cPanel has released a security update to address CVE-2026-58048, a database privilege escalation vulnerability affecting supported cPanel & WHM versions. We strongly recommend that all customers update their servers to the patched versions available.
Please refer to the official advisories below for more details:
Please log in to your server via SSH as the root user and run the following command:
/scripts/upcp
This command will download and install the latest available cPanel & WHM updates, including the security fixes released by cPanel.
After the update completes, verify your cPanel version:
/usr/local/cpanel/cpanel -V
Why This Update required
This security release addresses a vulnerability that could allow privilege escalation within the database environment. Applying the latest cPanel update is the recommended mitigation from cPanel and helps protect your server from potential exploitation.
If you are unable to perform the update or experience any issues during the upgrade process, please contact our support team. We will be happy to assist you.
Aug 03, 2026 - 20:31 AEST
Resolved -
This incident has been resolved.
Aug 12, 21:44 AEST
Monitoring -
Dear Customer,
We are writing to share an important update regarding the evolving landscape of security patching.
Microsoft has recently announced that due to advancements in AI-driven security research, the volume and frequency of security updates both on the regular Patch Tuesday schedule and through occasional out-of-band releases are increasing.
As the frequency of updates increases, keeping your operating systems and software current is more critical than ever. To ensure your Windows Dedicated Server environment remains secure, we ask that you be prepared to manage and apply security patches to your servers promptly as they are released. Staying current with these updates is essential to protecting your infrastructure against emerging threats.
To help maintain the security and stability of your environment, we recommend the following best practices:
Review and apply the latest Windows security updates and patches as soon as practical after their release to address known vulnerabilities and security risks; and
Strengthen your security posture by enabling Multi-Factor Authentication (MFA/2FA), using dedicated administrative accounts, limiting privileged access, and implementing other recommended security controls.
These measures can significantly reduce the risk of compromise and help maintain the security of your systems.
Please note that the Microsoft patch release will require a server reboot for the updates to be fully applied. After installing the patches, kindly ensure that the server is restarted at the earliest opportunity to complete the update process and avoid any pending update-related issues.'’’
Should you have any questions or need further assistance, please feel free to reach out to our Support team.
Jul 3, 19:59 AEST