Home/ Blog/ Security news/ Article
Blog · Security news

cPanel security update fixes three flaws rated up to High, including one in the bundled Exim mail server

cPanel and WHM's new security release fixes CVE-2026-58047, CVE-2026-58048 and an Exim flaw, rated up to High. Patched versions for every branch, what to do.

Server panels with sealed hatches representing cPanel security fixes

cPanel and WHM shipped a security release today, 29 July 2026, fixing three vulnerabilities the vendor collectively rates up to High severity: CVE-2026-58047 in cpsrvd, the daemon that serves the cPanel and WHM web interfaces, CVE-2026-58048 in the panel's database functionality, and GCVE-25-2026-07-45-3 in the bundled Exim mail server. Patched builds exist for every supported branch. Servers that auto-update will pick them up on their own; anything pinned to a fixed version needs a manual push.

If you run a hosting fleet, the short version: two of the three flaws have no public technical details yet, which is normal for cPanel's process and temporary. The clock that matters starts when those details publish, because that is when working exploits tend to follow. The update window is now, while attackers know as little as you do.

Three fixes, two of them still sealed

The release note to customers names the components but not the mechanics. Both CVE records were still marked reserved at the National Vulnerability Database when we checked, and the public changelog entry for the new builds says only "Targeted Security Release".

IdentifierComponentWhat is public
CVE-2026-58047cpsrvd, the service behind the cPanel and WHM web interfacesDetails withheld until the disclosure window closes
CVE-2026-58048Database functionality in the panelDetails withheld until the disclosure window closes
GCVE-25-2026-07-45-3The Exim mail server that ships with cPanelLocal privilege escalation via .forward file handling; fixed upstream in Exim 4.99.5
The three fixes in the 29 July 2026 cPanel and WHM security release, per the vendor's customer notification.

The patched versions, one per supported branch:

BranchPatched version
110 (long-term support)11.110.0.137
12611.126.0.78
13411.134.0.48
13611.136.0.32
13811.138.1.6
Fixed builds listed in cPanel's notification; the 110 build is confirmed in the public 110 changelog, dated 29 July 2026.

The release also carries what the vendor describes as additional security hardening for certain supported operating system configurations, with no further specifics.

The Exim flaw is the one with public details

The third item is not a cPanel bug at all. The Exim project fixed GCVE-25-2026-07-45-3 upstream in version 4.99.5, released as a security release under an advisory dated 22 June 2026; today's cPanel update brings that fix to the Exim build the panel ships and manages.

Per the advisory and reporting on the release, exploitation needs a specific configuration: a redirect router that processes user .forward files, combined with a pipe transport using the force_command option, with that pipe running as a privileged user. When all three line up, a local account can get Exim to run commands with elevated privileges. That is not every mail server, but forwarding setups and older mailing-list configurations are where the combination tends to appear. A quick way to see whether your configuration uses the risky option:

terminal · check the Exim config for the option involved
grep -n "force_command" /etc/exim.conf
exim -bV | head -1

No output from the first command means the force_command precondition is absent from the main config. The second prints the running Exim version. On cPanel servers Exim is installed and updated by the panel, so the panel update is the fix path; separately maintained Exim installs need 4.99.5 or later on their own.

Why cPanel says so little, and what that means for timing

cPanel handles security fixes through what it calls a Targeted Security Release: patched builds ship first, technical details follow later, after the fleet has had time to update. The details being sealed is not a red flag. It is the working assumption behind the process: give defenders a head start measured in days, because once the specifics publish, proof-of-concept code and scanning usually arrive quickly.

Recent history makes the point. cPanel's previous major cpsrvd flaw, the CVE-2026-41940 authentication bypass patched in April, ended up in CISA's known-exploited-vulnerabilities catalog after attackers weaponized it, and this spring's LiteSpeed cPanel plugin escalations showed how quickly panel-layer bugs get picked up once documented. There are no exploitation reports for the three new flaws at the time of writing, and the head start only has value if it is used.

Update the pinned branches first

cPanel installations update themselves nightly by default, so most of the fleet will absorb this release without anyone touching it. The servers that need a human are the ones where updates are pinned to a fixed version or disabled, which in practice means the most change-averse machines: the long-term-support boxes on the 110 branch. Check and update by hand:

terminal · check the panel version, then update
cat /usr/local/cpanel/version
/usr/local/cpanel/scripts/upcp

Compare the version you see against the table above for your branch. After the update, the quiet second step is verification, the same lesson as patching a gateway and then checking it was not already visited: keep an eye on panel authentication logs and mail logs in the days after the technical details publish. A patched server tells you nothing about what happened before the patch, and with two of the three flaws still sealed, the log review is cheap insurance you can set up today.

Topics

Frequently asked questions

Which cPanel versions contain the July 2026 security fixes?

The patched builds are 11.110.0.137, 11.126.0.78, 11.134.0.48, 11.136.0.32, and 11.138.1.6, one per supported branch.

Servers with automatic updates enabled pick them up on the nightly update; pinned or update-disabled servers must run an update manually.

Are CVE-2026-58047 and CVE-2026-58048 being exploited?

There are no exploitation reports at the time of writing, and technical details are withheld.

cPanel ships Targeted Security Release fixes before publishing specifics, so the low-risk window is now: exploitation risk typically rises after details and proof-of-concept code become public.

What does the Exim flaw in the cPanel update do?

GCVE-25-2026-07-45-3 lets a local account run commands with elevated privileges through Exim.

Per the Exim advisory, it requires a redirect router processing .forward files plus a pipe transport using force_command running as a privileged user. Exim fixed it upstream in version 4.99.5 on 22 June 2026.

Do I need to update Exim separately on a cPanel server?

No. cPanel installs and manages its own Exim build, and the panel security update delivers the Exim fix.

Only Exim installations maintained outside the panel need to move to version 4.99.5 or later on their own.

What is a cPanel Targeted Security Release?

It is how cPanel ships security fixes: patched builds first, technical details published only later.

The delay gives administrators time to update before the specifics enable exploit development, which is why updating during the quiet window matters more than the missing details.

Ready to meet the Guardians?

Deploys fast - agentless for monitoring and cloud, a lightweight agent for deep endpoint security. Just Suriq, standing watch.