixed CPANEL-51923: Reduce AutoSSL notification spam by sending a single digest email when multiple domains fail certificate renewal, instead of one email per domain.
- Fixed CPANEL-52502: Fix inability to manage excluded AutoSSL domains in the unified SSL interface.
- Fixed CPANEL-52514: Fix spurious “uninitialized value” warning in in-product survey new-user check.
136.0.1 · 2026-04-08
- Fixed CPANEL-51692: Prevent SSL certificates which advertise coverage for names which contain spaces from being expressed in the Dovecot configuration, something which breaks the service.
- Fixed CPANEL-52430: Fix an error that could appear in the cPanel interface when the AutoSSL problems database is inaccessible.
- Fixed CPANEL-52565: Fix calendar-multiget href resolution when REPORT URL lacks trailing slash.
136.0.0 · 2026-04-07
- Fixed CPANEL-38968: Remove deprecated Ruby on Rails and RubyGems features from WHM Feature Manager and cPanel Jupiter UI.
- Fixed CPANEL-39627: Allow configuring Dovecot to not provide SSL SNI support to service subdomains, in order to save against Dovecot memory limits when the number of domains served is very high.
- Fixed CPANEL-40311: New form field to specify region of S3-compatible backup destinations.
- Fixed CPANEL-43087: Removed use of cpanel side user cache files.
- Fixed CPANEL-43136: Fix Security Advisor to properly detect Imunify360, ImunifyAV, and ImunifyAV+ when market provider is disabled.
- Fixed CPANEL-43386: Transfer tool now automatically updates PHP handlers in .htaccess files to match the destination server’s available handlers, preventing PHP configuration issues after transfers.
- Fixed CPANEL-44000: scripts/cpdig now will print DNS errors if encountered.
- Fixed CPANEL-45395: Prevent Live Transfer from modifying custom A records that point to external servers.
- Fixed CPANEL-45401: Remove remaining ICQ/OSCAR related code from the product.
- Fixed CPANEL-46346: Reduce timeouts in DNS Cluster interface by extending peer timeouts from 7->15.
- Fixed CPANEL-46546: Fix Ticket Assist firewall detection when Imunify360 creates /etc/csf without installing the CSF binary.
- Fixed CPANEL-46581: Obfuscate the whm-server-status apache endpoint.
- Fixed CPANEL-46584: Harden MySQL upgrade process by setting locale to C defensively.
- Fixed CPANEL-46970: Improved error messaging for package max_email_per_hour validation.
- Fixed CPANEL-47033: Fix MariaDB 10.11+ startup error caused by attempting to load the non-existent auth_socket.so plugin.
- Fixed CPANEL-47555: MySQL and MariaDB upgrades now detect and automatically remove version locks when proceeding with the upgrade, preventing database service from being left in a non-functional state.
- Fixed CPANEL-48069: Automatically configure PHP error logging to ~/logs/php.error.log for all newly created domains.
- Fixed CPANEL-48069: Allow PHP error logging directives (error_log, log_errors, error_log_mode) to be configured in MultiPHP INI Editor Basic Mode.
- Fixed CPANEL-48418: Make stats program state/requirements clearer.
- Fixed CPANEL-48631: Exempt CalDAV/CardDAV from DoS protection.
- Fixed CPANEL-48930: Always force jailshell for jailed users crontabs.
- Fixed CPANEL-49084: AutoDomain xfer config update will ignore files over 1 MiB.
- Fixed CPANEL-49245: Stop stripping ‘defaults’ from fstab for disks which support usrjquota.
- Fixed CPANEL-49464: Remove custom Net::SSLeay fork in favor of upstream module.
- Fixed CPANEL-49681: Fix proxydomains CalDAV/CardDAV SRV records writing literal ‘%domain%’ placeholder instead of actual domain name to DNS zones.
- Fixed CPANEL-49693: Additional package prefixes now supported in easyapache UI.
- Fixed CPANEL-49983: Ensure that WHM-managed IPv4 addresses are added after NetworkManager finishes configuring the basic parameters on the interface.
- Fixed CPANEL-50064: Update the maintenance script to notify the admin of any long-running rpm/apt locks.
- Fixed CPANEL-50065: Block updates if the package manager is actively holding locks.
- Fixed CPANEL-50066: Label outdated and secured PHP versions in MultiPHP Manager and INI Editor.
- Fixed CPANEL-50129: Fix redirect issue for search results on the domains page.
- Fixed CPANEL-50133: Fix issue where new login sessions were not able to make changes to items created in previous sessions from phpMyAdmin.
- Fixed CPANEL-50134: Allow Team user password invitation to work when the API log is enabled.
- Fixed CPANEL-50191: Fix mails on maildir immediately going to cur/ on delivery instead of new/.
- Fixed CPANEL-50213: Fix maildirsize file not getting re-created if missing on IMAP login.
- Fixed CPANEL-50213: Set autoexpunge rules for mailboxes in the config blocks which initially set them up instead of later in IMAP/POP settings.
- Fixed CPANEL-50214: Various integration improvements to Jodit Editor.
- Fixed CPANEL-50245: Add unified SSL interface.
- Fixed CPANEL-50271: Fix ability to set Dovecot ssl.conf settings.
- Fixed CPANEL-50301: Fix bug in Cpanel::RPM::Versions::Pkgr where children of the locker PID would destroy the lockfile out from under a parent on exit.
- Fixed CPANEL-50385: Fix 404 errors when granting support access for forked tickets where SSH keys already exist from parent tickets.
- Fixed CPANEL-50422: Address additional net-snmp dependency issues not fixed for CPANEL-50161.
- Fixed CPANEL-50423: Prevent team sub-account members from accessing WHMCS integration endpoints to block a privilege escalation path to WHM root.
- Fixed CPANEL-50486: Deprecate Site Publisher, and recommend SiteJet instead.
- Fixed CPANEL-50497: Update cpanel-jodit-editor to 4.7.9-2.cp130.
- Fixed CPANEL-50532: Updated Trademarks pages to reflect WebPros International, L.L.C. ownership with improved layout and current third-party trademark attributions.
- Fixed CPANEL-50565,CPANEL-50567,CPANEL-50665: Add additional File Manager usage analytics.
- Fixed CPANEL-50575: Prevent the team users interface from being exploited to suspend or unsuspend arbitrary MySQL users.
- Fixed CPANEL-50592: Allow upgrades to Dovecot 2.4 to reset SNI and SSL include file local templates in addition to the main configuration file’s local template.
- Fixed CPANEL-50612: Fix typo in dovecot.conf template referring to cpdoveauth_domainownerd.sock.
- Fixed CPANEL-50614: Change default value for auth_allow_cleartext to yes to improve compatibility with existing client connections.
- Fixed CPANEL-50623: Re-build Munin so that munin-node can start when IPv6 is disabled.
- Fixed CPANEL-50673: Update ssl_minimum_protocol list for Dovecot 2.4.
- Fixed CPANEL-50686: Fix lua-socket for dovecot auth on 7->8 elevated systems.
- Fixed CPANEL-50695: Fix email archiving.
- Fixed CPANEL-50715: Fix bad auth proxying on mail node setups.
- Fixed CPANEL-50721: Address missing libmariadb.so on upgrade to 132.
- Fixed CPANEL-50725: Fix tailwatch’s AuthedMailIPTracker regexp for changes in strings emitted from Dovecot 2.4 (Login: -> Logged in:).
- Fixed CPANEL-50739: Update Roundcube to v1.6.12.
- Fixed CPANEL-50742: Allow the Task Queue system to load the POSIX interface Perl module freely again.
- Fixed CPANEL-50744: Fixed manage disk usage in Roundcube with sieve scripts present.
- Fixed CPANEL-50746: Adjust the default mail_path for virtual users to prevent permission denied errors before mail_path is overridden in userdb/passdb returns.
- Fixed CPANEL-50756: Update cpanel-exim to 4.99.1.
- Fixed CPANEL-50784: Fix request parsing fallback logic when integrations to dovecot don’t set a namespace in the auth request.
- Fixed CPANEL-50795: Update PHP to 8.4.16.
- Fixed CPANEL-50811: Add OpenAPI documentation for deprecated FeatureLists API methods.
- Fixed CPANEL-50838: Allow php*-php-common namespace.
- Fixed CPANEL-50845: Fix account backup failure when userdata directory contains subdirectories.
- Fixed CPANEL-50847: Update cpanel-mailman to 2.2.0.41-1.cp130.
- Fixed CPANEL-50852: Add some DumpFile variants to Cpanel::JSON.
- Fixed CPANEL-50872: Force dovecot quota recalculation when deleting emails via the webmail interface.
- Fixed CPANEL-50875: Fixed race condition viewing restore/transfer sessions.
- Fixed CPANEL-50903: Fix HTML Editor File Browse relative pathing.
- Fixed CPANEL-50911: Fix various issues in openapi specs.
- Fixed CPANEL-50919: Fix masterContainer’s data-app-key being set inconsistently in some mysql upgrade ‘stage’ pages.
- Fixed CPANEL-50935: The system now applies the Update DNS Zone setting when you use the Apply to Other Selected Accounts button in the Transfer Tool.
- Fixed CPANEL-50950: Add “Formbricks” survey widget to RoundCube via plugin.
- Fixed CPANEL-50957: Rename “Process Memory Limit: config” in Mailserver Config to “Process Memory Limit for Other Services”, and apply the setting to all internal Dovecot services not otherwise covered by another setting.
- Fixed CPANEL-50960: Teach cpkeyclt about the comet backup acitvation code.
- Fixed CPANEL-50967: Improve Jodit to support browsing subdirectories, and use relative links when inserting images via the filebrowser.
- Fixed CPANEL-50990: Add Annual survey notification.
- Fixed CPANEL-51016: Make the ‘Process Memory Limit: config (MB)’ setting in WHM » Mailserver Configuration apply to more Dovecot subprocesses/services.
- Fixed CPANEL-51020: Fix archive.* domains failing SMTP authentication in roundcube.
- Fixed CPANEL-51044: Fix config location for 999-cpanel-plugins.inc.php in cpanel-roundcubemail-plugins-cpanel package.
- Fixed CPANEL-51068: Address ‘Use of uninitialized value’ errors when saving TweakSettings.
- Fixed CPANEL-51074: Add support for File::Scan::ClamAV on U24.
- Fixed CPANEL-51092: Modify SpamAssassin to recognize different Exim behavior when using the “+all” log selector.
- Fixed CPANEL-51118: Fix “Oops” page displaying on MySQL roundcube.
- Fixed CPANEL-51163: Update PHP to 8.4.17.
- Fixed CPANEL-51255: Fix incorrect email disk usage calculations in Dovecot 2.4 where INBOX.INBOX folders and subaccount folders were incorrectly counted in quota.
- Fixed CPANEL-51274: Fix tool link issues on the Domains page.
- Fixed CPANEL-51335: Fix hook script output parsing when third-party hooks output JSON data before the result line.
- Fixed CPANEL-51346: Fixed Whostmgr::Quota::setusersquota() condition that confused 0 with unlimited.
- Fixed CPANEL-51488: Make EOL PHP/Hardened PHP clearer in EA4 UI output.
- Fixed CPANEL-51510: Update cpanel-roundcubemail to 1.6.13.
- Fixed CPANEL-51513: Respect httpd_deferred_restart_time during bulk account removal to avoid redundant Apache PHP-FPM restarts.
- Fixed CPANEL-51568: Add ARC signing to SRS forwarded SMTP messages.
- Fixed CPANEL-51576: Add WHM API function to report the count of domains using end-of-life PHP versions.
- Fixed CPANEL-51581: Update cpanel-php84 to 8.4.18.
- Fixed CPANEL-51591: Fix vacation autoresponse emails being bounced by providers like Gmail due to an empty envelope sender (-f <>) causing SPF/DKIM failures.
- Fixed CPANEL-51627: Re-add support for Dovecot to use custom Diffie-Hellman parameters file.
- Fixed CPANEL-51641: Display PHP outdated version warning in WHM List Accounts page when sites use end-of-life PHP versions.
- Fixed CPANEL-51652: Removes Site Publisher deprecation notices from cPanel tools page, and the notification UI in WHM and cPanel.
- Fixed CPANEL-51678: Fix FileManager upload popup incorrectly tracking anonymous Mixpanel events regardless of user analytics consent settings.
- Fixed CPANEL-51680: Use less alarming warning text for SSL certificates that are expiring soon but will be auto-renewed.
- Fixed CPANEL-51680: Fix false-alarm SSL expiry warnings for AutoSSL-managed domains.
- Fixed CPANEL-51763: Update cpanel-jodit-editor to 4.9.14-1.cp130.
- Fixed CPANEL-51765: PHP versions older than the system-configured minimum are now labeled “Outdated” instead of “Deprecated” in the MultiPHP Manager interface.
- Fixed CPANEL-51788: Fix chkservd not reading mail service logs, which could cause Eximstats and Track Delivery to stop updating.
- Fixed CPANEL-51833: Remove the Site Publisher link from the Domains additional resources panel.
- Fixed CPANEL-51917: Ugrade Net::CIDR to 0.27 to address CVE-2021-4456.
- Fixed CPANEL-51919: Upgrade Crypt::URandom for CVE-2026-2474.
- Fixed CPANEL-51921: Upgrade Compress::Raw::Zlib to address CVE-2026-3381.
- Fixed CPANEL-52006: Update PHP to 8.4.19.
- Fixed CPANEL-52028: Show Hostname, Operating System, cPanel Version, and Load Averages in the WHM home Statistics card on mobile-sized viewports.
- Fixed CPANEL-52097: Update cpanel-roundcubemail to 1.6.14.
- Fixed CPANEL-52164: Fix uninitialized-value warnings in Cpanel::CachedDataStore when the datastore file disappears between stat calls during disk cache validation.
- Fixed CPANEL-52185: The MultiPHP Manager outdated PHP banner now includes a description explaining that outdated PHP versions no longer receive security updates and recommends PHP ELS. The More Info link is positioned inline with the description instead of pushed to the far right.
- Fixed CPANEL-52196: Fixed XSS vulnerability when using /viewer/ routes.
- Fixed CPANEL-52224: CPAN updates, addressing CVE-2026-4177, CVE-2006-10002, CVE-2006-10003.
- Fixed CPANEL-52327: Fix Apache rebuild warnings and repeated survey prompts caused by root’s scoped userdata directory.
- Fixed CPANEL-52340: Update cpanel-roundcubemail to 1.6.15.
- Fixed CPANEL-52361: Do not promote PHP ELS on servers that have an immunify360 license.
- Fixed CPANEL-52412: Fix “Apply DMARC Policy” so it no longer overwrites existing DMARC records, and ensure it uses the server’s configured default policy rather than the hardcoded fallback.
- Fixed CPANEL-52428: Fix cPanel MultiPHP Manager failing to display installed PHP versions with an out of date ea-cpanel-tools package.
- Fixed DUCKS-4951: Fix 360 monitoring widget load failure on account creation page.
- Fixed DUCKS-4995: Improve required extension handling and warning messages in WHM package forms.
- Fixed DUCKS-5111: Add translations related to Nova for 8 languages.
- Fixed DUCKS-5434: Fix feature-list rule validation for the default feature list to properly expand sparse entries and delegate to the shared validation module.
- Fixed WPX-7724: Throttle AutoSSL failure notifications to at most once per 24 hours per vhost, notification type, and recipient.
- Fixed WPX-9299: Fix WordPress installation failing to redirect to Extendify when a concurrent WPTK task caused the install task to be deferred.
- Fixed WPX-9325: Skip the MailMan install task when disabled.
- Fixed WPX-9862: AutoSSL now emits a clear error when the configured provider module does not exist on the system.
- Fixed WPX-10026: Added the Stats::get_stats_daily UAPI method to retrieve daily AwStats data for a domain.
- Implemented CPANEL-47921: Added a new tweak setting to control web server log archive retention and a script to perform automated cleanup.
- Implemented CPANEL-47921: Added log retention controls to the Raw Access and Log Manager interfaces.
- Implemented CPANEL-47921: Added WHM API for managing web server log retention settings across accounts.
- Implemented CPANEL-47921: Added a WHM interface for managing web server log retention settings across cPanel accounts.
- Implemented CPANEL-48364: Allow third-party backup tools to restore domains on DNS-clustered servers via the force parameter.
- Implemented CPANEL-49391: Improve MIME header decoding in BoxTrapper by switching to the actively maintained CPAN Encode::MIME::Header module, which better handles malformed email headers.
- Implemented CPANEL-49394: Ubuntu 22 is no longer supported by cPanel.
- Implemented CPANEL-50070: Remove redundant server info rows from the WHM home Statistics sidebar and hide the sidebar when it has no content.
- Implemented CPANEL-50109: Add scripts to view and mass-change PHP versions across all domains.
- Implemented CPANEL-50258: Add option to log out of WebPros Account when logging out of cPanel, WHM, or Webmail.
- Implemented CPANEL-50441: Updated Security Advisor for CSF.
- Implemented CPANEL-50679: Remove libmariadb autofix logic from Sysup.
- Implemented CPANEL-50694: Set dovecot_storage_version to dovecot version for possible compatibility with changes dovecot may or may not have in the future.
- Implemented CPANEL-50759: Fix EasyApache4 wizard to correctly auto-select PHP extensions when installing ALT PHP versions from CloudLinux.
- Implemented CPANEL-50963: Enable Imunify support on A10/CL10.
- Implemented CPANEL-51137: Redesign PHP ELS installation progress indicator in MultiPHP Manager.
- Implemented CPANEL-51430: Add automatic reissuance of short-lived (200-day) SSL certificates via the cPanel Store API.
- Implemented CPANEL-51589: Let’s Encrypt certificates may be obtained from TLS wizard even if cPanel Store is disabled.
- Implemented CPANEL-51639: Change Security Advisor to suggest installing cPanel CSF using cleaner methods.
- Implemented CPANEL-51639: Display cPanel CSF in the WHM Manage Plugins interface.
- Implemented CPANEL-51959: Fix styling of the Cancel button in the outdated PHP version confirmation dialog on the WHM MultiPHP Manager page.
Loading…
Loading…
Loading…
Loading…
Loading…
Loading…
Loading…
Loading…
Loading…
Loading…
Source: cPanel & WHM Documentation