A security update for cPanel & WHM is now available. This update resolved multiple vulnerabilities across supported versions of cPanel & WHM, including the following, rated up to High severity.
Our team have patched all managed services and servers, un-managed server customers please read below..
CVE-2026-58047 - issue affecting cpsrvd functionality
CVE-2026-58048 - issue affecting database functionality
GCVE-25-2026-07-45-3 issue affecting Exim mail functionality
The update also includes additional security hardening improvements for certain supported operating system configurations.
Please follow the instructions in the linked support article and update cPanel to one of the patched versions listed below.
Patched versions:
11.110.0.137
11.126.0.78
11.134.0.48
11.136.0.32
11.138.1.6 (WP2)
Key Resources:
Security: CVE-2026-58047
https://support.cpanel.net/hc/en-us/articles/42285024734743-Security-CVE-2026-58047-HTTP-Request-Smuggling
Security: CVE-2026-58048
https://support.cpanel.net/hc/en-us/articles/42285745783703-Security-CVE-2026-58048-Database-Privilege-Escalation
Security: GCVE-25-2026-07-45-3
https://support.cpanel.net/hc/en-us/articles/42285884685207-Security-GCVE-25-2026-07-45-3-Exim-forward-Privilege-Escalation?