CriticalSecurity & Privacy
Hackers are actively exploiting a bug in cPanel, used by millions of websites
A critical authentication-bypass vulnerability (CVE-2026-41940) in cPanel and WHM—web server management software used by tens of millions of websites—is being actively exploited by hackers to gain full administrative control of affected servers, with evidence of exploitation attempts dating back to February. This poses significant risk to organizations relying on shared hosting providers, as unpatched systems could expose customer data, websites, and critical configurations at scale. IT leaders and CIOs must immediately coordinate with their hosting providers to confirm patch deployment and verify no unauthorized access has occurred, particularly for mission-critical web infrastructure.

Web hosts are scrambling to fix the bug under active attack by hackers. One company said hackers have been abusing the bug for months.