Ugggh this one is going to suck. cPanel is everywhere and most are not patched frequently.
Post
@mttaggart ooooh, that's a bad one. Good thing I ditched cPanel/WHM after they started jacking prices and imposing new, arbitrary limitations
@mttaggart cPanel has shipped with automatic updates enabled for a very long time. Typically, when systems don't update, either the administrator turned them off, or some piece of critical software supplied by the distro is so obsolete that the newer cPanel releases do not support it anymore.
@mttaggart
Before the patches were released, the recommended emergency fix was to firewall off all the login ports: WHM, cPanel, and a few others (including Webmail).
Those login services are independent of the main httpd that serves up the hosted websites, and they must share a similar code base, with the same vulnerabilities.