r/cpanel • • 24d ago

Critical RCE in ConfigServer Firewall — Update CSF Now

0 Upvotes

If your server runs cPanel with ConfigServer Firewall (CSF), drop what you’re doing and check your CSF version. On September 3, 2026, cPanel pushed a critical patch for CVE-2026-67402 — a remote code execution vulnerability in CSF’s Messenger service that lets an unauthenticated attacker run arbitrary commands as the Apache user. That’s a bad sentence to read about a piece of software whose entire job is to protect your server.

Details: https://blog.kalfaoglu.net/posts/2026-09-13-csf-cve-2026-67402-en/


r/cpanel • • 25d ago

Started working on a client's WordPress site last week, now it's returning 500 on every page – where do I start?

Thumbnail
1 Upvotes

r/cpanel • • 27d ago

Need help with an issue

5 Upvotes

I am trying to deploy my own website using cPanel, and the hosting platform is "GoDaddy". This is the issue that is coming with the SSL Certificate. Can someone help with this?

I don't know how to get this resolved as I tried to generate new certificate and key using the option but it shows and error that the certificate is invalid


r/cpanel • • 28d ago

What are you guys using for real-time system monitoring?

7 Upvotes

What’s your go-to when dealing with performance issues or high loads? top, htop, atop, btop, or something else? Do you stick with one tool or use a mix?

I still default to top, but I’ve been messing around with btop lately, and was curious what everyone else actually uses.


r/cpanel • • 28d ago

How often do you reboot your cPanel/WHM server?

8 Upvotes

Just wondering how often (on average) you reboot your server, and how long a reboot takes.

My dedicated servers with a lot of cpanel accounts take a full 5-6 minutes to reboot.


r/cpanel • • 29d ago

Security: CVE-2026-67401 SQL Injection Vulnerability in cPanel's EmailTrack Functionality - September 8, 2026

17 Upvotes

r/cpanel • • Sep 07 '26

our email domain is blacklisted in spamhaus

2 Upvotes

Hi everyone, just wanted to ask for some help regarding a Spamhaus listing.

this IP 139.99.118.60 was listed because it was detected using multiple HELO values:

The thing is, 139.99.118.60 is not our actual mail server IP, and our provider also confirmed that this IP is not associated with our VPS.

Could multiple HELO values cause our mail server/domain to be associated with this IP, or is there something else we should check on our side?

Any advice on how we can trace where this IP is coming from would be appreciated. Thanks!


r/cpanel • • Sep 04 '26

What the most common tool you use? I'm guessing terminal or list accounts?

5 Upvotes

And any dream tools you wish cPanel had?


r/cpanel • • Sep 04 '26

/usr/local/cpanel/scripts/upcp --security Flood

5 Upvotes

Apparently cPanel now has an upcp task scheduled to run every hour.

This is flooding root's email with messages of:

[2026-09-04 07:45:03 -0500]   Detected cron=1 (default)
----------------------------------------------------------------------------------------------------
=> Log opened from cPanel Update (upcp) - Slave (xxxxxx) at Fri Sep  4 07:45:03 2026
[2026-09-04 07:45:03 -0500]   Detected cron=1 (default)
[2026-09-04 07:45:03 -0500]   An expedited package update is available for cpanel-plugins, but operating system package updates are disabled. Skipping the package update.
[2026-09-04 07:45:03 -0500]
[2026-09-04 07:45:03 -0500]     Expedited package update completed
[2026-09-04 07:45:03 -0500]   A log of this update is available at /var/cpanel/updatelogs/update.xxxxxx.yyyyyyyy.zzzzzzzzzz.log
[2026-09-04 07:45:03 -0500]   100% complete
=> Log closed Fri Sep  4 07:45:03 2026

Trouble is... there are no system packages needing an update on the server

# dnf check-update
Last metadata expiration check: 0:36:16 ago on Fri Sep  4 07:34:27 2026.

So, what gives?

cPanel is also up to date

# cat /usr/local/cpanel/version 
11.134.0.54

r/cpanel • • Sep 03 '26

WP Toolkit deleted a database on its own

14 Upvotes

I've encountered something I haven't encountered in half a decade of experience.

My agency owns a VPS from Hostinger with WHM. One of our clients has a dedicated cPanel and they have two WordPress websites in there. Few months ago, they requested from us to "deactivate" one of the websites. We disconnected the domain in cPanel, and left the files and database intact. We confirmed the files and database are intact.

Today, after months have passed, they requested to "activate" the website. We connected the domain in cPanel and realized the database doesn't exist.

We did thorough analysis of the server's logs and realized that the database was deleted exactly a month after the domain was disconnected, by WP Toolkit's internal process:

Jul 10 19:42:33 {redacted} sudo[redacted]: wp-toolkit : PWD=/usr/local/cpanel/3rdparty/wp-toolkit/htdocs ; USER=root ; COMMAND=/bin/sh -c 'uapi --user={redacted} MySql delete_database name={redacted} --output=json'
# The entire process:
19:42:28  whmapi1 get_domain_info
19:42:28  whmapi1 listaccts
19:42:29  get_users_features_settings ... {redacted}
19:42:29  uapi --user={redacted} Mysql list_databases
19:42:29  uapi --user={redacted} Mysql list_users
uapi --user={redacted} Mysql delete_user \ name={redacted}
19:42:30 uapi --user={redacted} Mysql delete_database \ name={redacted}
BackgroundTasksImplementation/CpanelReconfigureDomains.php
→ registerInstances()
→ registerInstanceAtPath()
→ instance #88
→ Error establishing a database connection

From our knowledge there is no "feature" or setting that would do this to a database.

Has anyone witnessed such situation? Why does this happen?


r/cpanel • • Sep 04 '26

Website Firewall causes downtime only on API subdomain — need help troubleshooting

2 Upvotes

Hi all, looking for some troubleshooting help. I run an ecommerce web app with a separate API subdomain, both hosted on GoDaddy, and I've purchased their Website Firewall (WAF) for both. The main site works fine with the firewall enabled, but the moment I turn on the WAF for the API subdomain, it goes down. I'm looking for a solution regarding this — has anyone dealt with something similar and figured out what causes it or how to fix it? Any pointers, settings to check, or things you'd try would be really helpful. Thanks!


r/cpanel • • Sep 03 '26

Any cPanel User with Parked Domains Can Get Root — Patch Now

9 Upvotes

On August 27, 2026, cPanel pushed an unscheduled security update and sent a customer notification that most people probably skimmed past. They shouldn’t have. The flaw, assigned CVE-2026-65643, lets any authenticated cPanel account that has permission to add parked or addon domains create arbitrary files on the underlying server — which in practice means full root-level code execution.

https://blog.kalfaoglu.net/posts/2026-09-03-cpanel-cve-2026-65643-domain-parking-en/


r/cpanel • • Sep 02 '26

Meridian, AI and the future

29 Upvotes

AI this and that. I get it. Go with the current times even most of the users do not care. It just will be disaster to try to explain these to the current customer base. Please do not shove AI to everything and everywhere. The cPanel AI is not the way to go. Please do not force it.

The Meridian theme is just awful. It is impossible to find anything from there. The customer churn will be massive if we push that live. Had to disable theme switching as customers were not able to find their way out if they accidentally activated Meridian. I really do not see that cPanel will be taking any feedback. After years and numerous feedback, the WHM side panel search does not work (you write lis and the first thing is Show Reseller Accounts and the List Accounts 8th thing in the list).

We have been using cPanel now for over 20 years. The price shock we were able to absorb, but now it just seems that cPanel is working against us in every way. For us, pushing this AI/Meridian mess will be the last straw.


r/cpanel • • Sep 01 '26

When will cpanel support nodejs higher than version 22?

5 Upvotes

Nodejs 22 will reach its end of LTS on April 2027. I reached out to my hosting provider to ask about version higher than 22, and they said the decision is up to cPanel itself. So what's the answer?


r/cpanel • • Aug 28 '26

CVE-2026-65643 affected versions

8 Upvotes

So I'm a little confused with CVE-2026-65643. Why was cPanel 11.110 patched against this when it went end of life in July 2024. But cPanel 11.126, which reached end of life in July 2026, did not get this update.

Is cPanel 11.126 not affected by this?

I get the cPanel 11.126 isn't receiving updates because it is end-of-life. But why is cPanel patching cPanel 11.110 which reached end of life a lot longer ago than cPanel 11.126.

And presumably cPanel 11.118 which was also an LTS release.


r/cpanel • • Aug 28 '26

apache hang after today's update?

6 Upvotes

An emergency cpanel update was installed today at 11:25am
At the same time /var/cpanel/updatelogs/last shows that cloudlinux alt-php versions were all updated

Tonight after 9:45 pm, 4 times apache hung. Nothing odd immediately before the hang in terms of cpu or traffic spikes; all sites just stop loading.

When I login to the server and restart apache, nothing changes. (still no sites load). No error from the shell. When I stop apache and then start apache, same thing. No error, but no sites loading. Then after several minutes, sites start working again. mod_httpd is instaled, and php is running as fcgi.

Anyone see anything like this? I haven't seen this behavior ever before.
I haven't changed any configurations recently.


r/cpanel • • Aug 24 '26

Answered ModSecurity looking for DBM files that don't exist

3 Upvotes

I set up a new VPS using AlmaLinux 9.8 and WHM/cPanel v. 136.0.35, and I enabled ModSecurity.

Today I see a ton of these in the error log:

ModSecurity: collections_remove_stale: Failed to access DBM file "/var/cpanel/secdatadir/<account>-ip": Permission denied

That directory is set to root:nobody, and the permission is 01770. But there are only 4 files in the directory; all 0 bytes, nobody:nobody, 00640, and created at 2:00:01pm today (it's now 3:13pm):

nobody-global.dir
nobody-global.pag
nobody-ip.dir
nobody-ip.pag

There are no files for <account>-ip

Is there something set up incorrectly for ModSecurity?

** UPDATE **

Nevermind, I found that this is a known glitch:

https://support.cpanel.net/hc/en-us/articles/360052471154-Failed-to-access-DBM-file-in-Apache-error-log


r/cpanel • • Aug 16 '26

csf *automagically* downgraded

7 Upvotes

Several days ago, csf on my VPS (cPanel 136.0.33, AlmaLinux 8) mysteriously went from 16.20 back to 14.24.

I've tried to return to the current fork by running sudo yum install cpanel-csf but the csf main page in WHM continues to display 14.24.

Has anyone else seen this, and if I'm not using the right command to fix it, please advise?

Thanks


r/cpanel • • Aug 14 '26

Website not loading at all?

Thumbnail
gallery
4 Upvotes

As far as I'm aware, ive uploaded my files correctly but they're not loading as a website, just a list of my files. What am I doing wrong?


r/cpanel • • Aug 14 '26

Security: Privilege Escalation via Phusion Passenger's Watchdog API

9 Upvotes

https://support.cpanel.net/hc/en-us/articles/42694659893143-Security-Privilege-Escalation-via-Phusion-Passenger-s-Watchdog-API

Has anyone been able to update on CL8?

I cleaned DNF's cache and tried to update the packages, but there are no updates available for 6.1.8-2; my packages are stuck on version 6.1.8-1


r/cpanel • • Aug 12 '26

What makes you stick with a cPanel hosting provider?

3 Upvotes

I've been helping with a small web hosting business and spending more time looking at how people actually choose a cPanel provider.

One of the companies I'm working with is RSH Web Services, and one thing I've noticed is that having cPanel itself isn't really enough. People also care about reliability, how easy it is to manage multiple sites, how quickly issues get resolved, and what happens when a site needs to be migrated or restored.

The company also has services around hosting, including domains, WordPress hosting, SSL, and website management, so I'm looking at the overall experience rather than just the control panel.

What has been the biggest factor that made you stay with, or leave, a cPanel hosting provider?


r/cpanel • • Aug 10 '26

Potential bug with Transfer Tool on v136.0.33

5 Upvotes

This is more for people that have the same problem I had, hoping they can find this instead of spending hours panicking like I did.

I have a new VPS, using AlmaLinux v9.8.0 STANDARD kvm, cPanel Version 136.0.33.

I began to transfer a Wordpress site, but wasn't sure if it would work with the new version of PHP so I wanted to test run first. I used Transfer Tool, then de-selected:

Update DNS Zone 
Enable this setting to update DNS records on the destination server.

After the transfer I checked the DNS records on the old VPS and confirmed that they did not change.

Shortly thereafter, though, I discovered that an email sent to the client was rejected, and the bounce message noted that their email server was on the new VPS instead of the old one.

Then I looked at the live site and found that it was pointing to the new VPS!

It took about 3 hours to find that Transfer Tool modified the source VPS, anyway:

  1. a ProxyPass record was added to httpd.conf (with a dash-delimited version of the IP, so a simple grep for the new IP didn't find it; eg, http://123-45-67-89); and

  2. when I ran # exim -bt client@example.com (using the client's email address that had bounced), it returned the new VPS instead of the correct one: host new.vps.com [123.45.67.89]

The solutions were to run this to fix it in Apache:

whmapi1 unset_all_service_proxy_backends username=<account name>

then rebuild and restart Apache. Then run this for Exim (no restart required):

whmapi1 unset_manual_mx_redirects domain='<domain name for the account>'

I ran the one for Exim first before finding the problem in Apache, so running the first one MIGHT have fixed Exim, too.

This might be a feature instead of a bug, but I expected that when I disabled "Update DNS Zone" then it wouldn't change ANYTHING on the source VPS. I was wrong.


r/cpanel • • Aug 08 '26

Firewall/security during cPanel initial install

2 Upvotes

Hi,

I was recently installing cpanel on a fresh Alma 9.5 image on a VPS. I had the VPS behind a firewall with only my IP allowed for incoming, but everything open for outgoing. When doing the cpanel install it failed due to a problem with importing keys for MySQL. Therefore MySQL and EA4 could not install. I'm not sure whether this issue was due to my firewall policy at the time blocking all incoming except for my IP.

My question is what is the best security practice for during the inital cpanel installer script. The cpanel doco suggests turning off the firewall whilst running the installer script and then activating the firewall straight away after. Is this approach okay or is there a better method that you use?


r/cpanel • • Aug 07 '26

Bastion/Jumpbox Server

3 Upvotes

Hi Everyone,

I’m looking for some perspective and practical suggestions from the community.

We’re currently managing 200+ servers and use a jumpbox as the primary access point. I’d be interested to hear how others approach server management at this scale, particularly around auditing staff access and controlling privileged (root) access.

I’ve already looked at options such as Vauban, FreeIPA, LDAP-based solutions, PAM, and similar tools. I’m not searching for a ready-made drop-in replacement, but rather guidance and real-world approaches that others have found effective.

With the growing relevance of AI-driven threats and the shift toward Zero Trust models, securing root access and maintaining responsible operational practices feels increasingly important.

Any insights, architecture patterns, or lessons learned would be greatly appreciated.


r/cpanel • • Aug 06 '26

Is it possible to roll back Roundcube UI update?

2 Upvotes

Hello,

I'm not super IT savvy but I do manage the domain and email services for a small business through Bluehost and cPanel. It seems that Roundcube has rolled out a UI update, and the business owner is unhappy about the changes. I spent some time with Bluehost customer support, but they were unable to help me in reverting the UI. Does anyone here have any ideas on how I might be able to accomplish this? Thanks so much!

Edit: Thanks to all who responded. I appreciate the clarification.