Hackers Are Actively Exploiting a Bug In cPanel, Used By Millions of Websites (techcrunch.com) 15
Hackers are actively exploiting a critical cPanel and WHM vulnerability, tracked as CVE-2026-41940, that allows remote attackers to bypass the login screen and gain full administrative access to affected web servers. Major hosts including Namecheap, HostGator, and KnownHost have taken mitigation steps or patched systems, but cPanel is urging all customers and web hosts to update immediately because the software is widely used across millions of websites. TechCrunch reports: cPanel and WHM are two software suites used for managing web servers that host websites, manage emails, and handle important configurations and databases needed to maintain an internet domain. The two suites have deep-access to the servers that they manage, allowing a malicious hacker potentially unrestricted access to data managed by the affected software.
Given the ubiquity of the cPanel and WHM software across the web hosting industry, hackers could compromise potentially large numbers of websites that haven't patched the bug. Canada's national cybersecurity agency said in an advisory that the bug could be exploited to compromise websites on shared hosting servers, such as large web hosting companies.
The agency said that "exploitation is highly probable" and that immediate action from cPanel customers, or their web hosts, is necessary to prevent malicious access. [...] One web hosting company says it found evidence that hackers have been abusing the vulnerability for months before the attempts were discovered.
Given the ubiquity of the cPanel and WHM software across the web hosting industry, hackers could compromise potentially large numbers of websites that haven't patched the bug. Canada's national cybersecurity agency said in an advisory that the bug could be exploited to compromise websites on shared hosting servers, such as large web hosting companies.
The agency said that "exploitation is highly probable" and that immediate action from cPanel customers, or their web hosts, is necessary to prevent malicious access. [...] One web hosting company says it found evidence that hackers have been abusing the vulnerability for months before the attempts were discovered.
ah yep (Score:1)
Customers Update (Score:4, Insightful)
cPanel is urging all customers and web hosts to update immediately.
For hosted websites, is this not something the web host should be doing for their customers?
Re: (Score:1)
Re: (Score:1)
I believe they meant in the general sense, not necessarily very-end-users.
Re: (Score:2)
very-end-users.
Haven't heard that term before. I like it :)
Re: (Score:1)
Just don't take it too literally ;-)
Re: (Score:2)
"should" is doing some heavy lifting there.
But if you're concerned about a cPanel server where you have a site, you could just exploit the hole to gain admin access and then apply the update.
Re: (Score:3)
Chained to Copyfail (Score:3)
They get auth through CPanel then get root through Copyfail.
Brace for impact.
Re:Chained to Copyfail (Score:4, Funny)
CopyFail only affects kernels from 2017 on, nothing that new is running CPanel
Re: (Score:1)
Re: (Score:1)
AI hasn’t even shown its true capabilities yet.
Brace for impact.
Indeed.
So what? (Score:1)
cPanel has been under attack via different exploits for a long, long, looooooong time.
Just look at how long its CVE history is.
Namecheap Mitigations (Score:2)