CriticalSecurity & Privacy
Hackers are still exploiting the cPanel bug to gain control of thousands of websites
A critical vulnerability (CVE-2026-41940) in cPanel/WHM software, which powers 60 million domains, continues to be actively exploited by threat actors to compromise web servers and deploy ransomware, with approximately 550,000 potentially vulnerable instances still unpatched weeks after disclosure. This represents significant business continuity and data security risks for any organization relying on cPanel-hosted infrastructure, requiring immediate patch deployment and incident response readiness. IT leaders must treat this as a critical priority given the widespread adoption of the platform, the evidence of active exploitation, and potential regulatory implications for government agencies under CISA mandates.

Days after the disclosure of a critical vulnerability in popular web hosting software cPanel and WHM, hackers keep targeting and hacking websites.