CVE-2026-67401 affects cPanel & WHM EmailTrack: an authenticated account with mail permissions can reach root code execution. This is not an unauthenticated attack. The vendor published its advisory on September 8, 2026. Guide reviewed September 13.
What is the actual scope?
The cPanel advisory describes arbitrary file creation and full server control after exploitation. It provides no victim count. A vulnerable build does not prove intrusion; a patched build does not rule out an earlier compromise.
Patched versions
| Branch | Patched build |
|---|---|
| 11.110 | 11.110.0.143 |
| 11.134 | 11.134.0.55 |
| 11.136 | 11.136.0.39 |
| 11.138 | 11.138.0.4 |
| WP2 | 11.138.1.9 |
Compare within your branch. For example, 11.136.0.38 precedes the fix; 11.136.0.39 includes it. An unsupported branch needs an upgrade plan, not an assumption that omission from this table means safety.
Quick check: do you need to act?
With administrative SSH access, this version check is read-only. The first line labels the language; copy only the command.
/usr/local/cpanel/cpanel -V
Plan how your infrastructure is managed
Explore VPS Hosting and confirm the administration, licenses and backups your projects need.


- Older build: arrange the security update promptly.
- Patched build: record when it was updated and assess previous exposure.
- Shared-hosting customer: ask your provider for the installed build and patch confirmation. Updating WordPress does not update cPanel.
How to update cPanel & WHM
Check a recoverable backup, free disk space and maintenance window first. Log in to WHM as root and open cPanel → Upgrade to Latest Version. Alternatively, follow the vendor’s terminal procedure. Unlike the version check, this changes the server and may affect services during updating:
/usr/local/cpanel/scripts/upcp --force
/usr/local/cpanel/cpanel -V
Confirm successful completion and compare the resulting build. If it remains below the fix, escalate the update blocker to your administrator or provider. Then test panel access, mail delivery and representative websites.
How can you tell whether an intrusion already happened?
The cited advisory offers no quick test that certifies a clean server. Our recommended initial review is to preserve logs, investigate unfamiliar account activity and examine unexpected users, SSH keys and scheduled tasks. Suspicious changes warrant investigation; they do not independently prove this CVE was exploited.
With strong indicators, coordinate containment and evidence preservation before cleaning. Confirmed root access may require rebuilding from a trusted base and rotating secrets from a clean device: patching alone does not remove persistence.
This is separate from the domain-management vulnerability CVE-2026-65643. Do not reuse its minimum patched builds to close this incident. For infrastructure you manage yourself, explore TERAMONT VPS Hosting; migration does not replace patching and recovery checks.









