logo

Actively exploited cPanel bug exposes millions of websites to takeover

ID: 7de7c587-ea20-5f68-9627-57f123ce0803

STIX ID: report--7de7c587-ea20-5f68-9627-57f123ce0803

Feed Name: Malwarebytes Blog

Threat Score
90/100

Date Published: 2026-05-01

Date Updated: 2026-05-01

...
...

A critical authentication-bypass vulnerability (CVE-2026-41940) in cPanel/WHM is being actively exploited in the wild; CISA added it to its Known Exploited Vulnerabilities catalog, cPanel released patches on April 28, 2026, and major hosting providers temporarily blocked cPanel interfaces while addressing exploit attempts that date back to late February 2026.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.