Skip to content

webmin

Server & OS Management

A web‑based Unix system administration tool for managing servers and services

HTML Latest 2.641 · 24d ago Security brief →

Features

  • Configure operating system internals (users, quotas, services, config files)
  • Manage open‑source apps like BIND, Apache, PHP, MySQL and many more
  • Extensible via standard and third‑party modules

Recent releases

View all 5 releases →
2.641 Bug fix
Notable features
  • Support for trusted proxy IP addresses
Full changelog
  • Add support for trusted proxy IP addresses
  • Fix a bug when editing monitors in the System and Server Status module
  • Fix skip hwclock when unavailable #2693
2.640 Security relevant
Security fixes
  • Fix to prevent bypassing two-factor authentication in RPC requests
  • Fix session cookies to use safer defaults
  • Fix unsafe mailbox attachment handling in Mailbox module
Notable features
  • New nftables module with profiles, saved tables, and chains/sets management
  • New Nginx module matching Apache look and feel
  • Hide sensitive values from Webmin request logs
Full changelog
  • Add new nftables module with profiles, saved tables, and chains/sets management
  • Add new Nginx module with look and feel matching the Apache module
  • Add option to hide sensitive values (like passwords or tokens) from Webmin's request logs
  • Add custom ACME server support for Webmin SSL renewal
  • Add support for the latest MariaDB on Ubuntu 26.04
  • Add multi-statement SQL query support when executing inline in MySQL/MariaDB module
  • Add support for ext4 hidden inode quota mode
  • Add used space and usage percentage reporting for ZFS in the dashboard
  • Add mass enable and disable buttons for status monitors in the System and Server Status module
  • Update tiny ACME client to the latest version
  • Update DHCP default config for openSUSE 16 #2678
  • Fix to prevent bypassing two-factor authentication in RPC requests
  • Fix session cookies to use safer defaults
  • Fix handling of connections coming through a reverse proxy
  • Fix unsafe mailbox attachment handling in Mailbox module
  • Fix unsafe decoding of Outlook winmail.dat attachments
  • Fix Certbot standalone port conflicts
  • Fix to correctly preserve full quoted action parameters in the Fail2Ban jail editor #2647
  • Fix Fail2Ban default jail options to preserve required timing defaults when saving
  • Fix ZFS to fall back to df when disk space cannot be computed from zpool
  • Fix to allow toggling process priority and I/O controls on or off
  • Fix issue where disabled email notifications were still being processed
  • Update Authentic theme to the latest version with various improvements and fixes:
    • Upgrade stats history graphs from laggy SVG to a blazing-fast canvas renderer
    • Add option to control corner roundness for the menu, content area and right-side slider
    • Change the content area to use rounded corners and a margin by default
    • Fix message of the day display in login page correctly webmin#2555
    • Fix tooltip visibility in dark palette
    • Fix session login button spinner
    • Fix various button styling issues (active state, tiny buttons, airy buttons, stack position)
2.621 Bug fix

Fixed NAT session timeouts during transfers, improved upload tracking, fixed PHP version display, updated Xterm.js, and optimized file upload memory handling in File Manager.

2.620 New feature
Notable features
  • Database driver selection
  • EC SSL certificate support
  • Ed25519 key support

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

About

Stars
5,843
Forks
779
Languages
HTML Perl Raku

Community & Support

Open source alternatives

Beta — feedback welcome: [email protected]