Panellicense

cPanel & WHM v136: unified SSL, log retention, removals

cPanel & WHM v136 hits the RELEASE tier — unified SSL/TLS, short-lived ACME certs, web log retention, mass PHP version changes, Dovecot 2.4, and a list of removals to audit first.

cPAll cPanel articlesNews & changelogs3 min readUpdated 2026-05-31
release-notessslphpdovecotdeprecations
schema: TechArticleschema: FAQPageschema: BreadcrumbList

cPanel & WHM v136 is now on the production RELEASE tier, current build 136.0.14 (21 May 2026). v138 is on EDGE for testing. This cycle is light on new UI and heavy on cleaning up the parts of day-to-day administration that waste time — certificates, logs, and PHP version sprawl — plus a handful of removals you need to audit before you push the upgrade.

What's worth upgrading for

  • Unified SSL/TLS interface — certificate install, view, and renewal land in one screen instead of being scattered across WHM. If you manage SSL across dozens of accounts this is the headline change.
  • Short-lived ACME certificates — support for ~200-day certs that auto-reissue via the ACME protocol and the cPanel Store API. This is where the industry is heading; pair it with a clean AutoSSL setup so renewals never lapse. If yours don't renew, see AutoSSL DCV failures.
  • Web log retention — new WHM scripts and interfaces to set how long web-server log archives are kept, with automated cleanup. This is the supported fix for the "/ is full of logs" cron hacks most hosts carry.
  • Mass PHP version management — view and bulk-change PHP across every domain from one tool, with automatic error logging on new domains. Useful alongside adding a PHP build in EasyApache 4.
  • WP Toolkit security risk assessment — per-site and per-component risk scoring.

Stack bumps

Componentv136
Dovecot2.4 (major bump, new config options)
PHP8.4.16–8.4.20
MariaDB11.8 offered in the upgrade workflow
Roundcube1.6.15

The MySQL/MariaDB upgrade now auto-detects and removes version locks that used to block it.

Removals — audit before you upgrade

Don't ignore the security cadence

2026 has been a heavy patch year: multiple emergency Technical Security Releases (TSRs), including an actively exploited authentication-bypass zero-day, plus May CVEs spanning every branch from 11.86 to 11.136. v136 itself bundles fixes across cpanel-unbound, cpanel-exim, and several CPAN modules. The build within v136 changes often as patches ship — stay current and check your version against the changelog:

/usr/local/cpanel/cpanel -V

For most servers the answer is upgrade: v136 is on RELEASE, the security fixes are not optional this year, and the SSL, logging, and PHP work removes real friction. Just clear the removals first. If the 2026 pricing has you reconsidering the panel entirely, weigh the tier math before you commit — and a current cPanel license keeps you on the patched RELEASE builds.

What is the latest cPanel version in 2026?+
v136 is the current RELEASE-tier production version, with build 136.0.14 dated 21 May 2026. v138 is available on the EDGE tier for testing.
Does cPanel v136 still support Ubuntu 22?+
No. Ubuntu 22 support is discontinued in v136. Plan an OS move to a supported AlmaLinux, Rocky, Ubuntu 24.04, or Debian release before upgrading hosts that still run it.
What happened to Ruby on Rails in cPanel v136?+
Ruby on Rails and RubyGems were removed from the WHM Feature Manager. There's no in-place replacement — audit accounts that depend on Ruby apps before upgrading.
How do I check which cPanel build I'm running?+
Run /usr/local/cpanel/cpanel -V on the server and compare the result against the official changelog. The exact build inside v136 changes frequently as security patches land.

Next steps

how to
Change a cPanel WHM hostname without breaking license, mail, or SSL
A clean WHM hostname change takes 15 minutes if you do it in order. The mistakes that cost an afternoon — broken services SSL, license re-checks, mail HELO mismatches, and rDNS — all in one playbook.
8 min read
how to
Add a new PHP version in EasyApache 4 without breaking sites
Add a PHP build in EasyApache 4, pick extensions, assign per-domain handlers, and recover when the Review stage stalls or rolls back.
4 min read
troubleshoot
Fix WHM AutoSSL failures — a decision tree
AutoSSL fails in five distinct ways. Identify which one you're hitting from the WHM log line, then apply the fix — DNS, HTTP-01, CAA, rate-limit, or DCV redirect.
5 min read
changelog
Blesta 6.0 Paradigm: what's new and the upgrade checklist
Blesta 6.0 ships a Bootstrap 5 admin rebuild called Paradigm, an optional AI layer, real-time notifications, and a revenue analytics dashboard. Here's what changes and how to upgrade without breaking custom extensions.
7 min read
changelog
Plesk Obsidian 18.0.79: what's new and why to upgrade now
Plesk Obsidian 18.0.79 opens the REST API to resellers and customers, adds SQL Server 2025 support and an AlmaLinux 8-to-9 upgrade script, and ships a security-audit-driven hardening pass.
6 min read
how to
CloudLinux Hardened PHP: legacy PHP without the CVE risk
Backported security fixes for PHP 5.6 through 8.1 let you keep legacy WordPress and Magento customers running on the version their plugins actually need, without the CVE backlog.
8 min read
Switch in an afternoon

Switch from your current reseller — free.

We migrate active cPanel, Plesk, LiteSpeed and CloudLinux licenses from any reseller. We prorate the first month so you never pay twice, and your customers see zero downtime during the swap.