CSF Firewall v16.31 Security Update
The Centmin Mod CSF Firewall fork has been updated to v16.31, a security-focused release carrying the security fixes from the cPanel CSF fork (16.20 and 16.30-1), adapted and tested for Centmin Mod. The vulnerabilities fixed could allow an attacker to gain root access to the server, and some can be triggered without local access.
Also new in v16.31:
- Verified updates -
csf -uchecks the downloaded package against the mirror's published SHA256 checksum before installing, with TLS certificate verification enforced on all mirror fetches - Downgrade support - new
csf -udrolls back to the previous v15.02 release using the same verified download - Boot recovery - if saved firewall rules cannot be restored at boot, CSF now reports the problem and rebuilds the full ruleset from your configuration during that same boot
A follow-up v16.32 release on August 8, 2026 fixes fresh AlmaLinux 10 / Rocky Linux 10 installs, where the nft_compat, xt_conntrack and xt_multiport modules moved out of the base kernel package. CSF now detects the missing modules at start and auto-installs the matching kernel-modules-extra package.
On 132.00stable, 140.00beta01 and 141.00beta01, running cmupdate since August 25, 2026 switches you to the Centmin Mod CSF mirror with daily update checks, which auto-upgrade CSF to v16.31+. Check your version with csf -v and update manually with csf -u if you are still on an older version. See the CSF Firewall v16.31 security update announcement for details.