Liquid Web Status · History · Incident #7050

RESOLVED

CVE-2026-67401 — cPanel/WHM EmailTrack SQL Injection

Minor · Started Sep 8, 2026 · 2:52 PM

  • Duration

    1d 2h 31m

  • Severity

    Minor

  • Detection lead

  • User reports

Summary

CVE-2026-67401 — cPanel/WHM EmailTrack SQL Injection

This incident has been resolved.


  • Started

    Sep 8, 2026 · 2:52 PM

  • Resolved

    Sep 9, 2026 · 5:24 PM

  • Duration

    1d 2h 31m

  • Severity

    None

Event timeline

How this incident unfolded

  • Investigating

    Sep 8 · 2:52 PM Liquid Web

    We are currently evaluating the impact of the recently released CVE-2026-67401 — cPanel/WHM EmailTrack SQL Injection and its impact on our hosting fleet. This vulnerability impacts all versions of cPanel. It is patched in the following versions of cPanel v11.110.0.143 v11.134.0.55 v11.136.0.39 v11.138.0.4 WP2: v11.138.1.9

  • Identified

    Sep 8 · 6:02 PM Liquid Web

    We are currently applying the available security patches for CVE-2026-67401 across our hosting fleet. Our teams are proactively triggering manual cPanel updates on affected servers in order to bring them to a patched version. We are continuing to work through the affected fleet and will provide additional updates as remediation progresses.

  • Monitoring

    Sep 9 · 1:59 AM Liquid Web

    The security patch for CVE-2026-67401 is being applied across the affected hosting fleet. Our teams continue to monitor the environment and validate the patched systems. We have not observed any new issues since our last update. We will provide further updates as needed. Thank you for your patience and understanding.

  • Monitoring

    Sep 9 · 5:24 PM Liquid Web

    We have completed applying the security update across our hosting fleet to servers which we are able to access and patch but there still remains a subset of servers that we were unable to patch. This is partly due to End of Life software, e.g. cPanel on CentOS 6. Customers whose servers we were unable to patch should review their servers and ensure that their servers are running one of the following patched versions of cPanel: v11.110.0.143 v11.134.0.55 v11.136.0.39 v11.138.0.4 WP2: v11.138.1.9 Any version of cPanel which is not running one of these versions is vulnerable and should be updated. cPanel can be updated by using the following steps: https://docs.cpanel.net/whm/cpanel/upgrade-to-latest-version/ For the customers on CentOS 6 (or older) we strongly suggest migrating to an Alma 9 server in order to receive future security patches

  • Resolved

    Sep 9 · 5:24 PM Liquid Web

    This incident has been resolved.

Get alerted before the next Liquid Web outage.

Pulsetic catches degradations minutes before vendors acknowledge them.