• Quarta-feira, Mai 20, 2026

Dear Valued Partner, 

We are writing to confirm that the latest patched builds for cPanel & WHM are now available, addressing multiple vulnerabilities including those rated up to High severity.

 

Note: Due to an actively exploited vulnerability in the LiteSpeed User-End Plugin - a third-party plugin that integrates with cPanel (see details below), this security release was published approximately 12 hours ahead of the originally scheduled May 20, 2026 release. We regret any disruption this may have caused.

 

Vulnerabilities Addressed

 

This release addresses the following security issues:

 

  • SEC-73728: See support article for details.
  • SEC-73755: See support article for details.
  • LiteSpeed User-End cPanel Plugin: A privilege-escalation vulnerability allowing unauthorized root access, actively exploited in the wild. As an interim security measure, an automated fix has been included in this release that uninstalls the LiteSpeed User-End cPanel Plugin. See support article for details.

 

Please follow the instructions in the linked support articles and update cPanel & WHM to one of the patched versions listed below. We strongly recommend performing a manual update.

 

Patched versions

TSR-May-19-Patched-V

Note for CloudLinux 6 users: Customers on CentOS 6 or CloudLinux 6 should update to the cl6110 branch (11.110.0.120) before manually updating.

 

 

Key Resources

Please reach out to your account manager or our support team, if you have any questions or need further guidance. 

 

Thank you for your continued partnership.