• AI Search
  • Cryptocurrency
  • Earnings
  • Enterprise
  • About TechBooky
  • Submit Article
  • Advertise Here
  • Contact Us
TechBooky
  • African
  • AI
  • Metaverse
  • Gadgets
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
  • African
  • AI
  • Metaverse
  • Gadgets
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
TechBooky
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
Home Security

Hackers Are Exploiting Critical cPanel Bug, Putting Millions of Websites at Risk

Paul Balo by Paul Balo
May 1, 2026
in Security
Share on FacebookShare on Twitter

Web hosting providers are racing to secure their infrastructure after security researchers disclosed a serious vulnerability in cPanel and WebHost Manager (WHM), the widely used server management tools that power tens of millions of websites.

The flaw, tracked as CVE-2026-41940, allows hackers to remotely bypass the login page and gain full access to the software’s administration panel. Because cPanel and WHM sit at the heart of many hosting environments, successful exploitation can effectively hand over complete control of affected servers.

cPanel and WHM are software suites used by hosting companies and administrators to manage web servers, websites, email, databases and key configuration settings. By design, they have deep access to the underlying systems they control, making them particularly sensitive points of failure when bugs are discovered.

According to the details shared so far, the CVE-2026-41940 vulnerability affects all supported versions of cPanel. The company behind cPanel has urged customers to ensure their systems are updated, and many commercial web hosts have already pushed patches to customer environments.

Because the bug lets an attacker bypass authentication and reach the administration interface directly, a successful exploit could provide unrestricted access to the data and services hosted on vulnerable servers. Given how widely cPanel and WHM are deployed across the web hosting industry, unpatched systems could expose large numbers of websites to compromise.

Canada’s national cybersecurity agency, in an advisory about the flaw, warned that the vulnerability could be used to compromise websites on shared hosting servers, such as those run by major hosting providers. The agency said “exploitation is highly probable” and called for immediate action by cPanel customers or their hosting providers to prevent malicious access.

Several big-name web hosting companies have already taken visible steps in response to the vulnerability.

  • Namecheap, which uses cPanel to let its customers manage their web servers, said it temporarily blocked access to customers’ cPanel panels after learning of the flaw. The move was intended to prevent exploitation while the company patched its customers’ systems.
  • HostGator confirmed that it has patched its systems and is treating the vulnerability as a “critical authentication-bypass exploit.”

One hosting provider says it has seen signs that attackers have been probing this weakness for some time. KnownHost CEO Daniel Pearson wrote in a Reddit post that the company observed attempts to exploit the vulnerability as early as February 23. In response, KnownHost briefly blocked access to customer systems while it applied patches.

Pearson said about 30 servers in KnownHost’s fleet showed signs of unauthorized attempted access, out of thousands of machines on its network. He likened what the company saw to attempts rather than confirmed takeovers, and said they have not found evidence of active compromise. The activity suggests, however, that at least some hackers were aware of and trying to exploit the bug months before the current wave of attention.

Alongside fixing the main cPanel and WHM issue, cPanel also rolled out a security fix for WP Squared, a related tool used for managing WordPress websites.

For website owners, the immediate priority is to confirm whether their hosting provider has deployed the relevant patches, or, for self-managed servers, to apply updates directly. Given the ability of this bug to bypass the login screen altogether, simply changing passwords or tightening user access is not enough on its own.

Update: This story will be updated as more hosting providers disclose their status and additional technical details about CVE-2026-41940 become public.

Related Posts:

  • cisco logo
    Cisco Patches Critical Flaws That Could Let Hackers…
  • blog5f352fc3b2393_wp
    Hackers Exploit Popular WordPress Backup Tool Used…
  • shutterstock_chatgpt
    Researchers Warn ChatGPT Crawler May Cause DDoS…
  • 1_8_VsolmlGbZ-OhZN0wEgrw
    Over 46,000 Grafana Instances Vulnerable to Account Takeover
  • Cloudflare-AI_Bot-Blocking
    Cloudflare Blames React2Shell Protections for Outage
  • Robotics
    Nigeria Ranked As Africa’s Second Most Cyber-secure…
  • winUpdate-2
    Microsoft Fixes 77 Vulnerabilities in March Patch Tuesday
  • MongoDB_Logo
    MongoDB Vulnerability Lets Attackers Crash Servers Remotely

Discover more from TechBooky

Subscribe to get the latest posts sent to your email.

Tags: cpanelCVE-2026-41940vulnerability
Paul Balo

Paul Balo

Paul Balo is the founder of TechBooky and a highly skilled wireless communications professional with a strong background in cloud computing, offering extensive experience in designing, implementing, and managing wireless communication systems.

BROWSE BY CATEGORIES

Receive top tech news directly in your inbox

subscription from
Loading

Freshly Squeezed

  • Meta Acquires Robotics Startup To Boost & Improve Its Humanoid AI Efforts May 2, 2026
  • xAI Rolls out Grok 4.3 and a New Voice Cloning Suite May 2, 2026
  • Pentagon Taps Nvidia, Microsoft And AWS To Bring AI To Classified Networks May 1, 2026
  • Hackers Are Exploiting Critical cPanel Bug, Putting Millions of Websites at Risk May 1, 2026
  • Alibaba’s Metis Agent Aims to Fix ‘Trigger‑Happy’ AI Tool Use With New RL Framework May 1, 2026
  • Samsung Q1 2026 Earnings: Record Profit Driven by AI Memory Chip Boom May 1, 2026
  • Qualcomm Q1 2026 Earnings: China Weakness and AI Push Drive Mixed Results May 1, 2026
  • Amazon Q1 2026 Earnings: AWS and AI Drive Strong Growth Despite Spending Concerns May 1, 2026
  • Meta Q1 2026 Earnings: Strong Revenue Growth Overshadowed by Massive AI Spending May 1, 2026
  • Apple Q2 2026 Earnings: $111B Revenue, iPhone 17 Drives Record Growth May 1, 2026
  • IBM Rolls out ‘Bob’, an AI Development Partner Built around Multi-model Routing and Human Checkpoints April 29, 2026
  • iOS 27 Reportedly Adds New Apple Intelligence Photo Editing Tools April 29, 2026

Browse Archives

May 2026
MTWTFSS
 123
45678910
11121314151617
18192021222324
25262728293031
« Apr    

Quick Links

  • About TechBooky
  • Advertise Here
  • Contact us
  • Submit Article
  • Privacy Policy
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
  • African
  • Artificial Intelligence
  • Gadgets
  • Metaverse
  • Tips
  • AI Search
  • About TechBooky
  • Advertise Here
  • Submit Article
  • Contact us

© 2025 Designed By TechBooky Elite

Discover more from TechBooky

Subscribe now to keep reading and get access to the full archive.

Continue reading

Chat with TechBooky AI
💬
TechBooky AI ✕
We use cookies to ensure that we give you the best experience on our website. If you continue to use this site we will assume that you are happy with it.