CVE-2026-67401 — cPanel/WHM EmailTrack SQL Injection

Incident Report for Liquid Web - Services

Monitoring

The security patch for CVE-2026-67401 is being applied across the affected hosting fleet.

Our teams continue to monitor the environment and validate the patched systems. We have not observed any new issues since our last update.

We will provide further updates as needed. Thank you for your patience and understanding.
Posted Sep 09, 2026 - 01:59 EDT

Identified

We are currently applying the available security patches for CVE-2026-67401 across our hosting fleet.
Our teams are proactively triggering manual cPanel updates on affected servers in order to bring them to a patched version.
We are continuing to work through the affected fleet and will provide additional updates as remediation progresses.
Posted Sep 08, 2026 - 18:02 EDT

Investigating

We are currently evaluating the impact of the recently released CVE-2026-67401 — cPanel/WHM EmailTrack SQL Injection and its impact on our hosting fleet.

This vulnerability impacts all versions of cPanel.

It is patched in the following versions of cPanel
v11.110.0.143
v11.134.0.55
v11.136.0.39
v11.138.0.4
WP2: v11.138.1.9
Posted Sep 08, 2026 - 14:52 EDT
This incident affects: CPanel.