Panellicense

cPanel & WHM v136: unified SSL, log retention, removals

cPanel & WHM v136 hits the RELEASE tier — unified SSL/TLS, short-lived ACME certs, web log retention, mass PHP version changes, Dovecot 2.4, and a list of removals to audit first.

3 min readUpdated 2026-05-31release-notes · ssl · php · dovecot
schema: TechArticleschema: FAQPageschema: BreadcrumbList

cPanel & WHM v136 is now on the production RELEASE tier, current build 136.0.14 (21 May 2026). v138 is on EDGE for testing. This cycle is light on new UI and heavy on cleaning up the parts of day-to-day administration that waste time — certificates, logs, and PHP version sprawl — plus a handful of removals you need to audit before you push the upgrade.

What's worth upgrading for

  • Unified SSL/TLS interface — certificate install, view, and renewal land in one screen instead of being scattered across WHM. If you manage SSL across dozens of accounts this is the headline change.
  • Short-lived ACME certificates — support for ~200-day certs that auto-reissue via the ACME protocol and the cPanel Store API. This is where the industry is heading; pair it with a clean AutoSSL setup so renewals never lapse. If yours don't renew, see AutoSSL DCV failures.
  • Web log retention — new WHM scripts and interfaces to set how long web-server log archives are kept, with automated cleanup. This is the supported fix for the "/ is full of logs" cron hacks most hosts carry.
  • Mass PHP version management — view and bulk-change PHP across every domain from one tool, with automatic error logging on new domains. Useful alongside adding a PHP build in EasyApache 4.
  • WP Toolkit security risk assessment — per-site and per-component risk scoring.

Stack bumps

Componentv136
Dovecot2.4 (major bump, new config options)
PHP8.4.16–8.4.20
MariaDB11.8 offered in the upgrade workflow
Roundcube1.6.15

The MySQL/MariaDB upgrade now auto-detects and removes version locks that used to block it.

Removals — audit before you upgrade

Don't ignore the security cadence

2026 has been a heavy patch year: multiple emergency Technical Security Releases (TSRs), including an actively exploited authentication-bypass zero-day, plus May CVEs spanning every branch from 11.86 to 11.136. v136 itself bundles fixes across cpanel-unbound, cpanel-exim, and several CPAN modules. The build within v136 changes often as patches ship — stay current and check your version against the changelog:

/usr/local/cpanel/cpanel -V

For most servers the answer is upgrade: v136 is on RELEASE, the security fixes are not optional this year, and the SSL, logging, and PHP work removes real friction. Just clear the removals first. If the 2026 pricing has you reconsidering the panel entirely, weigh the tier math before you commit — and a current cPanel license keeps you on the patched RELEASE builds.

What is the latest cPanel version in 2026?+
v136 is the current RELEASE-tier production version, with build 136.0.14 dated 21 May 2026. v138 is available on the EDGE tier for testing.
Does cPanel v136 still support Ubuntu 22?+
No. Ubuntu 22 support is discontinued in v136. Plan an OS move to a supported AlmaLinux, Rocky, Ubuntu 24.04, or Debian release before upgrading hosts that still run it.
What happened to Ruby on Rails in cPanel v136?+
Ruby on Rails and RubyGems were removed from the WHM Feature Manager. There's no in-place replacement — audit accounts that depend on Ruby apps before upgrading.
How do I check which cPanel build I'm running?+
Run /usr/local/cpanel/cpanel -V on the server and compare the result against the official changelog. The exact build inside v136 changes frequently as security patches land.

Next steps

Switch in an afternoon

Switch from your current reseller — free.

We migrate active cPanel, Plesk, LiteSpeed and CloudLinux licenses from any reseller. We prorate the first month so you never pay twice, and your customers see zero downtime during the swap.