We would like to inform you that cPanel has released important security updates addressing multiple vulnerabilities affecting several cPanel & WHM versions. Administrators are strongly advised to review their current version and apply the latest patched release immediately to ensure server security and stability.

The following vulnerabilities have been addressed:

  • CVE-2026-32993

  • CVE-2026-32992

  • CVE-2026-32991

  • CVE-2026-29206

  • CVE-2026-29205

The fixes are included in the following cPanel & WHM versions and later:

  • 11.86.0.44+

  • 11.94.0.31+

  • 11.102.0.42+

  • 11.110.0.118 (cl6110)

  • 11.110.0.119+

  • 11.118.0.67+

  • 11.124.0.38+

  • 11.126.0.59+

  • 11.130.0.23+

  • 11.132.0.32+

  • 11.134.0.26+

  • 11.136.0.10+

For WP Squared, the security patch is available in:

  • 11.136.1.12+

To manually update your server, you may use the following commands:

chattr -ia /etc/cpupdate.conf /usr/local/cpanel/version
rm -f /usr/local/cpanel/logs/license_log; touch /usr/local/cpanel/cpanel.lisc

VERSION=11.136.0.10
sed -i "s/^CPANEL=.*/CPANEL=$VERSION/g" /etc/cpupdate.conf

echo "$VERSION" > /usr/local/cpanel/version
/scripts/upcp --force

Please ensure that you replace the VERSION value with the appropriate patched release matching your update tier before running the commands.

We highly recommend applying these updates as soon as possible to mitigate potential security risks and keep your systems protected.



Thursday, May 14, 2026

« Back