Security
- [AutoSSL] Local HTTP DCV error 404 (not found) - Incorrect DNS
- [AutoSSL] Local HTTP DCV error 404 (not found) - IPv6 Record Issue
- [AutoSSL] Local HTTP DCV error 404 (not found) - .htaccess directives
- ClamAV cannot be installed on an Ubuntu 24 server
- HTTP/1.0 Protocol Downgrade Detected
- Vulnerability in AccelerateWP component in cPanel on CloudLinux OS
- AutoSSL ends with "global destruction; memory leak" errors
- SSLv3 is still a selectable option for SSL Minimum Protocol setting on v132.
- What are the minimum SSL protocol versions that Dovecot 2.4 accepts?
- Local Privilege Escalation Vulnerability using the Team Manager API CVE-2025-66429
- WP2: Enabling "Limit logins to verified IP addresses" option results in "Two-Factor Authentication" prompt.
- Team member password change by email blocked by cPanel password change feature being disabled
- AutoSSL fails with PKCS#1 1.5 is disabled as it is known to be vulnerable to marvin attacks
- How can I include and exclude domains for AutoSSL
- Webmail does not login to inbox after enabling two-factor authentication
- Unable to export private GnuPG secret key when using non-default server locale.
- AWStats vulnerability PTT-2025-021
- Error when using API function: “500 Security Policy requires exec termination.”
- Imunify360's Exim+Dovecot brute-force attack protection module erroring due to latest dovecot updates
- Two-factor Authentication (2FA) is reported as removed when using Team User.
- Security Advisor reports MySQL is configured to listen on all interfaces when using Imunify360 to close all ports except specified
- Does cPanel have any plans regarding the closure announcement of ConfigServer Services?
- How to stop ImunifyAV
- Rules are added to cpanel-dovecot-solr firewall chain each time service is restarted
- Service subdomains can still be accessed when port is blocked
- Multiple SSLs can be installed on service subdomain when added as an addon domain
- Hostname history can prevent the current hostname's SSL certificate from being obtained when the previously used hostname's domain is rate-limited.
- cPHulk chain is not added to INPUT filter in nftables, resulting in the cPHulk Firewall chain not blocking any IPs
- Mailman 2.1.39 - CVE-2025-43919, CVE-2025-43920, CVE-2025-43921
- Which ports should I open on a DNSOnly server?