Security
- Security: CVE-2026-29201 - cPanel & WHM / WP2 Security Update - May 08, 2026
- Exim CVE-2026-40684, CVE-2026-40685, CVE-2026-40686, and CVE-2026-40687
- Security : CVE-2026-24072 : Apache HTTP Server: mod_rewrite elevation of privileges via ap_expr
- Security: CVE-2026-23918
- cPanel User Wildcard Certificate Overrides Dovecot Hostname SSL
- Security: CVE-2026-41940 - cPanel & WHM / WP2 Security Update 04/28/2026
- AutoSSL excludes www for new accounts
- LFD is stopped and does not start automatically after cPanel version upgrades
- Security Advisor detected processes that are running outdated executables
- Unable to include or exclude domains from AutoSSL using SSL/TLS Certificates interface
- AutoSSL Problems error appears in the account interface
- Roundcube vulnerabilities prior to version 1.6.14.
- AutoSSL certificates are not installed automatically on new domains
- SSL/TLS Status page does not show
- cPanel fails to automatically start after setting update-crypto-policies --set FUTURE
- cPanel SSL/TLS error :: SSL certificate orders require the subscription type
- The cPanel-CSF package cannot unlink webmin, csfwebmin.tgz, or uninstall.sh
- [AutoSSL] Local HTTP DCV error 404 (not found) - Incorrect DNS
- [AutoSSL] Local HTTP DCV error 404 (not found) - IPv6 Record Issue
- [AutoSSL] Local HTTP DCV error 404 (not found) - .htaccess directives
- ClamAV cannot be installed on an Ubuntu 24 server
- HTTP/1.0 Protocol Downgrade Detected
- AutoSSL ends with "global destruction; memory leak" errors
- SSLv3 is still a selectable option for SSL Minimum Protocol setting on v132.
- What are the minimum SSL protocol versions that Dovecot 2.4 accepts?
- Local Privilege Escalation Vulnerability using the Team Manager API CVE-2025-66429
- WP2: Enabling "Limit logins to verified IP addresses" option results in "Two-Factor Authentication" prompt.
- Team member password change by email blocked by cPanel password change feature being disabled
- AutoSSL fails with PKCS#1 1.5 is disabled as it is known to be vulnerable to marvin attacks
- How can I include and exclude domains for AutoSSL