Liquid Web incident

CVE-2026-67401 — cPanel/WHM EmailTrack SQL Injection

Notice Resolved View vendor source →

Liquid Web experienced a notice incident on September 8, 2026 affecting CPanel, lasting 1d 2h. The incident has been resolved; the full update timeline is below.

Started
Sep 08, 2026, 06:52 PM UTC
Resolved
Sep 09, 2026, 09:24 PM UTC
Duration
1d 2h
Detected by Pingoru
Sep 08, 2026, 06:52 PM UTC

Affected components

CPanel

Update timeline

  1. investigating Sep 08, 2026, 06:52 PM UTC

    We are currently evaluating the impact of the recently released CVE-2026-67401 — cPanel/WHM EmailTrack SQL Injection and its impact on our hosting fleet. This vulnerability impacts all versions of cPanel. It is patched in the following versions of cPanel v11.110.0.143 v11.134.0.55 v11.136.0.39 v11.138.0.4 WP2: v11.138.1.9

  2. identified Sep 08, 2026, 10:02 PM UTC

    We are currently applying the available security patches for CVE-2026-67401 across our hosting fleet. Our teams are proactively triggering manual cPanel updates on affected servers in order to bring them to a patched version. We are continuing to work through the affected fleet and will provide additional updates as remediation progresses.

  3. monitoring Sep 09, 2026, 05:59 AM UTC

    The security patch for CVE-2026-67401 is being applied across the affected hosting fleet. Our teams continue to monitor the environment and validate the patched systems. We have not observed any new issues since our last update. We will provide further updates as needed. Thank you for your patience and understanding.

  4. monitoring Sep 09, 2026, 09:24 PM UTC

    We have completed applying the security update across our hosting fleet to servers which we are able to access and patch but there still remains a subset of servers that we were unable to patch. This is partly due to End of Life software, e.g. cPanel on CentOS 6. Customers whose servers we were unable to patch should review their servers and ensure that their servers are running one of the following patched versions of cPanel: v11.110.0.143 v11.134.0.55 v11.136.0.39 v11.138.0.4 WP2: v11.138.1.9 Any version of cPanel which is not running one of these versions is vulnerable and should be updated. cPanel can be updated by using the following steps: https://docs.cpanel.net/whm/cpanel/upgrade-to-latest-version/ For the customers on CentOS 6 (or older) we strongly suggest migrating to an Alma 9 server in order to receive future security patches

  5. resolved Sep 09, 2026, 09:24 PM UTC

    This incident has been resolved.