logo

Hackers are mass-exploiting the cPanel bug to gain control of thousands of websites

ID: a3dcd025-95db-569a-bce9-68fce523474d

STIX ID: report--a3dcd025-95db-569a-bce9-68fce523474d

Feed Name: TechCrunch Security News

Threat Score
78/100

Date Published: 2026-05-04

Date Updated: 2026-05-05

Author: Lorenzo Franceschi-Bicchierai

...
...

Nearly a week after disclosure of a critical cPanel/WHM vulnerability (CVE-2026-41940), attackers have been mass-compromising servers — Shadowserver reports ~550,000 potentially vulnerable servers and roughly 2,000 likely compromised instances — with some sites showing ransomware messages; CISA added the flaw to its Known Exploited Vulnerabilities catalog and urged immediate patching.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.