Elanlar
- Çərşənbə axşamı, 5th May, 2026
- 19:59axşam
We would like to inform all HostRainbow clients about a critical security vulnerability affecting Apache HTTP Server used in cPanel/WHM environments.
Official advisories:
https://support.cpanel.net/hc/en-us/articles/40229402602519-Security-CVE-2026-23918
https://cybersecuritynews.com/apache-http-server-rce/
https://cloudlinux.zendesk.com/hc/en-us/articles/27239221402908-Apache-CVE-2026-23918-ea-apache24-2-4-67-is-not-available-in-CloudLinux-repositories
Vulnerability ID: CVE-2026-23918
Severity: Critical
Affected Component: Apache HTTP Server (HTTP/2 module)
What is the issue?
A serious vulnerability has been discovered in Apache HTTP Server, specifically affecting the HTTP/2 feature. This flaw may allow attackers to perform remote attacks and potentially execute malicious actions on vulnerable servers.
What is the risk?
-
Remote exploitation of vulnerable servers
-
Potential unauthorized access or control
-
Service disruption or unexpected behavior
-
Security compromise if left unpatched
Actions taken by HostRainbow
-
All managed servers have been reviewed and patched
-
Apache services have been updated to secure versions
-
Additional monitoring and security checks have been applied
All HostRainbow managed infrastructure is secured against this vulnerability.
Required actions for unmanaged or self-managed servers
If you are managing your own server, please update immediately using the commands below:
For RHEL / CentOS systems:
yum clean all
yum makecache
yum -y update ea-apache*
For AlmaLinux / RockyLinux systems:
dnf clean all
dnf makecache
dnf -y update ea-apache*
Important Note for CloudLinux Users
CloudLinux users may not yet receive Apache 2.4.67 through stable repositories. CloudLinux has temporarily provided the patched version through the cl-ea4-testing repository.
Official CloudLinux advisory:
https://cloudlinux.zendesk.com/hc/en-us/articles/27239221402908-Apache-CVE-2026-23918-ea-apache24-2-4-67-is-not-available-in-CloudLinux-repositories
Run:
yum update ea-apache24 --enablerepo=cl-ea4-testing
After the update, verify Apache version:
httpd -v
You should see:
Apache/2.4.67
After successful update, it is recommended to disable the testing repository again to avoid receiving future testing packages unintentionally.
Check if the testing repo is enabled:
dnf repolist enabled | grep testing
If enabled, disable it using:
yum-config-manager --disable cl-ea4-testing
For Ubuntu systems:
apt update
apt install --only-upgrade "ea-apache24*"
Additional recommendations
-
Restart Apache after update
-
Keep automatic updates enabled
-
Use firewall and WAF protection (CSF, Imunify360, etc.)
-
Monitor logs for suspicious activity
Important note
Due to the critical nature of this vulnerability, we strongly recommend updating immediately. Delayed patching may expose your server to active threats.
Need assistance?
If you need help securing your server or applying updates, please contact our support team.
Team HostRainbow
Hostrainbow is a web hosting provider offering shared hosting, VPS, dedicated servers, and domain registration. Known for reliability, security, and user-friendly services, they cater to both individuals and businesses seeking robust online solutions.