cPanel & WHM v136 is now on the production RELEASE tier, current build 136.0.14 (21 May 2026). v138 is on EDGE for testing. This cycle is light on new UI and heavy on cleaning up the parts of day-to-day administration that waste time — certificates, logs, and PHP version sprawl — plus a handful of removals you need to audit before you push the upgrade.
What's worth upgrading for
- Unified SSL/TLS interface — certificate install, view, and renewal land in one screen instead of being scattered across WHM. If you manage SSL across dozens of accounts this is the headline change.
- Short-lived ACME certificates — support for ~200-day certs that auto-reissue via the ACME protocol and the cPanel Store API. This is where the industry is heading; pair it with a clean AutoSSL setup so renewals never lapse. If yours don't renew, see AutoSSL DCV failures.
- Web log retention — new WHM scripts and interfaces to set how long web-server log archives are kept, with automated cleanup. This is the supported fix for the "/ is full of logs" cron hacks most hosts carry.
- Mass PHP version management — view and bulk-change PHP across every domain from one tool, with automatic error logging on new domains. Useful alongside adding a PHP build in EasyApache 4.
- WP Toolkit security risk assessment — per-site and per-component risk scoring.
Stack bumps
| Component | v136 |
|---|---|
| Dovecot | 2.4 (major bump, new config options) |
| PHP | 8.4.16–8.4.20 |
| MariaDB | 11.8 offered in the upgrade workflow |
| Roundcube | 1.6.15 |
The MySQL/MariaDB upgrade now auto-detects and removes version locks that used to block it.
Removals — audit before you upgrade
Don't ignore the security cadence
2026 has been a heavy patch year: multiple emergency Technical Security Releases (TSRs),
including an actively exploited authentication-bypass zero-day, plus May CVEs spanning every
branch from 11.86 to 11.136. v136 itself bundles fixes across cpanel-unbound,
cpanel-exim, and several CPAN modules. The build within v136 changes often as patches
ship — stay current and check your version against the changelog:
/usr/local/cpanel/cpanel -V
For most servers the answer is upgrade: v136 is on RELEASE, the security fixes are not optional this year, and the SSL, logging, and PHP work removes real friction. Just clear the removals first. If the 2026 pricing has you reconsidering the panel entirely, weigh the tier math before you commit — and a current cPanel license keeps you on the patched RELEASE builds.