logo

cPanel released a patch for a WebHost Manager (WHM) authentication bypass bug

ID: 34f5a625-2131-55ec-bdfe-c625484620f9

STIX ID: report--34f5a625-2131-55ec-bdfe-c625484620f9

Feed Name: Expel Blog

Threat Score
90/100

Date Published: 2026-04-29

Date Updated: 2026-04-30

...
...

**TL;DR:** cPanel disclosed a critical authentication-bypass vulnerability in WHM on April 28, 2026 that affects nearly all known versions (including EOL releases); exploits were seen in the wild before patches were released, and administrators should update immediately as root or confirm their hosting provider has applied the fixes and review server access logs for suspicious activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.