CVE-2026-23918
Hello all,
https://support.cpanel.net/hc/en-us/articles/40229402602519-Security-CVE-2026-23918
Refers to:
This issue affects Apache HTTP Server: 2.4.66.
Users are recommended to upgrade to version 2.4.67, which fixes the issue.
But the latest version update available is 2.4.66
dnf -y update ea-apache*
Last metadata expiration check: 1:02:57 ago on Tue 05 May 2026 05:45:01 AM SAST.
Dependencies resolved.
Nothing to do.
Complete!
httpd -v
Server version: Apache/2.4.66 (cPanel)
Server built: Mar 13 2026 14:39:27
-
Perhaps you are on a Cloudlinux server? Cloudlinux repositories do not yet have the updated ea-apache
0 -
Some servers are, but the one used in the example is straight AlmaLinux v9.7.0
And this is across all the servers, no version 2.4.67
0 -
Hello,
I confirm. Not yet an updated version online.
Almalinux 8.10
0 -
Same problem here with Almalinux 8.10.
0 -
We just released an update for this around midnight last night, so you should be able to update and receive the patch. If that isn't happening, let me know!
0 -
I logged a ticket with cpanel, and was told it because we run Imunify, and Cloudlinux has not published the fix yet. #95994308
They will check again with Cloudlinux in 12 hours. :(
0 -
Update now with System Update and reboot server
Server Version: Apache/2.4.67 (cPanel)
0 -
gatewayza - CloudLinux has the builds ready and they are going through final testing right now. I'd expect them to be out in the next few hours, ready for tonight's update.
0 -
What a week, should go back 35 years and tell myself to choose a different career path
1 -
gatewayza - hindsight and all that.........................
1 -
still no available update (almalinux 9.7):
# dnf -y update ea-apache*
Last metadata expiration check: 0:00:36 ago on Tue 05 May 2026 06:23:58 PM +01.
Dependencies resolved.
Nothing to do.
Complete!
# httpd -v
Server version: Apache/2.4.66 (cPanel)
Server built: Dec 8 2025 00:00:000 -
YouA - are you using Imunify on your server? If so, those packages are provided by CloudLinux. You can confirm this with the following command:
rpm -qa | grep -i ea-apache24-2
as that will show where your packages come from.
0 -
Yes, Alma with Imunify on this server:
rpm -qa | grep -i ea-apache24-2
ea-apache24-2.4.66-4.el8.cloudlinux.1.x86_640 -
cPRex yes I'm using imunify, this is the output:
# rpm -qa | grep -i ea-apache24-2
ea-apache24-2.4.66-2.el9.cloudlinux.x86_640 -
That's why it hasn't updated just yet then - they are working on their build now and they are hoping to have it out before updates tonight.
0 -
Thank you cPRex
hope to see the updated before we get hacked.
Is there any temporary fixing manipulation to do ?0 -
There's no temporary way to patch these as it's an entirely new Apache build.
0 -
All waiting for this, updated has been posted:
yum update ea-apache24 --enablerepo=cl-ea4-testing
0 -
FYI, this only seems to be working on Cloudlinux servers, not Almalinux with Imunify
yum update ea-apache24 --enablerepo=cl-ea4-testing
Error: Unknown repo: 'cl-ea4-testing'
Dont Cpanel and Cloudlinux communicate? It seems this was only discovered after I made this post. Since Imunify / Cloudlinux is punted all over cPanel, and cPanel patched this over 12 hours ago, it seems both CVE's for Apache did make it way to CL? And then the other big problem, Imunify is now a liability, because we cant patch with it.
And then when we get hacked, the response is, you need to restore from backup, shrug shoulder. This is not acceptable for the amount of money we pay every month to both companies.1 -
We definitely communicate, and the builds were already complete before this post. If they are in the resting repos it won't be long now.
0 -
Still nothing an hour later.
0 -
I sent a ticket to cloudlinux Ice team, may be they forget that Imunify is under their support
1 -
We are not in old times anymore, and our software suppliers need to speed up.
https://www.securityweek.com/ai-fuels-industrial-cybercrime-as-time-to-exploit-shrinks-to-hours/amp/My first post was 15 hours ago for reference
0 -
@cpRex, any update?
0 -
I've been told the packages are released the beta and can be acquired with the command you mentioned earlier in the thread. As to when they go fully live on the CloudLinux side, I don't have any control over that.
0 -
Unfortunetly, after sending a ticket to cloudlinux support, it seems that the support team don't even know about the issue of updating apache in almalinux + imunify environment.
i tried to give them all requested informations , and this is their answer:
---------------------------------------
In this case, you will need to wait for updates directly from cPanel, as our team is providing a fix for this CVE only for servers using the ea-apache packages from our repositories (servers with CloudLinux).
---------------------------------------
there is a huge differnece between cpanel and cloudlinux answers.0 -
This is what I was just given by CloudLinux/Imunify support:
yum update ea-apache24* --enablerepo=imunify360-ea-php-hardened-beta
Can't say I'm excited about installing "beta" code, but I'm not sure we have a lot of choice.
0 -
In general, that's how CloudLinux always releases their packages - it'll be in the beta tier for a while and then in the normal repos in a couple weeks. Even for the critical security issues like this one.
0 -
I wonder if that philosophy would change if they had dozens and dozens (prob. 100's for some people) to maintain. :-)
0 -
cPRex if a server have litespeed enabled and apache disabled that system urgently must make apache update to 2.4.67 or can wait cloudlinux remove the package from beta?
0
Please sign in to leave a comment.
Comments
31 comments