Annonceringer
- onsdag, 20th Maj, 2026
- 18:42om eftermiddagen
We would like to inform all HostRainbow clients about important security updates affecting cPanel & WHM and the LiteSpeed WHM/cPanel Plugin.
These vulnerabilities include fixes for multiple issues rated up to High severity and should be patched immediately.
Security Advisory: cPanel & WHM
This security release addresses vulnerabilities across multiple versions of cPanel & WHM, including fixes for several vulnerabilities rated up to High severity.
Patched cPanel Versions
-
11.86.0.45 and higher
-
11.94.0.32 and higher
-
11.102.0.43 and higher
-
11.110.0.121 and higher
-
11.118.0.68 and higher
-
11.124.0.41 and higher
-
11.126.0.62 and higher
-
11.130.0.26 and higher
-
11.132.0.35 and higher
-
11.134.0.29 and higher
-
11.136.0.13 and higher
Patched WP Squared Versions
-
11.136.1.16 and higher
Actions Taken by HostRainbow
-
All managed servers are being reviewed and updated
-
Security patches are being applied where required
-
Additional monitoring and security checks have been enabled
Required Actions for Self-Managed Servers
Update cPanel immediately:
/scripts/upcp --force
If you are using LicenseCrate shared licenses:
licensecrateCP ; /scripts/upcp --force
Recommended Additional Steps
Restart cPanel services after update:
/scripts/restartsrv_cpsrvd
Clear active cPanel sessions:
rm -rf /var/cpanel/sessions/*
Verify cPanel version:
/usr/local/cpanel/cpanel -V
Security Advisory: LiteSpeed WHM/cPanel Plugin
A security vulnerability has been identified in the LiteSpeed WHM/cPanel plugin.
If exploited, this vulnerability could potentially allow an attacker to gain root-level access to the server.
This issue has been resolved in:
-
LiteSpeed WHM Plugin version 5.3.0.0 and higher
Update Guide for LiteSpeed Plugin
The updated version should now be available directly within the LiteSpeed WHM plugin interface.
You can update using WHM:
WHM → LiteSpeed Web Server → Version Manager / Plugin Update
Or verify plugin version manually:
rpm -qa | grep litespeed
Additional Recommendations
-
Keep automatic updates enabled
-
Use strong passwords and 2FA
-
Ensure firewall protection is active (CSF, Imunify360, etc.)
-
Monitor logs regularly for suspicious activity
-
Keep all server plugins and control panel components updated
Important Note
Due to the severity of these vulnerabilities, we strongly recommend updating immediately. Delayed patching may expose servers to unauthorized access or exploitation attempts.
Need Assistance?
If you need help updating or securing your server, our support team is available to assist.
Team HostRainbow
Hostrainbow is a web hosting provider offering shared hosting, VPS, dedicated servers, and domain registration. Known for reliability, security, and user-friendly services, they cater to both individuals and businesses seeking robust online solutions.