logo

Hackers are actively exploiting a bug in cPanel, used by millions of websites

ID: 5a31fb1e-7265-5b47-8f7d-4a856c500652

STIX ID: report--5a31fb1e-7265-5b47-8f7d-4a856c500652

Feed Name: TechCrunch Security News

Threat Score
78/100

Date Published: 2026-04-30

Date Updated: 2026-04-30

Author: Zack Whittaker

...
...

Security researchers disclosed a critical authentication-bypass vulnerability (CVE-2026-41940) in cPanel and WHM that can allow attackers to remotely bypass the login screen and gain full administrative control of affected servers. Given the wide use of cPanel/WHM across shared hosting providers, the flaw poses large-scale risk; major hosts (Namecheap, HostGator, KnownHost) reported blocking or patching access and observed exploitation attempts, and national cybersecurity guidance warned exploitation is highly probable.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.