CPanel Product Security Update Advisory

CPanel Product Security Update Advisory

Overview


cPanel has released a security update that addresses vulnerabilities in cPanel & WHM and WP Squared. users of these products should update to the latest version.

Resolved Vulnerabilities


  • CVE-2026-29201: Arbitrary file read vulnerability in cPanel & WHM and WP Squared.
  • CVE-2026-29202: Perl code injection vulnerability in cPanel & WHM and WP Squared, which allows malware to be injected into Perl.
  • CVE-2026-29203: Improper symbolic link handling vulnerability in cPanel & WHM and WP Squared (vulnerability that could lead to link handling errors).

Affected Products & Versions


the following versions and below are affected

  • cPanel & WHM 11.136.0.9 and earlier.
  • cPanel & WHM 11.134.0.25 and earlier.
  • cPanel & WHM 11.132.0.31 and earlier.
  • cPanel & WHM 11.130.0.22 or earlier.
  • cPanel & WHM 11.126.0.58 or lower.
  • cPanel & WHM 11.124.0.37 or lower.
  • cPanel & WHM 11.118.0.66 or lower.
  • cPanel & WHM 11.110.0.117 or lower.
  • cPanel & WHM 11.102.0.41 or lower.
  • cPanel & WHM below 11.94.0.30.
  • cPanel & WHM 11.86.0.43 or lower.
  • WP Squared 11.136.1.11 or lower.

Recommendations


you should update to the latest version of the Vulnerability Patch by following the instructions on the reference site. after applying the patches, cPanel & WHM should be at or above their respective baseline versions and WP Squared should be at or above 11.136.1.11.