TechBooky AI Assistant
TechBooky AI Assistant
👋 Welcome to TechBooky AI Assistant

I can help with:
🔎 Tech News
🤖 AI Topics
💻 Gadgets
☁️ Cloud
✍️ Guest Posts
📢 Advertising
🔗 Backlinks
📩 Newsletter
  • AI Search
  • Cryptocurrency
  • Earnings
  • Enterprise
  • About TechBooky
  • Submit Article
  • Advertise With TechBooky
  • Contact Us
TechBooky
  • African
  • AI
  • Metaverse
  • Gadgets
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
  • African
  • AI
  • Metaverse
  • Gadgets
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
TechBooky
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
Home Security

Hackers Are Exploiting Critical cPanel Bug, Putting Millions of Websites at Risk

Paul Balo by Paul Balo
May 1, 2026
in Security
Share on FacebookShare on Twitter
Share this story

Send it to someone who should read it.

f Facebook X X in LinkedIn wa WhatsApp tg Telegram @ Email
In Brief
  • Web hosting providers are racing to secure their infrastructure after security researchers disclosed a serious vulnerability in cPanel and WebHost Manager (WHM), the widely used server...
  • The flaw, tracked as CVE-2026-41940, allows hackers to remotely bypass the login page and gain full access to the software’s administration panel.
  • Because cPanel and WHM sit at the heart of many hosting environments, successful exploitation can effectively hand over complete control of affected servers.

Web hosting providers are racing to secure their infrastructure after security researchers disclosed a serious vulnerability in cPanel and WebHost Manager (WHM), the widely used server management tools that power tens of millions of websites.

The flaw, tracked as CVE-2026-41940, allows hackers to remotely bypass the login page and gain full access to the software’s administration panel. Because cPanel and WHM sit at the heart of many hosting environments, successful exploitation can effectively hand over complete control of affected servers.

cPanel and WHM are software suites used by hosting companies and administrators to manage web servers, websites, email, databases and key configuration settings. By design, they have deep access to the underlying systems they control, making them particularly sensitive points of failure when bugs are discovered.

According to the details shared so far, the CVE-2026-41940 vulnerability affects all supported versions of cPanel. The company behind cPanel has urged customers to ensure their systems are updated, and many commercial web hosts have already pushed patches to customer environments.

Because the bug lets an attacker bypass authentication and reach the administration interface directly, a successful exploit could provide unrestricted access to the data and services hosted on vulnerable servers. Given how widely cPanel and WHM are deployed across the web hosting industry, unpatched systems could expose large numbers of websites to compromise.

Canada’s national cybersecurity agency, in an advisory about the flaw, warned that the vulnerability could be used to compromise websites on shared hosting servers, such as those run by major hosting providers. The agency said “exploitation is highly probable” and called for immediate action by cPanel customers or their hosting providers to prevent malicious access.

Also worth reading
Critical Palo Alto PAN-OS Zero-Day Exploited in the Wild, Firewall RCE Risk Emerges Cisco Patches Critical Flaws That Could Let Hackers Take Over Systems Without Login Critical Vulnerability In Microsoft Authenticator Exposes Users To Token Theft Apple Patches iOS Bug That Allowed Recovery of Deleted Messages BlueHammer Windows Exploit Exposes Microsoft Bug Disclosure Crisis Exchange Vulnerability Turns OWA Into Script-Launching Tool

Several big-name web hosting companies have already taken visible steps in response to the vulnerability.

  • Namecheap, which uses cPanel to let its customers manage their web servers, said it temporarily blocked access to customers’ cPanel panels after learning of the flaw. The move was intended to prevent exploitation while the company patched its customers’ systems.
  • HostGator confirmed that it has patched its systems and is treating the vulnerability as a “critical authentication-bypass exploit.”

One hosting provider says it has seen signs that attackers have been probing this weakness for some time. KnownHost CEO Daniel Pearson wrote in a Reddit post that the company observed attempts to exploit the vulnerability as early as February 23. In response, KnownHost briefly blocked access to customer systems while it applied patches.

Pearson said about 30 servers in KnownHost’s fleet showed signs of unauthorized attempted access, out of thousands of machines on its network. He likened what the company saw to attempts rather than confirmed takeovers, and said they have not found evidence of active compromise. The activity suggests, however, that at least some hackers were aware of and trying to exploit the bug months before the current wave of attention.

Alongside fixing the main cPanel and WHM issue, cPanel also rolled out a security fix for WP Squared, a related tool used for managing WordPress websites.

For website owners, the immediate priority is to confirm whether their hosting provider has deployed the relevant patches, or, for self-managed servers, to apply updates directly. Given the ability of this bug to bypass the login screen altogether, simply changing passwords or tightening user access is not enough on its own.

Update: This story will be updated as more hosting providers disclose their status and additional technical details about CVE-2026-41940 become public.

Related Reading

More contextual TechBooky stories selected from tags, categories and article context.

  • cisco logo
    Cisco Patches Critical Flaws That Could Let Hackers…
  • blog5f352fc3b2393_wp
    Hackers Exploit Popular WordPress Backup Tool Used…
  • shutterstock_chatgpt
    Researchers Warn ChatGPT Crawler May Cause DDoS…
  • Palo-Alto-Networks-zero-day
    Critical Palo Alto PAN-OS Zero-Day Exploited in the…
  • 1_8_VsolmlGbZ-OhZN0wEgrw
    Over 46,000 Grafana Instances Vulnerable to Account Takeover
  • Cloudflare-AI_Bot-Blocking
    Cloudflare Blames React2Shell Protections for Outage
  • winUpdate-2
    Microsoft Fixes 77 Vulnerabilities in March Patch Tuesday
  • hero-image.fill.size_1248x702.v1778518702
    Instructure Reaches Deal With Hackers After Twin…
Keep Reading Smarter

Search TechBooky with AI

Use TechBooky's AI Search to explore the context behind this story and related coverage across the site.

Try AI Search
More On This Topic
Security
Follow TechBooky

Follow TechBooky for more technology stories and newsroom updates.

f Facebook X X in LinkedIn ig Instagram wa WhatsApp

Tags: cpanelCVE-2026-41940vulnerability
Paul Balo

Paul Balo

Paul Balo is the founder of TechBooky and a highly skilled wireless communications professional with a strong background in cloud computing, offering extensive experience in designing, implementing, and managing wireless communication systems.

Search TechBooky
Open TechBooky AI Search Try the AI Assistant

BROWSE BY CATEGORIES

Receive top tech news directly in your inbox

subscription from
Loading

Freshly Squeezed

  • Samsung Memory Warning Shows AI Chip Shortage May Last Into 2028 August 1, 2026
  • Siri AI Paywall Would Make Apple Intelligence A Services Business July 31, 2026
  • Mirage Kitten Malware Shows Cyber-Espionage Pressure Across Africa And MEA July 31, 2026
  • Snapchat Stops Paying Fully AI-Generated Spotlight Videos As AI Slop Spreads July 31, 2026
  • Anthropic Says Claude Models Breached Real Systems During Cyber Tests July 31, 2026
  • DeepSeek V4 Flash API Raises The Pressure In The AI Agent Price War July 31, 2026
  • MTN Nigeria Fintech Revenue Slump Shows Airtime Lending Risk July 31, 2026
  • Google Earth AI Image Tool Shows How Fake Satellite Proof Could Spread July 31, 2026
  • Lesotho Launches National CSIRT As Cybersecurity Becomes Core Digital Infrastructure July 31, 2026
  • Gabon Data Centre Push Shows Africa Digital Sovereignty Is Becoming Infrastructure July 31, 2026
  • Inforcer Raises $50M As AI Turns Microsoft 365 Security Into An MSP Problem July 31, 2026
  • Rwanda 3G Shutdown Shows Africa Mobile Money Needs A Careful 4G Migration July 31, 2026

Browse Archives

August 2026
M T W T F S S
 12
3456789
10111213141516
17181920212223
24252627282930
31  
« Jul    

Quick Links

  • About TechBooky
  • Advertise With TechBooky
  • Contact us
  • Submit Article
  • Privacy Policy
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
  • African
  • Artificial Intelligence
  • Gadgets
  • Metaverse
  • Tips
  • AI Search
  • About TechBooky
  • Advertise With TechBooky
  • Submit Article
  • Contact us

© 2025 Designed By TechBooky Elite

Discover more from TechBooky

Subscribe now to keep reading and get access to the full archive.

Continue reading

We use cookies to ensure that we give you the best experience on our website. If you continue to use this site we will assume that you are happy with it.