logo

First reports come in of victims of critical cPanel vuln as 'millions' of sites potentially exposed

ID: 8ac76a48-6dd2-5575-bb85-28b7ae1aec68

STIX ID: report--8ac76a48-6dd2-5575-bb85-28b7ae1aec68

Feed Name: The Register (Security)

Threat Score
85/100

Date Published: 2026-05-01

Date Updated: 2026-05-01

Author: Carly Page

...
...

CISA added a critical cPanel/WHM vulnerability (CVE-2026-41940, CVSS 9.8) to its Known Exploited Vulnerabilities list after evidence of active exploitation; vendors released a patch but hosting providers reported exploitation attempts and at least one alleged ransomware attack, while Rapid7/Shodan identified roughly 1.5 million internet-exposed cPanel instances, making immediate patching and access restriction urgent.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.