Use cases
Software Products E-commerce MSPs Schools Development & Marketing DevOps Agencies Help Desk
Company
Internet Status Blog Pricing Log in Get started free

Outage in Liquid Web

CVE-2026-67401 — cPanel/WHM EmailTrack SQL Injection

Resolved Minor
September 08, 2026 - Started 23 days ago - Lasted 1 day
Official incident page

Incident Report

Summary AI Generated

Liquid Web identified a SQL injection vulnerability (CVE-2026-67401) in cPanel/WHM's EmailTrack feature affecting all cPanel versions across their hosting fleet. The team proactively applied security patches by manually triggering cPanel updates on affected servers to bring them to a remediated version. The incident lasted approximately 26.5 hours before being fully resolved, with no new issues observed following patching.

We are currently evaluating the impact of the recently released CVE-2026-67401 — cPanel/WHM EmailTrack SQL Injection and its impact on our hosting fleet. This vulnerability impacts all versions of cPanel. It is patched in the following versions of cPanel v11.110.0.143 v11.134.0.55 v11.136.0.39 v11.138.0.4 WP2: v11.138.1.9
Components affected
Liquid Web CPanel

Trusted by 1,000+ teams

The Status Page Aggregator with Early Outage Detection

Stop finding out about outages from your users. Monitor 6,320+ cloud services and get alerted the second something breaks.

IsDown status aggregator dashboard
Latest Updates ( sorted recent to last )
RESOLVED 21 days ago - at 09/09/2026 09:24PM

This incident has been resolved.

MONITORING 22 days ago - at 09/09/2026 05:59AM

The security patch for CVE-2026-67401 is being applied across the affected hosting fleet.

Our teams continue to monitor the environment and validate the patched systems. We have not observed any new issues since our last update.

We will provide further updates as needed. Thank you for your patience and understanding.

IDENTIFIED 22 days ago - at 09/08/2026 10:02PM

We are currently applying the available security patches for CVE-2026-67401 across our hosting fleet.
Our teams are proactively triggering manual cPanel updates on affected servers in order to bring them to a patched version.
We are continuing to work through the affected fleet and will provide additional updates as remediation progresses.

INVESTIGATING 23 days ago - at 09/08/2026 06:52PM

We are currently evaluating the impact of the recently released CVE-2026-67401 — cPanel/WHM EmailTrack SQL Injection and its impact on our hosting fleet.

This vulnerability impacts all versions of cPanel.

It is patched in the following versions of cPanel
v11.110.0.143
v11.134.0.55
v11.136.0.39
v11.138.0.4
WP2: v11.138.1.9

The Status Page Aggregator with Early Outage Detection

With IsDown, you can monitor all your critical services' official status pages from one centralized dashboard and receive instant alerts the moment an outage is detected. Say goodbye to constantly checking multiple sites for updates and stay ahead of outages with IsDown.

Start free trial

No credit card required · Cancel anytime · 6320 services available

Integrations with Slack Microsoft Teams Google Chat Datadog PagerDuty Zapier Discord Webhook