cPanel released a patch for a WebHost Manager (WHM) authentication bypass bug
ID: 34f5a625-2131-55ec-bdfe-c625484620f9
STIX ID: report--34f5a625-2131-55ec-bdfe-c625484620f9
Feed Name: Expel Blog
Threat Score
**TL;DR:** cPanel disclosed a critical authentication-bypass vulnerability in WHM on April 28, 2026 that affects nearly all known versions (including EOL releases); exploits were seen in the wild before patches were released, and administrators should update immediately as root or confirm their hosting provider has applied the fixes and review server access logs for suspicious activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
