logo

cPanel, WHM emergency update fixes critical auth bypass bug

ID: 07458b3d-c9cd-5704-988b-f1a928335603

STIX ID: report--07458b3d-c9cd-5704-988b-f1a928335603

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2026-04-29

Date Updated: 2026-04-29

Author: Bill Toulas

...
...

## Executive Summary A critical authentication-bypass vulnerability was disclosed in cPanel and WHM affecting most supported versions; cPanel released emergency updates for specific versions and advised administrators to run the update process (upcp --force) or upgrade unsupported installations. Hosting providers (e.g., Namecheap) temporarily blocked relevant ports while patches were applied; no technical details or public tracking identifier have been published, but successful exploitation could grant full control of hosting accounts or entire servers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.