We are rolling out mandatory security patches for Roundcube Webmail to address vulnerabilities identified in the recent 1.6.19 and 1.7.4 releases. Alongside this webmail patch, we are making a necessary upgrade to the default PHP environment onDirectAdmin servers.
What is changing:
Roundcube Webmail Update: The webmail client will be upgraded to version 1.7.4 to ensure all active security patches are applied.
Server Default PHP (php1) Upgrade: In DirectAdmin, the primary PHP slot (php1) acts as the server's default. Whenever a new domain or subdomain is added without explicitly choosing a PHP version, the server automatically executes that site's scripts using php1. To maintain server security and support the latest software, we are upgrading the php1 slot to PHP 8.2, which is currently the lowest actively supported PHP version if php 8.2 is not already set. If php1 is a higher version it will not be changed.
How this impacts your hosting:
Webmail Access: Roundcube may experience brief moments of downtime while the updates are applied.
Website Compatibility: If your website currently relies on the server default (php1) rather than a manually selected PHP version, it will automatically shift to PHP 8.2. Most modern sites (like updated WordPress installations) will run fine, but older scripts may require adjustment.
Alternative PHP Versions: This change only affects the default slot. Multiple PHP versions remain fully available on the servers.
Posted Sep 10, 2026 - 16:11 EDT
This scheduled maintenance affects: Services (Webhosting).