logo

Federal agencies must patch cPanel bug by Sunday, CISA says

ID: 3accec02-098f-579a-93b2-c04103867af0

STIX ID: report--3accec02-098f-579a-93b2-c04103867af0

Feed Name: The Record from Recorded Future News

Threat Score
90/100

Date Published: 2026-05-01

Date Updated: 2026-05-01

...
...

CISA ordered federal agencies to patch CVE-2026-41940, a critical (CVSS 9.8) vulnerability in cPanel & WHM that can grant attackers full control of hosts, configurations, and managed websites. The bug is being actively exploited in the wild with evidence of exploitation since February, many internet-exposed instances may be vulnerable, vendors released detection and mitigation tools, and major hosting providers have taken emergency protective actions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.