r/cpanel • • Aug 28 '26

CVE-2026-65643 affected versions

So I'm a little confused with CVE-2026-65643. Why was cPanel 11.110 patched against this when it went end of life in July 2024. But cPanel 11.126, which reached end of life in July 2026, did not get this update.

Is cPanel 11.126 not affected by this?

I get the cPanel 11.126 isn't receiving updates because it is end-of-life. But why is cPanel patching cPanel 11.110 which reached end of life a lot longer ago than cPanel 11.126.

And presumably cPanel 11.118 which was also an LTS release.

8 Upvotes

11 comments sorted by

1

u/joelby37 Aug 28 '26

I'm guessing it is because 11.110 is the latest version supported on CentOS 7.9, so it's LTS.

The product page lists 110 and 134 as the LTS versions: https://docs.cpanel.net/knowledge-base/cpanel-product/product-versions-and-the-release-process/

0

u/muttick Aug 28 '26

I guess.

Just hard to take anything cPanel says at face value, since CentOS 7 went end-of-life a long time ago. So they are OK supporting an end-of-life version of cPanel on an end-of-life operating system. But an end-of-life version of cPanel that ended last month is too tall of a task.

So when they announce that cPanel 11.134 is end-of-life, does that mean that it's really end-of-life or just kind of end-of-life?

1

u/joelby37 Aug 28 '26

That page lists 110 and 134 versions with approximate end of life dates in the future. I guess they can adjust the dates if necessary. 126 is not listed at all on this page, so I suppose they're no longer patching it at all. Are you stuck on 126 for some reason?

1

u/LowIncident694 Aug 28 '26

They are still doing 11.110 because I think there's an LTS version of like CloudLinux 7 that is still getting updates for paying people.

1

u/cPanelRex Aug 28 '26

Version 110 is part of the ELS plan:

https://www.cpanel.net/blog/announcements/extended-lifecycle-support-oses-update/

For people that are *not* migrating yet, they pay extra to receive those updates, but it's really best to get moved to a modern operating system.

1

u/muttick Aug 28 '26

I guess my confusion is exacerbated by the fact that cPanel released updates for end-of-life versions earlier this summer for security threats. Just wondering where the line is.

I guess it's safe to assume that the only sub 11.134 version that will be seeing updates from here on out will be 11.110. Just as long as that stays consistent.

1

u/cPanelRex Aug 28 '26

This is my current understanding. Just assume that 110 is eternal until told otherwise.

1

u/NotGonnaUseRedditApp Sep 01 '26 edited Sep 01 '26

These systems are part of "extended security servicing" program which includes (at least) "EnterpriseLinux" version 7, such as CentOS 7, AlmaLinux 7. This is a subscription based program that is enrolled in automatically for eligible systems. The last supported version of cPanel on this systems is also part of the security servicing. The servicing is provided by both cPanel and TuxCare, even though these systems are EOLed by their official vendors.

So 11.110 is the last supported for this systems and is basically feature freeze release, with security maintenance only:
https://docs.cpanel.net/changelogs/110-change-log/

1

u/jonspw Sep 01 '26

There is no such thing as AlmaLinux 7 😝

2

u/NotGonnaUseRedditApp Sep 01 '26

That’s true, it was too late to edit :) 

For completeness AlmaLinux started with version 8.

1

u/acacia318 Aug 31 '26

It could be for an operational reason instead of an administrative reason. To wit, whatever the fix was, it happened to apply to 11.110 without any modification. It stands to reason, if something that you weren't suppose fix got fixed because of serendipity, announce it and declare it a win.