Security
- Webmail does not login to inbox after enabling two-factor authentication
- Unable to export private GnuPG secret key when using non-default server locale.
- AWStats vulnerability PTT-2025-021
- Error when using API function: “500 Security Policy requires exec termination.”
- Imunify360's Exim+Dovecot brute-force attack protection module erroring due to latest dovecot updates
- Two-factor Authentication (2FA) is reported as removed when using Team User.
- Security Advisor reports MySQL is configured to listen on all interfaces when using Imunify360 to close all ports except specified
- Does cPanel have any plans regarding the closure announcement of ConfigServer Services?
- How to stop ImunifyAV
- Rules are added to cpanel-dovecot-solr firewall chain each time service is restarted
- Service subdomains can still be accessed when port is blocked
- Multiple SSLs can be installed on service subdomain when added as an addon domain
- Hostname history can prevent the current hostname's SSL certificate from being obtained when the previously used hostname's domain is rate-limited.
- cPHulk chain is not added to INPUT filter in nftables, resulting in the cPHulk Firewall chain not blocking any IPs
- Mailman 2.1.39 - CVE-2025-43919, CVE-2025-43920, CVE-2025-43921
- Which ports should I open on a DNSOnly server?
- How to disable the ConfigServer Exploit Scanner (CXS) ModSecurity rules
- cpanel-p0f package is marked as malicious by some Antivirus Vendors
- SSL expiry notifications are sent before renewal is attempted
- How to deny access to WHM via Host Access Control on a RHEL-based server
- cpsrvd Returns 200 Response Code on all URLs
- How to determine the SSL certificate issuer from cPanel
- Checkallsslcerts fails with "400 (Bad Request)" for all service subdomains when using remote DNS
- AutoSSL can't issue certificates: REC_LAME
- Is there a patch for the Exim vulnerability CVE-2024-39929?
- How do I install an SSL for my hostname for the Apache service?
- Can TLS 1.1 or 1.0 be enabled on RHEL 9-based servers?
- Can't renew hostname SSL: The domainNames argument is invalid
- When will Sectigo be deprecated and removed from cPanel?
- AutoSSL error: 403 urn:ietf:params:acme:error:unauthorized (The client lacks sufficient authorization) when using Cloudflare