Emergency server help: get in touch

CSF Fork 2026: Which Reliable Replacement After ConfigServer?

A comparison of the maintained CSF forks a year after ConfigServer closed, covering who maintains each one, which panels and operating systems they target, how they update, and which one fits a given fleet.

Published Updated 6 min read

ConfigServer stopped trading on 31 August 2025 and CSF v15.00 was the last release from the original author, relicensed under GPLv3 on the way out. Nothing broke that day, but the update channel went silent, and the 2026 CVE cycle proved that an unmaintained firewall wrapper with a web-facing Messenger component is a liability. A year on there are four forks worth taking seriously, and the right one depends mostly on which control panel is underneath.

Applies to cPanel CSF fork 16.31+, DirectAdmin CSF 15.05, Aetherinox csf-firewall 15.10, Sentinel Firewall

Short answer: Match the fork to the panel. cPanel servers should be on the cPanel fork (cpanel-csf RPM, 16.31 or later, updated by upcp), DirectAdmin servers on DirectAdmin’s 15.05 tarball from its file server, panel-free, CyberPanel and Webmin hosts on Aetherinox csf-firewall, and Ubuntu or Debian servers on Sentinel Firewall. Anything still reporting the original v15.00 has no fix for CVE-2026-65638 and CVE-2026-65639 and should be migrated this week.

What actually changed when ConfigServer closed

CSF is a Perl wrapper around iptables (or iptables-nft) plus the LFD daemon that tails logs and blocks brute force. The code kept working; what stopped was the csf -u update source, the blocklist curation and, critically, security fixes. When CVE-2026-65638 and CVE-2026-65639 landed in August 2026, anyone still on a stock v15.00 install had no upstream to pull a patch from. That is the whole argument for picking a fork now rather than later.

Check what you are running before deciding anything:

csf -v
rpm -q cpanel-csf 2>/dev/null || ls -la /etc/csf/version.txt
grep -E '^(MESSENGER|URLGET|AUTO_UPDATES) ' /etc/csf/csf.conf

The cPanel fork

cPanel published its own fork in early 2026 and, on 18 February 2026, redirected the update endpoint so that any CSF 14 or newer install with AUTO_UPDATES = "1" on a cPanel server was moved across automatically. It ships as an RPM (cpanel-csf), is versioned 16.x, and its stated policy is security fixes only, no new features. That is the right posture for a firewall. The 16.30 and 16.31 builds in September 2026 fixed the Messenger and URLGET flaws.

Pick this one if the server runs cPanel. Do not try to install it on anything else; it is packaged for cPanel’s repositories and assumes cPanel paths. If a cPanel server somehow missed the redirect, /scripts/autorepair cpanel_csf_install brings it in line. Our guide on migrating to the cPanel CSF fork covers the verification steps.

The DirectAdmin fork

DirectAdmin maintains v15.05 as a tarball on its own file server and mirrors the work on GitHub. It stays close to the original codebase, which means fewer surprises for anyone with a decade of csf.conf muscle memory. Notable additions are OpenSSH 9.8 log-format parsing (the original v15.00 missed logins from newer sshd builds) and compatibility fixes for the current CustomBuild layout. DirectAdmin also changed some defaults in the panel integration, notably LF_INTEGRITY = "0" and PT_LIMIT = "0", so review those after install.

Pick this one for DirectAdmin servers. It works elsewhere, but the panel integration and testing effort go into DirectAdmin.

Aetherinox csf-firewall

This is the most active community fork and the one to choose for servers with no panel, or with CyberPanel or Webmin. Version 15.10 (February 2026) rewrote the cron and update handling, added a wrapper that speaks both iptables and nftables, and hosts its own update server under configserver.dev. It supports cPanel and DirectAdmin too, but on those panels you are trading vendor integration for faster feature work, and for a firewall that is usually the wrong trade.

The nftables-aware wrapper matters on EL10, where ipset handling is broken under the compat shim; see CSF on AlmaLinux 10 for the details.

Sentinel Firewall

Sentinel, from the OpenPanel project, is a drop-in replacement rather than a fork in the strict sense: it reads the same csf.conf, csf.allow and csf.deny files and accepts the same command-line flags, so scripts and runbooks keep working. It targets Ubuntu 22.04 through 25.x, Debian 12 and 13, and EL 8 through 10. It is the best fit for Debian-family servers, where the original CSF was always second-class, and we cover installation in Installing Sentinel Firewall.

Smaller forks, and staying on 15.00. Black-HOST, nkyo and the centminmod project all carry patched copies. They are fine for a single server run by the person who reads their commit log, and wrong for a fleet, because there is no commitment to security releases. Staying on the original v15.00 is not an option at all: it is vulnerable to CVE-2026-65638 when Messenger is enabled and to CVE-2026-65639 when remote lists are fetched, and nobody will fix it.

If you would rather leave CSF behind entirely, the realistic alternatives are Imunify360 (CloudLinux published a migration tool in September 2025), firewalld with fail2ban, CrowdSec, or nftables-native products such as VistoShield. Our post-CSF stack comparison weighs those up.

Decision summary

  • cPanel: the cPanel fork, delivered by RPM, kept current by upcp.
  • DirectAdmin: the DirectAdmin v15.05 fork from the DirectAdmin file server.
  • No panel, CyberPanel, Webmin: Aetherinox csf-firewall.
  • Ubuntu or Debian, any panel: Sentinel Firewall.
  • Anything still reporting v15.00 or lower: treat as unpatched and migrate this week.

A common pitfall is running two of these at once after an experiment, which leaves duplicate cron jobs and two LFD processes fighting over the chain. Before installing any fork, run csf -x and the uninstall script of whatever is present, then confirm pgrep -a lfd returns nothing.

Verify

After the move, confirm the version and the update path in one pass:

csf -v
csf -c
grep -E '^(AUTO_UPDATES|MESSENGER|URLGET) ' /etc/csf/csf.conf
systemctl status csf lfd --no-pager

csf -c should report that you are on the latest version for that fork, and MESSENGER should read "0" unless you have deliberately re-enabled it on a build of 16.31 or later. Record the fork and version in your server inventory so the next audit, or our server security audit script, can flag stragglers.

CSF fork 2026 at a glance

CSF Fork 2026 summary card: Match the fork to the panel. cPanel servers should be on the cPanel fork (cpanel-csf RPM, 16.31 or later, updated by…
In short: Match the fork to the panel. cPanel servers should be on the cPanel fork (cpanel-csf RPM, 16.31 or later, updated by upcp), DirectAdmin servers on DirectAdmin’s 15.05 tarball from its file server, panel-free, CyberPanel and Webmin hosts on…

Official documentation: DirectAdmin documentation, cPanel & WHM documentation, AlmaLinux wiki.

Related guides: KernelCare on cPanel and DirectAdmin servers: setup, verification and rollback · Replacing cxs: malware scanning with LMD (maldet), ClamAV and ImunifyAV on hosting servers · Incident response after a cPanel root-escalation CVE: rotating keys, hunting .sorry, auditing sessions.

Frequently asked questions

Does the original CSF v15.00 still work after ConfigServer closed?

It runs, but it receives no updates and is vulnerable to CVE-2026-65638 when Messenger is enabled and CVE-2026-65639 when remote lists are fetched, so it must be treated as unpatched and replaced with a maintained fork.

How long does switching from one CSF fork to another take?

Under an hour per server: run csf -x, uninstall the current copy, confirm pgrep -a lfd is empty, install the new fork and restore csf.conf, csf.allow and csf.deny, then verify with csf -v and csf -c.

Can I install the cPanel CSF fork on a DirectAdmin or plain Linux server?

No. It is packaged for cPanel’s repositories and assumes cPanel paths; use the DirectAdmin fork, Aetherinox csf-firewall or Sentinel on other systems.

Maintenance record

This guide changes servers, data or security settings, so we re-check it against current versions on a fixed schedule. Take a backup or snapshot before you start.

Maintained by
srvScripts editorial team
Supported versions
cPanel CSF fork 16.31+, DirectAdmin CSF 15.05, Aetherinox csf-firewall 15.10, Sentinel Firewall
Last full review
Next review

Free website test

Is your website set up right?

Check SSL, security headers, redirects, robots.txt, sitemap, llms.txt and security.txt in one test. It takes about 30 seconds.