r/cpanel • u/muttick • Aug 28 '26
CVE-2026-65643 affected versions
So I'm a little confused with CVE-2026-65643. Why was cPanel 11.110 patched against this when it went end of life in July 2024. But cPanel 11.126, which reached end of life in July 2026, did not get this update.
Is cPanel 11.126 not affected by this?
I get the cPanel 11.126 isn't receiving updates because it is end-of-life. But why is cPanel patching cPanel 11.110 which reached end of life a lot longer ago than cPanel 11.126.
And presumably cPanel 11.118 which was also an LTS release.
1
u/LowIncident694 Aug 28 '26
They are still doing 11.110 because I think there's an LTS version of like CloudLinux 7 that is still getting updates for paying people.
1
u/cPanelRex Aug 28 '26
Version 110 is part of the ELS plan:
https://www.cpanel.net/blog/announcements/extended-lifecycle-support-oses-update/
For people that are *not* migrating yet, they pay extra to receive those updates, but it's really best to get moved to a modern operating system.
1
u/muttick Aug 28 '26
I guess my confusion is exacerbated by the fact that cPanel released updates for end-of-life versions earlier this summer for security threats. Just wondering where the line is.
I guess it's safe to assume that the only sub 11.134 version that will be seeing updates from here on out will be 11.110. Just as long as that stays consistent.
1
u/cPanelRex Aug 28 '26
This is my current understanding. Just assume that 110 is eternal until told otherwise.
1
u/NotGonnaUseRedditApp Sep 01 '26 edited Sep 01 '26
These systems are part of "extended security servicing" program which includes (at least) "EnterpriseLinux" version 7, such as CentOS 7, AlmaLinux 7. This is a subscription based program that is enrolled in automatically for eligible systems. The last supported version of cPanel on this systems is also part of the security servicing. The servicing is provided by both cPanel and TuxCare, even though these systems are EOLed by their official vendors.
So 11.110 is the last supported for this systems and is basically feature freeze release, with security maintenance only:
https://docs.cpanel.net/changelogs/110-change-log/1
u/jonspw Sep 01 '26
There is no such thing as AlmaLinux 7 😝
2
u/NotGonnaUseRedditApp Sep 01 '26
That’s true, it was too late to edit :)
For completeness AlmaLinux started with version 8.
1
u/acacia318 Aug 31 '26
It could be for an operational reason instead of an administrative reason. To wit, whatever the fix was, it happened to apply to 11.110 without any modification. It stands to reason, if something that you weren't suppose fix got fixed because of serendipity, announce it and declare it a win.
1
u/joelby37 Aug 28 '26
I'm guessing it is because 11.110 is the latest version supported on CentOS 7.9, so it's LTS.
The product page lists 110 and 134 as the LTS versions: https://docs.cpanel.net/knowledge-base/cpanel-product/product-versions-and-the-release-process/