Critical security update for CloudLinux users running EasyApache 4
β οΈ Security Alert
A critical vulnerability (CVE-2026-23918) has been identified in Apache, affecting servers not running the latest patched version.
If you are using CloudLinux with EasyApache 4, immediate action is required to secure your server.
The patched version ea-apache24-2.4.67 may not yet be available in default repositories.
CloudLinux provides a workaround using the cl-ea4-testing repository.
π§ CloudLinux Fix
Run the following command to update Apache using the testing repository:
π‘οΈ Imunify360 (Non-CloudLinux) Fix
If your server is not using CloudLinux but has Imunify360 with ea-php-hardened, you can update Apache using the hardened beta repository:
This repository provides patched packages before they are available in stable repositories.
β Verify Apache Version
After updating, confirm your Apache version:
Expected output: Apache/2.4.67 or later
π¨ Why This Update is Critical
Servers running outdated Apache versions remain vulnerable to remote exploits. Delaying this update can expose your hosting environment to serious security risks.
π Official Advisory
For detailed technical information, refer to the CloudLinux advisory.
View Security Advisory