# What changed in cPanel 136: unified SSL, Ruby removed, Ubuntu 22.04 dropped, MariaDB 11.8

Source: https://srvscripts.com/guides/what-changed-in-cpanel-136/
Updated: 2026-10-03
Publisher: srvScripts (https://srvscripts.com/)

cPanel 136 reached the RELEASE tier in April and May 2026 and is now the version most non-LTS servers run, with 138 following in July. It is a larger change than its number suggests: several long-standing features were removed, the certificate model changed, and it is the last version that runs on Ubuntu 22.04. If you manage servers on the 134 LTS tier you will meet all of this at the next LTS jump, so it is worth understanding now. This guide lists the changes that affect operations and what to do about each.

In short: cPanel 136 merged the SSL/TLS pages into one interface and switched AutoSSL to short-lived Sectigo certificates with automatic reissue, removed Ruby on Rails and RubyGems support (a blocker if any Rails application is still registered)…

**Short answer:** cPanel 136 merged the SSL/TLS pages into one interface and switched AutoSSL to short-lived Sectigo certificates with automatic reissue, removed Ruby on Rails and RubyGems support (a blocker if any Rails application is still registered), and is the last version for Ubuntu 22.04. It also added MariaDB 11.8 to the WHM upgrade tool, bulk PHP version changes in MultiPHP Manager, consolidated PHP error logs, web log retention scripts and WP Toolkit security scores.

## Certificates: one interface and shorter lifetimes

The separate SSL/TLS pages in cPanel and WHM were merged into a single interface that installs, lists, renews and removes certificates in one place. Custom scripts and documentation that pointed to the old **SSL/TLS Manager** paths need updating; the API calls (`uapi SSL` and `whmapi1 fetch_ssl_certificates_for_fqdns` and friends) are unchanged. Our [unified SSL/TLS interface guide](/guides/cpanel-ssl-tls-interface-136/) walks through the new screens.

More significantly, AutoSSL now issues short-lived ACME certificates of roughly 200 days with automatic reissue. This tracks the CA/Browser Forum schedule that caps lifetimes at 200 days from March 2026, 100 days in 2027 and 47 days in 2029. Sectigo is the default provider; Let’s Encrypt remains available as an option. The operational consequence is that anything blocking DCV (CDN proxies, CAA records, `.htaccess` rules) now causes failures more often. The [AutoSSL troubleshooting guide](/guides/autossl-failed-cpanel-dcv-caa-cdn/) covers the cases, and our [SSL expiry check script](/scripts/ssl-expiry-check/) catches the ones that slip through.

## Removed: Ruby on Rails, RubyGems and ICQ

Ruby application support through EasyApache and the cPanel Ruby on Rails interface is gone, along with RubyGems management. If any account still has a registered Rails application, the upgrade to 136 is blocked until it is removed. Find them before scheduling the update:

```
ls /var/cpanel/userdata/*/ 2>/dev/null | grep -i rails
rpm -qa | grep -E '^ea-ruby'
```

Customers who need Ruby can run it under their own user with a version manager and proxy through Apache with a standard reverse-proxy include; the panel just no longer manages it. The ICQ field in contact settings was also removed, which affects nobody in practice but does appear in the changelog.

## Ubuntu 22.04 is the last supported release, and MariaDB 11.8 arrives

136 is the final version to run on Ubuntu 22.04. Version 138 requires 24.04. A server on 22.04 will stay on 136 and receive security builds only until 136 itself ages out. Plan the release upgrade to 24.04 before you need 138 features, and test it on a staging server first because the cPanel-specific `do-release-upgrade` sequence has more steps than a plain Ubuntu upgrade. If you are also weighing AlmaLinux, see [Ubuntu 24.04 or AlmaLinux for a new cPanel server](/guides/ubuntu-vs-almalinux-cpanel/). On the RHEL side, 136 still requires 9.5 or later on the 9 family and supports AlmaLinux 8, 9 and 10 and CloudLinux 8, 9 and 10.

**WHM » SQL Services » MySQL/MariaDB Upgrade** now offers MariaDB 11.8 (LTS until June 2028) alongside 10.11 and 11.4. The default for new installs remains 10.11. With 10.6 end of life since July 2026, servers still on 10.6 should move to 11.8 through the WHM workflow, one LTS at a time, and 12.3 is not yet offered in the panel. The [WHM MariaDB upgrade guide](/guides/upgrade-mariadb-whm-safely/) covers the preparation; the [startup failure guide](/guides/mariadb-not-starting-after-upgrade/) covers what to do if it goes wrong.

## PHP: bulk version management and consolidated logs

Two quality-of-life changes for shared hosts. MultiPHP Manager gained a bulk operation to move many domains between PHP versions in one action, which is what you want for retiring PHP 8.1 (security support ended; see [retiring PHP 8.1](/guides/retire-php-8-1-cpanel-tuxcare-els/)) and for moving customers to 8.4, which is now the mainstream EasyApache version with 8.5 available. And PHP error logging was consolidated so that each PHP-FPM pool’s errors are written to a predictable per-account location rather than scattered between the Apache error log and the site’s own log files.

Check `whmapi1 php_get_vhosts_by_version` output and the pool configuration on 136 to see the new log paths, because support staff used to grepping the Apache error log will need to look elsewhere.

## Web log retention and WP Toolkit

136 added the log retention scripts described in [managing web log retention](/guides/cpanel-apache-log-retention/), so domlog growth becomes a policy rather than a recurring disk emergency. WP Toolkit gained security risk scores, a vulnerable components view and moved wp-cron to a five-minute system cron; [our WP Toolkit guide](/guides/wp-toolkit-security-risk-score/) explains how to use them. Also note the bundled component versions: Dovecot 2.4, PHP 8.4 for cPanel’s internal use, and Roundcube 1.6.15 at release.

## Security builds and verification

136 received the emergency fix for CVE-2026-41940 on 28 April and then a series of builds through September. The current build at the end of September is around 136.0.44. Because a server can be “on 136” and still be months behind, verify the build rather than the major version; the [CVE-to-build mapping](/guides/cpanel-cve-build-numbers-2026/) has the numbers.

Before moving a server to 136, confirm the OS is supported, no Rails applications exist, and MariaDB is at least 10.6. Afterwards, run through:

```
whmapi1 version
/usr/local/cpanel/bin/autossl_check --all 2>&1 | grep -c FAILED
whmapi1 php_get_vhosts_by_version version=ea-php81 | grep -c vhost
mysql -e "SELECT VERSION()"
```

Zero AutoSSL failures, a shrinking PHP 8.1 count and a supported MariaDB version are the targets. A common pitfall is upgrading a server to 136 without checking the SSL provider setting; a server that had Let’s Encrypt configured keeps it, but a fresh install defaults to Sectigo, and mixed fleets confuse support staff. Set the provider explicitly under **Manage AutoSSL** and note it in your build standard.

## What changed in cPanel 136 at a glance

**Official documentation:** [MariaDB documentation](https://mariadb.com/docs/), [Let’s Encrypt documentation](https://letsencrypt.org/docs/), [cPanel & WHM documentation](https://docs.cpanel.net/).

**Related guides:** [Turning on Meridian, Ask AI and Nova for your users — and turning them off](https://srvscripts.com/guides/cpanel-meridian-ask-ai-nova/) · [How to install cPanel & WHM on AlmaLinux 10 (2026 checklist)](https://srvscripts.com/guides/install-cpanel-almalinux-10/) · [Fixing /scripts/upcp failures, tier blockers and “Upgrade blocked” on an unsupported OS](https://srvscripts.com/guides/cpanel-upcp-failed-upgrade-blocked/).

## Frequently asked questions

### Does cPanel 136 still support Ubuntu 22.04?

Yes, but it is the final version that does. A server on Ubuntu 22.04 stays on 136 and cannot move to 138, which requires Ubuntu 24.04, so plan the release upgrade before 136 ages out of security builds.

### Why is the upgrade to cPanel 136 blocked on my server?

The usual blocker is a registered Ruby on Rails application or installed `ea-ruby` packages, because 136 removed Ruby support. Remove the applications and packages and rerun `/scripts/upcp --force`; an unsupported operating system is the other common cause.

### Can I keep using Let’s Encrypt for AutoSSL on cPanel 136?

Yes. Sectigo is the default provider for new installs, but Let’s Encrypt remains available under Manage AutoSSL, and a server that already had it configured keeps it through the upgrade.
