Skip to main content

CVE-2026-23918

Comments

31 comments

  • @mh-alex

    Perhaps you are on a Cloudlinux server? Cloudlinux repositories do not yet have the updated ea-apache

    0
  • gatewayza

    Some servers are, but the one used in the example is straight AlmaLinux v9.7.0 

    And this is across all the servers, no  version 2.4.67

    0
  • net@work

    Hello,

    I confirm. Not yet an updated version online.

    Almalinux 8.10

    0
  • lcac upc

    Same problem here with Almalinux 8.10.

    0
  • cPRex Jurassic Moderator

    We just released an update for this around midnight last night, so you should be able to update and receive the patch.  If that isn't happening, let me know!

    0
  • gatewayza

    I logged a ticket with cpanel, and was told it because we run Imunify, and Cloudlinux has not published the fix yet. #95994308

    They will check again with Cloudlinux in 12 hours. :(

     

     

    0
  • ciao70

    Update now with System Update and reboot server

    Server Version: Apache/2.4.67 (cPanel) 

     

     

    0
  • cPRex Jurassic Moderator

    gatewayza - CloudLinux has the builds ready and they are going through final testing right now.  I'd expect them to be out in the next few hours, ready for tonight's update.

    0
  • gatewayza

    What a week, should go back 35 years and tell myself to choose a different career path

    1
  • cPRex Jurassic Moderator

    gatewayza - hindsight and all that.........................

    1
  • YouA

    still no available update (almalinux 9.7):
    # dnf -y update ea-apache*
    Last metadata expiration check: 0:00:36 ago on Tue 05 May 2026 06:23:58 PM +01.
    Dependencies resolved.
    Nothing to do.
    Complete!
    # httpd -v
    Server version: Apache/2.4.66 (cPanel)
    Server built:   Dec  8 2025 00:00:00

    0
  • cPRex Jurassic Moderator

    YouA - are you using Imunify on your server?  If so, those packages are provided by CloudLinux.  You can confirm this with the following command:

    rpm -qa | grep -i ea-apache24-2

    as that will show where your packages come from.

    0
  • gatewayza

    Yes, Alma with Imunify on this server: 

     rpm -qa | grep -i ea-apache24-2
    ea-apache24-2.4.66-4.el8.cloudlinux.1.x86_64

    0
  • YouA

    cPRex yes I'm using imunify, this is the output:
    # rpm -qa | grep -i ea-apache24-2
    ea-apache24-2.4.66-2.el9.cloudlinux.x86_64

    0
  • cPRex Jurassic Moderator

    That's why it hasn't updated just yet then - they are working on their build now and they are hoping to have it out before updates tonight.

    0
  • YouA

    Thank you cPRex
    hope to see the updated before we get hacked.

    Is there any temporary fixing manipulation to do ?

    0
  • cPRex Jurassic Moderator

    There's no temporary way to patch these as it's an entirely new Apache build.

    0
  • gatewayza

    All waiting for this, updated has been posted: 

    https://cloudlinux.zendesk.com/hc/en-us/articles/27239221402908-Apache-CVE-2026-23918-ea-apache24-2-4-67-is-not-available-in-CloudLinux-repositories

     

    yum update ea-apache24 --enablerepo=cl-ea4-testing
    0
  • gatewayza

    FYI, this only seems to be working on Cloudlinux servers, not Almalinux with Imunify 
    yum update ea-apache24 --enablerepo=cl-ea4-testing
    Error: Unknown repo: 'cl-ea4-testing'

    Dont Cpanel and Cloudlinux communicate? It seems this was only discovered after I made this post. Since Imunify / Cloudlinux is punted all over cPanel, and cPanel patched this over 12 hours ago, it seems both CVE's for Apache did make it way to CL? And then the other big problem, Imunify is now a liability, because we cant patch with it. 

    And then when we get hacked, the response is, you need to restore from backup, shrug shoulder. This is not acceptable for the amount of money we pay every month to both companies.  

    1
  • cPRex Jurassic Moderator

    We definitely communicate, and the builds were already complete before this post.  If they are in the resting repos it won't be long now.

    0
  • gatewayza

    Still nothing an hour later. 

    0
  • YouA

    I sent a ticket to cloudlinux Ice team, may be they forget that Imunify is under their support

    1
  • gatewayza

    We are not in old times anymore, and our software suppliers need to speed up.
    https://www.securityweek.com/ai-fuels-industrial-cybercrime-as-time-to-exploit-shrinks-to-hours/amp/

    My first post was 15 hours ago for reference 

    0
  • gatewayza

    @cpRex, any update?

    0
  • cPRex Jurassic Moderator

    I've been told the packages are released the beta and can be acquired with the command you mentioned earlier in the thread.  As to when they go fully live on the CloudLinux side, I don't have any control over that.

     
     
    0
  • YouA

    Unfortunetly, after sending a ticket to cloudlinux support, it seems that the support team don't even know about the issue of updating apache in almalinux + imunify environment.

    i tried to give them all requested informations , and this is their answer:
    ---------------------------------------
    In this case, you will need to wait for updates directly from cPanel, as our team is providing a fix for this CVE only for servers using the ea-apache packages from our repositories (servers with CloudLinux).
     ---------------------------------------
    there is a huge differnece between cpanel and cloudlinux answers.

    0
  • ffeingol

    This is what I was just given by CloudLinux/Imunify support:

    yum update ea-apache24* --enablerepo=imunify360-ea-php-hardened-beta

    Can't say I'm excited about installing "beta" code, but I'm not sure we have a lot of choice.

    0
  • cPRex Jurassic Moderator

    In general, that's how CloudLinux always releases their packages - it'll be in the beta tier for a while and then in the normal repos in a couple weeks.  Even for the critical security issues like this one.

    0
  • ffeingol

    I wonder if that philosophy would change if they had dozens and dozens (prob. 100's for some people) to maintain. :-)

    0
  • net@work

    cPRex if a server have litespeed enabled and apache disabled that system urgently must make apache update to 2.4.67 or can wait cloudlinux remove the package from beta?

    0

Please sign in to leave a comment.