GCM is far more preferred to either CBC or CTR because it's less for the implementer to screw up.
NaCl's ChaCha20-Poly1305 is even better, because it's fast and constant-time.
'cperciva made the CTR+HMAC recommendation here: http://www.daemonology.net/blog/2009-06-11-cryptographic-rig...
Properly authenticated encryption that uses CBC+HMAC-SHA2 with PKCS7 padding is probably okay, but new developments should prefer AEAD modes above all else, and CTR+HMAC-SHA2 if no AEAD modes are available.
(The kind folks in ##crypto on freenode have pointed out to me that CTR also allows random-access decryption, where CBC mode does not. We haven't ever implemented this feature and cannot comment on it.)