Hackers are actively exploiting a bug in cPanel and WHM

Published: (April 30, 2026 at 04:43 PM EDT)
2 min read
Source: Hacker News

Source: Hacker News

Overview

Security researchers are sounding the alarm on a newly discovered vulnerability in the widely used web server management software cPanel and WebHost Manager (WHM). The bug allows hackers to hijack and take full control of servers running the affected software, which is thought to be used by tens of millions of website owners worldwide.

Impact

The vulnerability affects all supported versions of the software. It allows malicious actors to remotely bypass the login screen and gain full access to the administration panel, giving them unrestricted access to data managed by cPanel/WHM.

Given the ubiquity of cPanel and WHM across the web‑hosting industry, unpatched installations could lead to large numbers of compromised websites, especially on shared‑hosting servers.

Advisory

Canada’s national cybersecurity agency issued an advisory warning that exploitation is “highly probable” and that immediate action from cPanel customers—or their web hosts—is necessary to prevent malicious access.

The bug is officially tracked as CVE‑2026‑41940: https://support.cpanel.net/hc/en-us/articles/40073787579671-Security-CVE-2026-41940-cPanel-WHM-WP2-Security-Update-04-28-2026

Responses from Hosting Companies

Evidence of Exploitation

KnownHost reported that hackers had been abusing the vulnerability for months before it was publicly disclosed.

cPanel also rolled out a security fix for WP Squared, a tool for managing WordPress sites: https://docs.wpsquared.com/changelogs/versions/changelog/#cpanel-related-changes

0 views
Back to Blog

Related posts

Read more »

When Networking Doesn't Work

My Windows 11 → Tyan SMDC IPMI Troubleshooting Story _Last week I spent far too much time trying to get my Windows 11 machine to talk to an antique Tyan SMDC S...