logo

cPanel Warns of Critical Authentication Flaw – Emergency Patch Released

ID: a8280bac-271b-5e23-a981-a369975a619b

STIX ID: report--a8280bac-271b-5e23-a981-a369975a619b

Feed Name: cybersecurityNews.com

Threat Score
80/100

Date Published: 2026-04-29

Date Updated: 2026-04-29

Author: Abinaya

...
...

cPanel issued an emergency security advisory for a critical authentication vulnerability affecting all supported cPanel/WHM versions; administrators are urged to apply provided patches (listed secure builds) immediately or run `/scripts/upcp --force`. The flaw could allow attackers to bypass logins and gain root-level control of hosting servers, risking site defacement, ransomware, data exfiltration, and botnet enlistment; the advisory also warns unsupported/EOL installs will not receive fixes and recommends MFA, IP allowlisting, and firewall mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.