CVE-2026-67401 — cPanel/WHM EmailTrack SQL Injection

Incident Report for Nexcess

Resolved

This incident has been resolved.
Posted Sep 09, 2026 - 17:24 EDT

Update

We have completed applying the security update across our hosting fleet to servers which we are able to access and patch but there still remains a subset of servers that we were unable to patch. This is partly due to End of Life software, e.g. cPanel on CentOS 6. Customers whose servers we were unable to patch should review their servers and ensure that their servers are running one of the following patched versions of cPanel:

v11.110.0.143
v11.134.0.55
v11.136.0.39
v11.138.0.4
WP2: v11.138.1.9

Any version of cPanel which is not running one of these versions is vulnerable and should be updated.

cPanel can be updated by using the following steps:
https://docs.cpanel.net/whm/cpanel/upgrade-to-latest-version/

For the customers on CentOS 6 (or older) we strongly suggest migrating to an Alma 9 server in order to receive future security patches
Posted Sep 09, 2026 - 17:23 EDT

Monitoring

The security patch for CVE-2026-67401 is being applied across the affected hosting fleet.

Our teams continue to monitor the environment and validate the patched systems. We have not observed any new issues since our last update.

We will provide further updates as needed. Thank you for your patience and understanding.
Posted Sep 09, 2026 - 02:00 EDT

Identified

We are currently applying the available security patches for CVE-2026-67401 across our hosting fleet.
Our teams are proactively triggering manual cPanel updates on affected servers in order to bring them to a patched version.
We are continuing to work through the affected fleet and will provide additional updates as remediation progresses.
Posted Sep 08, 2026 - 18:02 EDT

Investigating

We are currently evaluating the impact of the recently released CVE-2026-67401 — cPanel/WHM EmailTrack SQL Injection and its impact on our hosting fleet.

This vulnerability impacts all versions of cPanel.

It is patched in the following versions of cPanel
v11.110.0.143
v11.134.0.55
v11.136.0.39
v11.138.0.4
WP2: v11.138.1.9
Posted Sep 08, 2026 - 14:51 EDT
This incident affected: CPanel.