cPanel Security Releases
2026, Dated.
Each cPanel & WHM security fix this year that has a published CVE record: the date, what it fixed, its score, and the build that fixes it. Sourced to the CVE record and cPanel's advisories.
Published October 1, 2026 · Last updated October 6, 2026
By Ace-Host, Southfield, Michigan: hosting on our own network (AS22878) since 2003
What this list is
One row per date on which CVE records for cPanel & WHM, or for software cPanel ships with it, were published in 2026. Dates are the CVE record's publication date. cPanel's own advisory can come a day earlier: CVE-2026-41940's advisory is dated April 28, its record April 29. Scores are as published on the record, with the CVSS version named, because the records do not all use the same one. A row is added when its CVE record is published, not before.
The list
| Published | What it fixed, score, fixed builds |
|---|---|
| April 29 CVE-2026-41940 | Authentication bypass in the login flow: no login needed to get into the control panel. CVSS 4.0 9.3, Critical. On CISA's Known Exploited Vulnerabilities catalog since April 30. Fixed in 11.134.0.20, 11.136.0.5, WP Squared 11.136.1.7, and older branches listed in the advisory. |
| May 8 CVE-2026-29201 CVE-2026-29202 CVE-2026-29203 | Three fixes: an arbitrary file read through a relative path (CVSS 3.1 8.6, High); Perl code run as the logged-in account's own system user (CVSS 4.0 5.3, Medium; CVSS 3.1 8.8, High); and a chmod in the Nova plugin that follows symlinks, setting root permissions on arbitrary files (CVSS 4.0 5.3, Medium; CVSS 3.1 8.8, High). Fixed in 11.134.0.25, 11.136.0.9, and older branches listed in the advisories. |
| May 13 CVE-2026-29205 CVE-2026-29206 CVE-2026-32991 CVE-2026-32992 CVE-2026-32993 | Five fixes: an arbitrary file read through cpdavd's attachment download endpoints, no login needed (CVSS 3.1 8.6, High); SQL injection in the sqloptimizer script when slow query logging is on (CVSS 3.1 8.1, High); a team member raising their own privileges to the team owner's account (CVSS 3.1 7.1, High); SSL verification turned off in DNS clustering, so a server in the middle could capture credentials (CVSS 3.1 8.2, High); and HTTP header injection through the nova_error endpoint, no login needed (CVSS 3.1 8.3, High). Fixed in 11.134.0.26, 11.136.0.10, WP Squared 11.136.1.12, and older branches listed in the records. |
| May 20 CVE-2026-33278 | Unbound, the DNS resolver cPanel ships as cpanel-unbound: a DNSSEC validation bug that can lead to denial of service or remote code execution. CVSS 4.0 9.1, Critical (scored by NLnet Labs). Fixed in Unbound 1.25.1, shipped by cPanel as cpanel-unbound 1.25.1. |
| September 1 CVE-2026-65643 | Eval injection: an authenticated user can run code as root. CVSS 4.0 8.7, High. Fixed in 11.110.0.141, 11.134.0.53, 11.136.0.37, 11.138.0.2, WP Squared 11.138.1.7. |
| September 9 CVE-2026-67401 | SQL injection in EmailTrack: an account with mail can run code as root. CVSS 3.0 9.9, Critical. Fixed in 11.110.0.143, 11.134.0.55, 11.136.0.39, 11.138.0.4, WP Squared 11.138.1.9. |
| September 19 CVE-2026-94054 CVE-2026-94055 CVE-2026-94056 CVE-2026-94057 | Exim, the mail server cPanel ships: four fixes in Exim 4.100.1. With Proxy-Protocol and an attacker-controlled proxy, an out-of-bounds write (CVSS 3.1 7.0, High) and a read of uninitialized stack memory (CVSS 3.1 7.5, High); with certain non-default GnuTLS TLS settings, a use-after-free (CVSS 3.1 3.7, Low); and SMTP smuggling, where the message received does not match any message sent (CVSS 3.1 4.0, Medium). Fixed in 11.110.0.147, 11.134.0.59, 11.136.0.43 and 11.138.0.10, released September 23, which update the bundled Exim to 4.100.1. |
| September 23 CVE-2026-87899 CVE-2026-68490 CVE-2026-87900 | A cPanel account can run code as root through CalDAV/CardDAV (CVSS 4.0 9.4, Critical); local users can read other accounts' calendars and contacts (CVSS 4.0 8.2, High); and argument injection in WP Toolkit lets a logged-in user run code across customer accounts (CVSS 4.0 9.4, Critical). Fixed in 11.134.0.57, 11.136.0.41, 11.138.0.8, and WP Toolkit 6.11.3-10850. Our article on these three. |
Exploitation is marked only where we confirmed it: CVE-2026-41940 is on CISA's catalog. For the others, check CISA's catalog yourself; an unmarked row means we have not confirmed it either way.
Is your server past all of them?
Each fix is "this build or later", so a server on or above the highest number for its branch in the list is past every row for that branch: 11.110.0.147, 11.134.0.59, 11.136.0.43 or 11.138.0.10. 11.110 has no number in the September 23 row because those records list it as not affected; their ranges start at 11.120. Any other branch has no fix in the September rows; the fix is to move up to a branch that has one. To read your build, log in as root over SSH:
cat /usr/local/cpanel/version
To update, run cPanel's documented update command as root, then read the version again:
/usr/local/cpanel/scripts/upcp --force
cat /usr/local/cpanel/version
WP Toolkit and cpanel-unbound carry their own version numbers, so the cPanel build does not tell you whether they are fixed. Check them against the rows above.
On our shared or reseller hosting you won't have root, so these checks aren't yours to run. To ask which build your server is on, log in and open a ticket. A system administrator will answer, 24/7/365.
Leaving cPanel does not end patching: every server needs updates, with a panel or without one. It does end the cPanel license. If that trade interests you, here is what moving off cPanel involves.
Sources
- CVE records for CVE-2026-41940, CVE-2026-29201, CVE-2026-29202, CVE-2026-29203, CVE-2026-33278, CVE-2026-65643, CVE-2026-67401, CVE-2026-87899, CVE-2026-68490 and CVE-2026-87900: dates, descriptions, scores and fixed versions. Fetched October 1, 2026. Records for CVE-2026-94054 through CVE-2026-94057 fetched October 5, 2026. Records for CVE-2026-29205, CVE-2026-29206 and CVE-2026-32991 through CVE-2026-32993 fetched October 6, 2026.
- Exim, Exim 4.100.1 security release (September 18, 2026). Fetched October 5, 2026.
- cPanel change logs for 110, 134, 136 and 138: the September 23 builds that update Exim to 4.100.1. Fetched October 5, 2026.
- Canadian Centre for Cyber Security, AV26-404 (April 28, 2026), AV26-437 (May 8, 2026) and AV26-499 (May 22, 2026), which link cPanel's advisories, including the April 28 advisory date and the cpanel-unbound 1.25.1 release. Fetched October 1, 2026.
- cPanel, cPanel & WHM Security Update 04-28-2026 and CVE-2026-33278 cpanel-unbound 1.25.1 Security Release. Not fetched; cited by the Cyber Centre advisories.
- cPanel, How do I update cPanel/WHM? Fetched September 29, 2026.