PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-28387 cPanel CVE debrief

CVE-2026-28387 is addressed in cPanel’s EasyApache 4 25.54 release, which delivers a security patch for ea-openssl11. The vendor advisory groups this issue with related OpenSSL package CVEs in the same update stream, so the practical response is to treat the EasyApache 4 package refresh as the fix path for affected cPanel/WHM systems.

Vendor
cPanel
Product
cPanel/WHM
CVSS
HIGH 7
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-12
Original CVE updated
2026-05-14
Advisory published
2026-05-12
Advisory updated
2026-07-24

Who should care

cPanel/WHM administrators, hosting providers, and system owners running EasyApache 4 with ea-openssl11 installed should review this release promptly, especially on internet-facing servers.

Technical summary

The supplied vendor source does not describe the underlying flaw mechanics for CVE-2026-28387. What is confirmed is that cPanel’s EasyApache 4 25.54 release includes a security patch for ea-openssl11, alongside related CVEs CVE-2026-28388 through CVE-2026-28390 and other package updates. The CVE record provided a CVSS score of 8.1 (High).

Defensive priority

High. The vendor has already released a package update that includes the fix, and the provided CVSS score indicates significant security impact. Apply the EasyApache 4 security update as soon as practical.

Recommended defensive actions

  • Update EasyApache 4 to the vendor-released 25.54 package set or later.
  • Confirm the installed ea-openssl11 package version matches the vendor-fixed release level.
  • Review whether related EasyApache package updates (ea-php84, ea-php85, ea-nginx) are also pending on your servers.
  • Prioritize systems that are publicly reachable or that host customer workloads.
  • Track the cPanel release notes and linked CVE records for any follow-on clarification or additional package guidance.

Evidence notes

This debrief is based only on the supplied cPanel release-note summary and the provided CVE metadata. The source confirms a security patch for ea-openssl11 in EasyApache 4 25.54, but it does not provide root-cause details, affected versions, or exploitation conditions for CVE-2026-28387.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-28387 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-28387

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-28387 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-28387

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Vendor advisory source

    Unverified legacy reference

    URL: https://docs.cpanel.net/release-notes/release-notes/

    cpanel_changelog_rss

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.