PatchSiren cyber security CVE debrief
CVE-2026-28387 cPanel CVE debrief
CVE-2026-28387 is addressed in cPanel’s EasyApache 4 25.54 release, which delivers a security patch for ea-openssl11. The vendor advisory groups this issue with related OpenSSL package CVEs in the same update stream, so the practical response is to treat the EasyApache 4 package refresh as the fix path for affected cPanel/WHM systems.
- Vendor
- cPanel
- Product
- cPanel/WHM
- CVSS
- HIGH 7
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-12
- Original CVE updated
- 2026-05-14
- Advisory published
- 2026-05-12
- Advisory updated
- 2026-07-24
Who should care
cPanel/WHM administrators, hosting providers, and system owners running EasyApache 4 with ea-openssl11 installed should review this release promptly, especially on internet-facing servers.
Technical summary
The supplied vendor source does not describe the underlying flaw mechanics for CVE-2026-28387. What is confirmed is that cPanel’s EasyApache 4 25.54 release includes a security patch for ea-openssl11, alongside related CVEs CVE-2026-28388 through CVE-2026-28390 and other package updates. The CVE record provided a CVSS score of 8.1 (High).
Defensive priority
High. The vendor has already released a package update that includes the fix, and the provided CVSS score indicates significant security impact. Apply the EasyApache 4 security update as soon as practical.
Recommended defensive actions
- Update EasyApache 4 to the vendor-released 25.54 package set or later.
- Confirm the installed ea-openssl11 package version matches the vendor-fixed release level.
- Review whether related EasyApache package updates (ea-php84, ea-php85, ea-nginx) are also pending on your servers.
- Prioritize systems that are publicly reachable or that host customer workloads.
- Track the cPanel release notes and linked CVE records for any follow-on clarification or additional package guidance.
Evidence notes
This debrief is based only on the supplied cPanel release-note summary and the provided CVE metadata. The source confirms a security patch for ea-openssl11 in EasyApache 4 25.54, but it does not provide root-cause details, affected versions, or exploitation conditions for CVE-2026-28387.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-28387 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-28387
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-28387 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-28387
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Vendor advisory source
Unverified legacy reference
URL: https://docs.cpanel.net/release-notes/release-notes/
cpanel_changelog_rss
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.