News & changelogs
Vendor release notes, CVEs that matter, and what we ship to support them.
8 articles in this category
Articles in news & changelogs
5 min
RtabRace (CVE-2026-68138): mitigating the kernel race on CloudLinux
A traffic-control race in the Linux kernel lets any shell user panic a shared server on demand. CloudLinux 8 and 7 Hybrid need the sysctl mitigation today — here's the command and the patch status.
2026-08-18
7 min
CVE-2026-33278: the cpanel-unbound DNSSEC RCE, and how to check for it
A critical Unbound DNSSEC validator bug shipped as cpanel-unbound puts remote code execution one malicious signed zone away, no login required. Patched builds and how to check exposure.
2026-08-17
7 min
Blesta 6.0 Paradigm: what's new and the upgrade checklist
Blesta 6.0 ships a Bootstrap 5 admin rebuild called Paradigm, an optional AI layer, real-time notifications, and a revenue analytics dashboard. Here's what changes and how to upgrade without breaking custom extensions.
2026-08-13
5 min
EasyApache 4 25.69: cPanel patches six Tomcat CVEs in ea-tomcat101
EasyApache 4 25.69 ships Apache Tomcat 10.1.56 in ea-tomcat101, closing six CVEs — an auth-bypass on default servlet constraints among them. Here's what's fixed and how to update.
2026-07-31
6 min
Plesk Obsidian 18.0.79: what's new and why to upgrade now
Plesk Obsidian 18.0.79 opens the REST API to resellers and customers, adds SQL Server 2025 support and an AlmaLinux 8-to-9 upgrade script, and ships a security-audit-driven hardening pass.
2026-07-30
7 min
CVE-2026-41940: the cPanel & WHM auth bypass, and how to check for it
A CRLF injection in cpsrvd session handling let unauthenticated attackers write user=root into their own session file. Patched versions, IOCs, and how to check if you were hit.
2026-07-23
3 min
cPanel & WHM v136: unified SSL, log retention, removals
cPanel & WHM v136 hits the RELEASE tier — unified SSL/TLS, short-lived ACME certs, web log retention, mass PHP version changes, Dovecot 2.4, and a list of removals to audit first.
2026-05-31
3 min
NGINX Rift (CVE-2026-42945) — what hosting operators need to do
An 18-year-old heap overflow in NGINX's rewrite module — CVSS 9.2, unauthenticated, exploitable from the internet. Here's the patched versions, the config workaround, and how it affects Plesk and cPanel stacks.
2026-05-15