cPanel released a coordinated security update today, May 8, 2026, addressing three separate vulnerabilities in cPanel & WHM. We received advance notice of the patch yesterday evening, monitored for its release at noon EDT, and applied it across our fleet as soon as it became available.
This post summarizes what cPanel disclosed, when the patch actually landed, and what we did about it.
What cPanel Disclosed in Advance
On the evening of May 7, cPanel sent affected partners an early-warning email letting us know a security update was coming the following day at 12:00 PM EDT. The advance notice covered three CVEs being patched together: CVE-2026-29201, CVE-2026-29202, and CVE-2026-29203.
The notice specified the minimum patched build for every supported tier from 11.86 through 11.136, including the WP Squared (11.136 WP2) line. cPanel recommended performing a manual update via /scripts/upcp once the patch was made available, rather than waiting for the standard automatic update window.
Full technical details were embargoed until the patch itself was released.
Continue reading “cPanel & WHM Security Update: CVE-2026-29201, 29202, and 29203 Patched”






AutoSSL is going to change how webmasters secure data transferred to and from their sites. For the longest time SSL was an additional expense that many webmasters chose to forego as it wasn’t required for the operation of their websites. The time when not having SSL is the norm for most sites is coming to an end. Generally SSL has been reserved for usage by those that send or receive private information such as your name, address, email address, and phone number or even your credit card information.
We recently identified a bug in the latest versions of WHMCS including version 6.3.1. The bug consists of unexpected behavior when modifying a client’s product details and using the “Enter” key to submit the changes when the product is a cPanel Account. In previous versions of WHMCS you could change a field, such as the renewal price, and press “Enter” to submit the form. Over the years we had become accustomed to changing client product settings in this manner as we found it was the most efficient way to do it.