Actively exploited cPanel bug exposes millions of websites to takeover
ID: 7de7c587-ea20-5f68-9627-57f123ce0803
STIX ID: report--7de7c587-ea20-5f68-9627-57f123ce0803
Feed Name: Malwarebytes Blog
Threat Score
A critical authentication-bypass vulnerability (CVE-2026-41940) in cPanel/WHM is being actively exploited in the wild; CISA added it to its Known Exploited Vulnerabilities catalog, cPanel released patches on April 28, 2026, and major hosting providers temporarily blocked cPanel interfaces while addressing exploit attempts that date back to late February 2026.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
