Physical Address
304 North Cardinal St.
Dorchester Center, MA 02124
Physical Address
304 North Cardinal St.
Dorchester Center, MA 02124

Security researchers have raised the alarm over a newly discovered vulnerability in the widely used web server management software cPanel and WebHost Manager (WHM).
This flaw allows hackers to infiltrate and take full control of the servers running the affected software, which are believed to be used by tens of millions of website owners around the world.
Many commercial web hosting companies have already patched their customers’ systems. But the cPanel manufacturer urged customers to make sure their systems are patched when the glitch occurs All supported versions of the program.
cPanel and WHM are two sets of software used to manage web servers that host websites, manage emails, and handle important configurations and databases needed to maintain an Internet domain. Both groups have deep access to the servers they manage, allowing the malicious hacker unfettered access to data managed by the affected software.
The error, was officially traced as CVE-2026-41940allows malicious hackers to remotely bypass its login screen to gain full access to the software’s administration panel.
Since cPanel and WHM are ubiquitous across the web hosting industry, hackers can compromise a large number of websites that have not patched the error.
Canada’s National Cyber Security Agency said In consultation It is possible to exploit the vulnerability to hack websites located on shared hosting servers, such as large web hosting companies.
The agency said that “exploitation is highly likely” and that immediate action by cPanel customers, or their web hosts, is necessary to prevent malicious access.
Web hosting company Namecheap, which uses cPanel to let its customers manage their web servers, said the company blocked access to customers’ cPanel panels after learning of the flaw to prevent exploitation, and to give it time to… To patch its customers’ systems.
Hostgator said it too Corrected its systems This bug is considered a “critically important authentication bypass exploit.”
One web hosting company says it has found evidence that hackers were abusing the vulnerability for months before the attempts were discovered.
said KnownHost CEO Daniel Pearson In a post on Reddit His company has witnessed attempts to exploit the vulnerability since February 23 He said It also briefly began blocking access to customer systems before applying patches.
According to Pearsonabout 30 servers at KnownHost showed signs of an unauthorized access attempt to thousands of computers on its network. Pearson likened the efforts to attempts, and saw no signs of active settlement. cPanel said so too Introducing a security fix For WP Squared, a similar tool for managing WordPress sites.
When you make a purchase through the links in our articles, We may earn a small commission. This does not affect our editorial independence.