logo

First reports come in of victims of critical cPanel vuln as 'millions' of sites potentially exposed

ID: 9f2ff802-7c41-5630-920c-317296f09dbb

STIX ID: report--9f2ff802-7c41-5630-920c-317296f09dbb

Feed Name: The Register (Security)

Threat Score
88/100

Date Published: 2026-05-01

Date Updated: 2026-05-06

...
...

Critical cPanel vulnerability CVE-2026-41940 (CVSS 9.8) was actively exploited in the wild before patches shipped, affecting an estimated ~1.5 million internet-exposed cPanel instances; hosting providers reported blocking access and deploying updates, and there is at least one anecdotal report of ransomware demand following exploitation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.