Live / Incidents / Liquid Web
Liquid Web: CVE-2026-67401 — cPanel/WHM EmailTrack SQL Injection
Liquid Web · liquidweb.comImpact: noneResolved2026-09-09 05:59 UTC
Public — what happened
Summary
The security patch for CVE-2026-67401 is being applied across the affected hosting fleet.
Our teams continue to monitor the environment and validate the patched systems. We have not observed any new issues since our last update.
We will provide further updates as needed. Thank you for your patience and understanding.
Timeline
- Started — 2026-09-08 18:52 UTC
- Last update — 2026-09-09 05:59 UTC
- Resolved — 2026-09-09 21:27 UTC
With SquidGrid — where it starts on the route
Independent path health
The status page is the symptom. SquidGrid measures the paths that reach Liquid Web against their own baselines — whether the routes carrying your traffic degraded, at which handoff, and who owns that stretch.
🔒 Sign in to seeCustomers get the live Provider Assessment Report for Liquid Web: its full incident track record, what tends to break, and recent public reports of problems.
Included with any paid plan.
Open the Liquid Web report →