<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Security Announcements Archives - MediaCP</title>
	<atom:link href="https://www.mediacp.net/category/security-announcements/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.mediacp.net/category/security-announcements/</link>
	<description>Media Control Panel</description>
	<lastBuildDate>Fri, 13 Feb 2026 03:25:53 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.9.7</generator>

<image>
	<url>https://www.mediacp.net/wp-content/uploads/2025/07/IconSquare-Transparent-150x150.png</url>
	<title>Security Announcements Archives - MediaCP</title>
	<link>https://www.mediacp.net/category/security-announcements/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Security Advisory [All Versions]</title>
		<link>https://www.mediacp.net/news/2026-02-12-security-advisory-all-versions/</link>
		
		<dc:creator><![CDATA[Matt]]></dc:creator>
		<pubDate>Thu, 12 Feb 2026 05:37:39 +0000</pubDate>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Security Announcements]]></category>
		<guid isPermaLink="false">https://www.mediacp.net/?p=33395</guid>

					<description><![CDATA[<p>Several critical XSS security issues have been identified that affects all versions of MediaCP Audio and Video Panel. The security vulnerabilities may allow an unauthorized attacker to gain admin access to the MediaCP software. We have published new minor updates to the LTS, Stable, and Latest release tiers and urge all customers to upgrade MediaCP [&#8230;]</p>
<p>The post <a href="https://www.mediacp.net/news/2026-02-12-security-advisory-all-versions/">Security Advisory [All Versions]</a> appeared first on <a href="https://www.mediacp.net">MediaCP</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>Several critical XSS security issues have been identified that affects all versions of MediaCP Audio and Video Panel.</p>



<p>The security vulnerabilities may allow an unauthorized attacker to gain admin access to the MediaCP software.</p>



<p>We have published new minor updates to the <a href="https://www.mediacp.net/doc/admin-server-manual/install/versions-releases/">LTS, Stable, and Latest release tiers</a> and urge all customers to <a href="https://www.mediacp.net/doc/admin-server-manual/install/upgrade-guide/">upgrade MediaCP </a>immediately. </p>



<p class="has-luminous-vivid-amber-background-color has-background"><strong>Severity: </strong>Critical<br><strong>Versions Affected:</strong> &lt;= 2.13.13, &lt;= 2.14.8, &lt;= 2.15.1<br><strong>References: MCP-2970, MCP-2969</strong></p>



<h2 class="wp-block-heading">What should I do?</h2>



<p>You should <a href="https://www.mediacp.net/doc/admin-server-manual/install/upgrade-guide/">upgrade MediaCP immediately</a>, as soon as possible.</p>



<p>If you are unable to upgrade due to an unsupported operating system we do have two hot-fixes available for 2.13.x and 2.14.x</p>



<h4 class="wp-block-heading">2.13.x Hot-fix:</h4>



<ol class="wp-block-list">
<li>Access your server over SSH as the root user </li>



<li>Run<code> the following to apply the hot-fix</code></li>
</ol>



<pre class="wp-block-preformatted">bash &lt;(curl -s https://mirror.mediacp.net/download/hotfix/MCP-2969-2970-2980-21314.txt?v1)</pre>



<h4 class="wp-block-heading">2.14.x Hot-fix:</h4>



<ol class="wp-block-list">
<li>Access your server over SSH as the root user </li>



<li>Run<code> the following to apply the hot-fix</code></li>
</ol>



<pre class="wp-block-preformatted">bash &lt;(curl -s https://mirror.mediacp.net/download/hotfix/MCP-2969-2970-2980-2149.txt?v2)</pre>



<h2 class="wp-block-heading">Can the hot-fix be applied to earlier versions?</h2>



<p>The hot-fixes are built specifically for the currently supported releases of 2.13, 2.14, and 2.15 and may not be compatible. We do not recommend applying the hot-fix to versions earlier than 2.13.</p>



<h2 class="wp-block-heading">Release Notes:</h2>



<ul class="wp-block-list">
<li><a href="https://www.mediacp.net/release-notes/mediacp-2-13-14-release-notes/">MediaCP 2.13.14 Release Notes</a></li>



<li><a href="https://www.mediacp.net/news/mediacp-2-14-9-release-notes/">MediaCP 2.14.9 Release Notes</a></li>



<li><a href="https://www.mediacp.net/release-notes/mediacp-2-15-2-release-notes/">MediaCP 2.15.2 Release Notes</a></li>
</ul>



<p></p>
<p>The post <a href="https://www.mediacp.net/news/2026-02-12-security-advisory-all-versions/">Security Advisory [All Versions]</a> appeared first on <a href="https://www.mediacp.net">MediaCP</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Wowza log4j2 security vulnerability</title>
		<link>https://www.mediacp.net/security-announcements/security-wowza-log4j2-security-vulnerability/</link>
		
		<dc:creator><![CDATA[Matt]]></dc:creator>
		<pubDate>Thu, 16 Dec 2021 06:37:46 +0000</pubDate>
				<category><![CDATA[Security Announcements]]></category>
		<category><![CDATA[News]]></category>
		<guid isPermaLink="false">https://www.mediacp.net/?p=13493</guid>

					<description><![CDATA[<p>Severity: CriticalVersions: Wowza Streaming Engine &#62;= 4.8.8.01Exploit type: Apache Log4j2 security vulnerability (CVE-2021-44228 &#38; CVE-2021-45046) A zero-day exploit affecting the popular&#160;Apache Log4j utility&#160;(CVE-2021-44228) was made public on December 9, 2021 that results in remote code execution (RCE). This vulnerability is actively being exploited and anyone using Log4j should update to version 2.15.0 as soon as [&#8230;]</p>
<p>The post <a href="https://www.mediacp.net/security-announcements/security-wowza-log4j2-security-vulnerability/">Wowza log4j2 security vulnerability</a> appeared first on <a href="https://www.mediacp.net">MediaCP</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="has-white-color has-vivid-red-background-color has-text-color has-background"><strong>Severity: </strong>Critical<br><strong>Versions:</strong> Wowza Streaming Engine &gt;= 4.8.8.01<br><strong>Exploit type:</strong> Apache Log4j2 security vulnerability (CVE-2021-44228 &amp; CVE-2021-45046)</p>



<p>A zero-day exploit affecting the popular&nbsp;<a href="https://logging.apache.org/log4j/2.x/index.html" target="_blank" rel="noreferrer noopener">Apache Log4j utility</a>&nbsp;(<a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-44228" target="_blank" rel="noreferrer noopener">CVE-2021-44228</a>) was made public on December 9, 2021 that results in remote code execution (RCE). This vulnerability is actively being exploited and anyone using Log4j should update to version 2.15.0 as soon as possible.</p>



<p>Logging in Wowza Streaming Engine 4.8.8.01 and later uses a version of Apache Log4j2 with a security vulnerability (CVE-2021-44228) involving JNDI functionality that is not protected against attacker-controlled LDAP and other JNDI-related endpoints.</p>



<p>If you have Wowza Streaming Engine installed on your system, you should immediately apply the update patch. If you do not have Wowza Streaming Engine installed then no action is required.</p>



<h2 class="wp-block-heading"><strong>Solution</strong></h2>



<p>You can manually apply the <a href="https://www.wowza.com/docs/update-for-apache-log4j2-security-vulnerability">Wowza update to fix the Apache Log4j2 security vulnerability</a> or run the following command to apply all steps automatically.</p>



<pre class="wp-block-preformatted">sh -c "$(curl -sSL https://mirror.mediacp.net/download/hotfix/WSE-log4j2-patch.txt)"</pre>
<p>The post <a href="https://www.mediacp.net/security-announcements/security-wowza-log4j2-security-vulnerability/">Wowza log4j2 security vulnerability</a> appeared first on <a href="https://www.mediacp.net">MediaCP</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>DST Root CA X3 Expiration and Let&#8217;s Encrypt (Sep 2021)</title>
		<link>https://www.mediacp.net/news/dst-root-ca-x3-expiration-and-lets-encrypt/</link>
		
		<dc:creator><![CDATA[Matt]]></dc:creator>
		<pubDate>Mon, 04 Oct 2021 00:43:56 +0000</pubDate>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Security Announcements]]></category>
		<category><![CDATA[letsencrypt]]></category>
		<category><![CDATA[autossl]]></category>
		<category><![CDATA[certificate]]></category>
		<category><![CDATA[ssl]]></category>
		<category><![CDATA[root ca]]></category>
		<category><![CDATA[ssl expired]]></category>
		<guid isPermaLink="false">https://www.mediacp.net/?p=12473</guid>

					<description><![CDATA[<p>As of September 30th, 2021, the DST Root CA X3 certificate that is used in the chain of trust for Let&#8217;s Encrypt expires causing clients that do not recognize ISRG Root X1 to fail security checks when accessing sites that use Let&#8217;s Encrypt for their SSL provider. The details about this issue can be found [&#8230;]</p>
<p>The post <a href="https://www.mediacp.net/news/dst-root-ca-x3-expiration-and-lets-encrypt/">DST Root CA X3 Expiration and Let&#8217;s Encrypt (Sep 2021)</a> appeared first on <a href="https://www.mediacp.net">MediaCP</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>As of September 30th, 2021, the DST Root CA X3 certificate that is used in the chain of trust for Let&#8217;s Encrypt expires causing clients that do not recognize ISRG Root X1 to fail security checks when accessing sites that use Let&#8217;s Encrypt for their SSL provider.</p>



<p>The details about this issue can be found <a href="https://letsencrypt.org/docs/dst-root-ca-x3-expiration-september-2021/" target="_blank" rel="noreferrer noopener">in the following post made by Let&#8217;s Encrypt about this issue</a></p>



<p>The problem is not specific to the MediaCP software and affects many users using LetsEncrypt certificates. Many <a href="https://support.cpanel.net/hc/en-us/articles/4409759316759-DST-Root-CA-X3-Expiration-and-Let-s-Encrypt" target="_blank" rel="noreferrer noopener">cPanel users are also experiencing the problem</a> are also experiencing the problem.</p>



<p>Our technical team have done some further research and we&#8217;ve written this guide on how to solve the problem on any CentOS or Debian machine.</p>



<h2 class="wp-block-heading">How to check if you are affected?</h2>



<p>Checking for the issue is simple, run the following on your MediaCP system <em>(replacing your-domain.com with your actual domain name)</em>. </p>



<pre class="wp-block-preformatted">curl https://your-domain.com:2020 &gt; /dev/null</pre>



<p>If there is a problem then you will see the error <em>&#8220;(60) SSL certificate problem: certificate has expired&#8221;</em> but do not worry, your certificate is not necessarily expired and the solution is simple.</p>



<h2 class="wp-block-heading">Workaround</h2>



<p><strong>CentOS 7+</strong></p>



<p>For servers running CentOS 7 or higher, the issue has been solved in recent operating system updates. We recommend running the following on your system as root user.</p>



<pre class="wp-block-preformatted">yum clean all;
yum -y update;
yum -y install ca-certificates;
yum -y update ca-certificates;
update-ca-trust;
</pre>



<p><strong>Debian Servers</strong></p>



<p>For Debian servers, the problem can be solved simply by running the following on your system as root:</p>



<pre class="wp-block-preformatted">mv /usr/share/ca-certificates/mozilla/DST_Root_CA_X3.crt /usr/share/ca-certificates/mozilla/DST_Root_CA_X3.crt.backup;
sudo update-ca-certificates;</pre>
<p>The post <a href="https://www.mediacp.net/news/dst-root-ca-x3-expiration-and-lets-encrypt/">DST Root CA X3 Expiration and Let&#8217;s Encrypt (Sep 2021)</a> appeared first on <a href="https://www.mediacp.net">MediaCP</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>CentOS 6 Discontinued</title>
		<link>https://www.mediacp.net/news/centos-6-discontinued/</link>
		
		<dc:creator><![CDATA[Matthew Lear]]></dc:creator>
		<pubDate>Wed, 29 Apr 2020 05:10:40 +0000</pubDate>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Security Announcements]]></category>
		<category><![CDATA[Discontinued]]></category>
		<category><![CDATA[CentOS 6]]></category>
		<category><![CDATA[CentOS 8]]></category>
		<category><![CDATA[CentOS]]></category>
		<guid isPermaLink="false">https://www.mediacp.net/?p=7696</guid>

					<description><![CDATA[<p>It has been decided that the MediaCP support for CentOS 6 will end on 10th May 2020. After this date it will not be possible to install or upgrade the MediaCP on CentOS 6. Attention Required If you are still using CentOS 6 currently then you should upgrade to CentOS 7 before this date. * [&#8230;]</p>
<p>The post <a href="https://www.mediacp.net/news/centos-6-discontinued/">CentOS 6 Discontinued</a> appeared first on <a href="https://www.mediacp.net">MediaCP</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>It has been decided that the MediaCP support for CentOS 6 will end on <strong>10th May 2020</strong>. After this date it will not be possible to install or upgrade the MediaCP on CentOS 6.</p>



<p><strong>Attention Required</strong></p>



<p>If you are still using CentOS 6 currently then you should upgrade to CentOS 7 before this date. <em>* Note CentOS 8 is not currently supported.</em></p>



<p><strong>Why will CentOS 6 no longer be supported?</strong></p>



<p>CentOS 6 will officially reach end of life in November this year meaning security patches and bug fixes will no longer be provided by CentOS.</p>



<p>Our next version, MediaCP 2.9, will introduce support for Liquidsoap version 1.4 which is not compatible with CentOS 6. For this reason we have decided to remove CentOS 6 support at the same time as we launch MediaCP 2.9.</p>



<p><strong>When will CentOS 8 be supported?</strong></p>



<p>CentOS 8 will be supported on 11th May 2020.</p>
<p>The post <a href="https://www.mediacp.net/news/centos-6-discontinued/">CentOS 6 Discontinued</a> appeared first on <a href="https://www.mediacp.net">MediaCP</a>.</p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
