TechBooky AI Assistant
TechBooky AI Assistant
👋 Welcome to TechBooky AI Assistant

I can help with:
🔎 Tech News
🤖 AI Topics
💻 Gadgets
☁️ Cloud
✍️ Guest Posts
📢 Advertising
🔗 Backlinks
📩 Newsletter
  • AI Search
  • Cryptocurrency
  • Earnings
  • Enterprise
  • About TechBooky
  • Submit Article
  • Advertise Here
  • Contact Us
TechBooky
  • African
  • AI
  • Metaverse
  • Gadgets
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
  • African
  • AI
  • Metaverse
  • Gadgets
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
TechBooky
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
Home Security

Hackers Are Exploiting Critical cPanel Bug, Putting Millions of Websites at Risk

Paul Balo by Paul Balo
May 1, 2026
in Security
Share on FacebookShare on Twitter

Web hosting providers are racing to secure their infrastructure after security researchers disclosed a serious vulnerability in cPanel and WebHost Manager (WHM), the widely used server management tools that power tens of millions of websites.

The flaw, tracked as CVE-2026-41940, allows hackers to remotely bypass the login page and gain full access to the software’s administration panel. Because cPanel and WHM sit at the heart of many hosting environments, successful exploitation can effectively hand over complete control of affected servers.

cPanel and WHM are software suites used by hosting companies and administrators to manage web servers, websites, email, databases and key configuration settings. By design, they have deep access to the underlying systems they control, making them particularly sensitive points of failure when bugs are discovered.

According to the details shared so far, the CVE-2026-41940 vulnerability affects all supported versions of cPanel. The company behind cPanel has urged customers to ensure their systems are updated, and many commercial web hosts have already pushed patches to customer environments.

Because the bug lets an attacker bypass authentication and reach the administration interface directly, a successful exploit could provide unrestricted access to the data and services hosted on vulnerable servers. Given how widely cPanel and WHM are deployed across the web hosting industry, unpatched systems could expose large numbers of websites to compromise.

Canada’s national cybersecurity agency, in an advisory about the flaw, warned that the vulnerability could be used to compromise websites on shared hosting servers, such as those run by major hosting providers. The agency said “exploitation is highly probable” and called for immediate action by cPanel customers or their hosting providers to prevent malicious access.

Several big-name web hosting companies have already taken visible steps in response to the vulnerability.

  • Namecheap, which uses cPanel to let its customers manage their web servers, said it temporarily blocked access to customers’ cPanel panels after learning of the flaw. The move was intended to prevent exploitation while the company patched its customers’ systems.
  • HostGator confirmed that it has patched its systems and is treating the vulnerability as a “critical authentication-bypass exploit.”

One hosting provider says it has seen signs that attackers have been probing this weakness for some time. KnownHost CEO Daniel Pearson wrote in a Reddit post that the company observed attempts to exploit the vulnerability as early as February 23. In response, KnownHost briefly blocked access to customer systems while it applied patches.

Pearson said about 30 servers in KnownHost’s fleet showed signs of unauthorized attempted access, out of thousands of machines on its network. He likened what the company saw to attempts rather than confirmed takeovers, and said they have not found evidence of active compromise. The activity suggests, however, that at least some hackers were aware of and trying to exploit the bug months before the current wave of attention.

Alongside fixing the main cPanel and WHM issue, cPanel also rolled out a security fix for WP Squared, a related tool used for managing WordPress websites.

For website owners, the immediate priority is to confirm whether their hosting provider has deployed the relevant patches, or, for self-managed servers, to apply updates directly. Given the ability of this bug to bypass the login screen altogether, simply changing passwords or tightening user access is not enough on its own.

Update: This story will be updated as more hosting providers disclose their status and additional technical details about CVE-2026-41940 become public.

Related Posts:

  • cisco logo
    Cisco Patches Critical Flaws That Could Let Hackers…
  • blog5f352fc3b2393_wp
    Hackers Exploit Popular WordPress Backup Tool Used…
  • shutterstock_chatgpt
    Researchers Warn ChatGPT Crawler May Cause DDoS…
  • Palo-Alto-Networks-zero-day
    Critical Palo Alto PAN-OS Zero-Day Exploited in the…
  • 1_8_VsolmlGbZ-OhZN0wEgrw
    Over 46,000 Grafana Instances Vulnerable to Account Takeover
  • Cloudflare-AI_Bot-Blocking
    Cloudflare Blames React2Shell Protections for Outage
  • Robotics
    Nigeria Ranked As Africa’s Second Most Cyber-secure…
  • winUpdate-2
    Microsoft Fixes 77 Vulnerabilities in March Patch Tuesday

Discover more from TechBooky

Subscribe to get the latest posts sent to your email.

Tags: cpanelCVE-2026-41940vulnerability
Paul Balo

Paul Balo

Paul Balo is the founder of TechBooky and a highly skilled wireless communications professional with a strong background in cloud computing, offering extensive experience in designing, implementing, and managing wireless communication systems.

BROWSE BY CATEGORIES

Receive top tech news directly in your inbox

subscription from
Loading

Freshly Squeezed

  • Britain’s Under-16 Social Media Ban Could Redefine Big Tech’s Responsibility To Children June 15, 2026
  • Anthropic Asked for AI Regulation, Fable 5 May Show What That Really Looks Like June 14, 2026
  • Amazon Raised Anthropic AI Security Concerns Before US Crackdown on Fable 5 and Mythos 5 June 14, 2026
  • Europe Calls Anthropic AI Ban a ‘Wake-Up Call’ as US Shuts Off Access to Fable 5 and Mythos 5 June 14, 2026
  • US Orders Anthropic to Disable Claude Fable 5 and Mythos 5 Over National Security Concerns June 14, 2026
  • Elon Musk Hits $1.1 Trillion as SpaceX Surpasses $2 Trillion Valuation June 13, 2026
  • SpaceX Prices Record $75 Billion IPO as Elon Musk Nears Trillionaire Status June 12, 2026
  • DoorDash Launches AI Chatbot for Food Orders June 12, 2026
  • Pool Launches App That Makes Screenshots More Useful June 12, 2026
  • Deezer Launches Tool to Detect AI-Generated Music June 12, 2026
  • Coinbase Introduces Platform for Agents to Trade Assets and Buy Premium Insights June 12, 2026
  • Meta Expands Edits App With AI Features and Desktop Access June 12, 2026

Browse Archives

June 2026
MTWTFSS
1234567
891011121314
15161718192021
22232425262728
2930 
« May    

Quick Links

  • About TechBooky
  • Advertise Here
  • Contact us
  • Submit Article
  • Privacy Policy
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
  • African
  • Artificial Intelligence
  • Gadgets
  • Metaverse
  • Tips
  • AI Search
  • About TechBooky
  • Advertise Here
  • Submit Article
  • Contact us

© 2025 Designed By TechBooky Elite

Discover more from TechBooky

Subscribe now to keep reading and get access to the full archive.

Continue reading

We use cookies to ensure that we give you the best experience on our website. If you continue to use this site we will assume that you are happy with it.