News & changelogs
Vendor release notes, CVEs that matter, and what we ship to support them.
19 articles in this category
Articles in news & changelogs
5 min
JetBackup 5.4.2 release notes: Object Lock wizard and DR fixes
JetBackup 5.4.2 ships an Immutable Backups Wizard for S3 Object Lock, destination duplication, and fixes for cPanel v136 restore warnings and Bare Metal Recovery ordering.
2026-09-16
7 min
CVE-2026-67401: the cPanel EmailTrack flaw that turns mail access into root
A SQL injection in cPanel's EmailTrack feature lets any account with mail privileges write files as root. Fixed builds, affected versions, and how to check your fleet.
2026-09-15
5 min
EasyApache 4 25.82: cPanel patches ea-libxml2, ea-nginx, ea-ruby27-ruby
EasyApache 4 build 25.82 patches eight libxml2 CVEs, two Ruby resolv CVEs, and bumps ea-nginx to 1.31.5. Here's what's affected and how to update.
2026-09-13
4 min
CVE-2026-84761: the LiteSpeed Cache for WordPress SSRF fix
An unauthenticated SSRF in LiteSpeed Cache for WordPress below v7.9.1 hits sites behind QUIC.cloud with client-IP restoration off. Patch and exposure check.
2026-09-11
5 min
bridge-stp-uaf (CVE-2026-72389): the CloudLinux kernel advisory
A use-after-free in the kernel bridge STP timer code lets a local user who can configure a network bridge become root. CloudLinux 7h and 8 need the modprobe mitigation now.
2026-09-11
4 min
Plesk CVE-2026-68487 and 68488: patch Backup Manager now
Two critical Plesk Backup Manager flaws let an authenticated customer or reseller write root-owned files and take over the server. Hotfixes ship in 18.0.79.11 and 18.0.80.7.
2026-09-10
4 min
cPanel TSR-2026-09-08: prepare for the critical WHM patch
cPanel pre-announced a Targeted Security Release for 8 September 2026 fixing a critical cPanel & WHM vulnerability. Here is how to identify affected servers and apply the fix.
2026-09-08
4 min
CSF security update: patch cpanel-csf 16.30-1 and older
cPanel is shipping a ConfigServer Firewall security release on 3 September 2026 covering flaws rated up to Critical. Servers on cpanel-csf 16.30-1 or older need it.
2026-09-03
3 min
CVE-2026-67394: patch the Plesk root privilege-escalation flaw
CVE-2026-67394 can let a Plesk customer or reseller with shell access gain root control of a Linux server. Update to 18.0.79.9, 18.0.80.5, or later.
2026-08-27
3 min
CVE-2026-65643: patch the cPanel domain parking root vulnerability
CVE-2026-65643 lets an authenticated cPanel user with parked or addon-domain access create arbitrary server files and potentially execute code as root. Check the fixed builds and update now.
2026-08-27
3 min
Plesk CVE-2026-65646, 65642, and 65647: patch your server
Three critical Plesk flaws expose server files, customer databases, and root access. Check the affected builds and update Plesk plus both extensions.
2026-08-25
5 min
RtabRace (CVE-2026-68138): mitigating the kernel race on CloudLinux
A traffic-control race in the Linux kernel lets any shell user panic a shared server on demand. CloudLinux 8 and 7 Hybrid need the sysctl mitigation today — here's the command and the patch status.
2026-08-18
7 min
CVE-2026-33278: the cpanel-unbound DNSSEC RCE, and how to check for it
A critical Unbound DNSSEC validator bug shipped as cpanel-unbound puts remote code execution one malicious signed zone away, no login required. Patched builds and how to check exposure.
2026-08-17
7 min
Blesta 6.0 Paradigm: what's new and the upgrade checklist
Blesta 6.0 ships a Bootstrap 5 admin rebuild called Paradigm, an optional AI layer, real-time notifications, and a revenue analytics dashboard. Here's what changes and how to upgrade without breaking custom extensions.
2026-08-13
5 min
EasyApache 4 25.69: cPanel patches six Tomcat CVEs in ea-tomcat101
EasyApache 4 25.69 ships Apache Tomcat 10.1.56 in ea-tomcat101, closing six CVEs — an auth-bypass on default servlet constraints among them. Here's what's fixed and how to update.
2026-07-31
6 min
Plesk Obsidian 18.0.79: what's new and why to upgrade now
Plesk Obsidian 18.0.79 opens the REST API to resellers and customers, adds SQL Server 2025 support and an AlmaLinux 8-to-9 upgrade script, and ships a security-audit-driven hardening pass.
2026-07-30
7 min
CVE-2026-41940: the cPanel & WHM auth bypass, and how to check for it
A CRLF injection in cpsrvd session handling let unauthenticated attackers write user=root into their own session file. Patched versions, IOCs, and how to check if you were hit.
2026-07-23
3 min
cPanel & WHM v136: unified SSL, log retention, removals
cPanel & WHM v136 hits the RELEASE tier — unified SSL/TLS, short-lived ACME certs, web log retention, mass PHP version changes, Dovecot 2.4, and a list of removals to audit first.
2026-05-31
3 min
NGINX Rift (CVE-2026-42945) — what hosting operators need to do
An 18-year-old heap overflow in NGINX's rewrite module — CVSS 9.2, unauthenticated, exploitable from the internet. Here's the patched versions, the config workaround, and how it affects Plesk and cPanel stacks.
2026-05-15