PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-45447 cPanel CVE debrief

A security and maintenance update for EasyApache 4 (version 25.66) was released, addressing five CVEs, including four High-severity issues (CVE-2026-45447, CVE-2026-34180, CVE-2026-7383, CVE-2026-9076). The update patches ea-openssl11 to 1.1.1w-8 (for CentOS 7 only) with TuxCare/ELS backports and updates the Passenger ecosystem to v6.1.5. This release aims to enhance security and stability for users of cPanel/WHM.

Vendor
cPanel
Product
cPanel/WHM
CVSS
HIGH 8.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-06-09
Original CVE updated
2026-06-16
Advisory published
2026-06-09
Advisory updated
2026-06-16

Who should care

System administrators and security teams managing cPanel/WHM environments, particularly those using EasyApache 4, should prioritize this update to mitigate potential security risks associated with the addressed CVEs.

Technical summary

The EasyApache 4 25.66 update specifically addresses CVE-2026-45447, a High-severity vulnerability, along with four other CVEs. It updates ea-openssl11 to 1.1.1w-8 for CentOS 7 and upgrades the Passenger ecosystem components (ea-passenger-src, ea-apache24-mod-passenger, ea-nginx-passenger, ea-ruby27-passenger) to version 6.1.5. These changes are designed to enhance the security posture of cPanel/WHM installations.

Defensive priority

High

Recommended defensive actions

  • Apply the EasyApache 4 25.66 update to patch CVE-2026-45447 and other addressed CVEs.
  • Ensure all components of the Passenger ecosystem are updated to version 6.1.5.
  • Review and apply TuxCare/ELS backports for ea-openssl11 (CentOS 7 only).
  • Monitor cPanel/WHM environments for any signs of exploitation attempts related to these CVEs.
  • Regularly review and update EasyApache 4 configurations to align with the latest security recommendations.
  • Consider implementing additional security measures, such as enhanced monitoring and intrusion detection systems.

Evidence notes

The information provided is based on the official cPanel changelog and CVE records. The update directly addresses multiple High-severity vulnerabilities, emphasizing the importance of prompt application.

Official resources

CVE-2026-45447 was published on 2026-06-09T17:17:19.277Z and modified on 2026-06-16T02:56:50.707Z.