{"id":47175,"date":"2026-04-30T19:55:40","date_gmt":"2026-04-30T19:55:40","guid":{"rendered":"https:\/\/bondahx.com\/index.php\/2026\/04\/30\/hackers-are-actively-exploiting-a-bug-in-cpanel-used-by-millions-of-websites\/"},"modified":"2026-04-30T19:55:40","modified_gmt":"2026-04-30T19:55:40","slug":"hackers-are-actively-exploiting-a-bug-in-cpanel-used-by-millions-of-websites","status":"publish","type":"post","link":"https:\/\/bondahx.com\/index.php\/2026\/04\/30\/hackers-are-actively-exploiting-a-bug-in-cpanel-used-by-millions-of-websites\/","title":{"rendered":"Hackers are actively exploiting a bug in cPanel, used by millions of websites"},"content":{"rendered":"<p><br \/>\n<\/p>\n<div>\n<p id=\"speakable-summary\" class=\"wp-block-paragraph\">Security researchers are sounding the alarm on a newly discovered vulnerability in the widely used web server management software cPanel and WebHost Manager (WHM).\u00a0<\/p>\n<p class=\"wp-block-paragraph\">The bug allows hackers to hijack and take full control of the servers running the affected software, which is thought to be used by tens of millions of website owners around the world.<\/p>\n<p class=\"wp-block-paragraph\">Many commercial web hosting companies have patched their customers\u2019 systems already. But the cPanel maker urged customers to ensure that their systems are patched as the bug affects <a rel=\"nofollow\" href=\"https:\/\/support.cpanel.net\/hc\/en-us\/articles\/40073787579671-Security-CVE-2026-41940-cPanel-WHM-WP2-Security-Update-04-28-2026\">all supported versions of the software<\/a>.<\/p>\n<p class=\"wp-block-paragraph\">cPanel and WHM are two software suites used for managing web servers that host websites, manage emails, and handle important configurations and databases needed to maintain an internet domain. The two suites have deep-access to the servers that they manage, allowing a malicious hacker potentially unrestricted access to data managed by the affected software.<\/p>\n<p class=\"wp-block-paragraph\">The bug, officially tracked as <a rel=\"nofollow\" href=\"https:\/\/support.cpanel.net\/hc\/en-us\/articles\/40073787579671-Security-CVE-2026-41940-cPanel-WHM-WP2-Security-Update-04-28-2026\">CVE-2026-41940<\/a>, allows malicious hackers to remotely bypass its login screen to gain full access to the software\u2019s administration panel.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">Given the ubiquity of the cPanel and WHM software across the web hosting industry, hackers could compromise potentially large numbers of websites that haven\u2019t patched the bug.<\/p>\n<p class=\"wp-block-paragraph\">Canada\u2019s national cybersecurity agency said <a rel=\"nofollow\" href=\"https:\/\/www.cyber.gc.ca\/en\/alerts-advisories\/al26-008-vulnerability-affecting-cpanel-webhost-manager-whm-cve-2026-41940\">in an advisory<\/a> that the bug could be exploited to compromise websites on shared hosting servers, such as large web hosting companies.<\/p>\n<p class=\"wp-block-paragraph\">The agency said that \u201cexploitation is highly probable\u201d and that immediate action from cPanel customers, or their web hosts, is necessary to prevent malicious access.<\/p>\n<p class=\"wp-block-paragraph\">Web hosting giant Namecheap, which uses cPanel to allow its customers to manage their web servers, said the company blocked access to customers\u2019 cPanel panels after learning of the flaw to prevent exploitation, and to give it time <a rel=\"nofollow\" href=\"https:\/\/www.namecheap.com\/status-updates\/ongoing-critical-security-vulnerability-in-cpanel-april-28-2026\/\">to patch its customers\u2019 systems<\/a>.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">Hostgator also said it <a rel=\"nofollow\" href=\"https:\/\/www.hostgator.com\/help\/article\/centos6-cpanel-vulnerability\">patched its systems<\/a> and is considering the bug a \u201ccritical authentication-bypass exploit.\u201d<\/p>\n<p class=\"wp-block-paragraph\">One web hosting company says it found evidence that hackers have been abusing the vulnerability for months before the attempts were discovered.<\/p>\n<p class=\"wp-block-paragraph\">KnownHost CEO Daniel Pearson said <a rel=\"nofollow\" href=\"https:\/\/www.reddit.com\/r\/cpanel\/comments\/1syyajp\/comment\/oiz12pp\/?utm_source=BC\">in a post on Reddit<\/a> that his company has seen attempts to exploit the vulnerability as far back as February 23. The company <a rel=\"nofollow\" href=\"https:\/\/www.knownhost.com\/forums\/threads\/cpanel-zero-day-exploit-network-wide-protections-in-place-for-cpanel-and-whm-logins-ports.6599\/\">said<\/a> it also briefly began blocking access to customer systems before applying patches.<\/p>\n<p class=\"wp-block-paragraph\"><a rel=\"nofollow\" href=\"https:\/\/www.knownhost.com\/forums\/threads\/cpanel-zero-day-exploit-network-wide-protections-in-place-for-cpanel-and-whm-logins-ports.6599\/post-29957\">According to Pearson<\/a>, around 30 servers at KnownHost showed signs of unauthorized attempted access out of thousands of computers on its network. Pearson likened the efforts to attempts, and has not seen signs of active compromise. cPanel also said it <a rel=\"nofollow\" href=\"https:\/\/docs.wpsquared.com\/changelogs\/versions\/changelog\/#cpanel-related-changes\">rolled out a security fix<\/a> for WP Squared, a similar tool for managing WordPress websites.<\/p>\n<\/div>\n<p><em>When you purchase through links in our articles, <a href=\"https:\/\/techcrunch.com\/techcrunch-affiliate-monetization-standards\/\">we may earn a small commission<\/a>. This doesn\u2019t affect our editorial independence.<\/em><\/p>\n<p><br \/>\n<br \/><a href=\"https:\/\/techcrunch.com\/2026\/04\/30\/hackers-are-actively-exploiting-a-bug-in-cpanel-used-by-millions-of-websites\/\">Source link <\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Security researchers are sounding the alarm on a newly discovered vulnerability in the widely used web server management software cPanel<\/p>\n","protected":false},"author":1,"featured_media":47176,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-47175","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized"],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v25.0 (Yoast SEO v26.9) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>Hackers are actively exploiting a bug in cPanel, used by millions of websites - bondahx<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/bondahx.com\/index.php\/2026\/04\/30\/hackers-are-actively-exploiting-a-bug-in-cpanel-used-by-millions-of-websites\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Hackers are actively exploiting a bug in cPanel, used by millions of websites\" \/>\n<meta property=\"og:description\" content=\"Security researchers are sounding the alarm on a newly discovered vulnerability in the widely used web server management software cPanel\" \/>\n<meta property=\"og:url\" content=\"https:\/\/bondahx.com\/index.php\/2026\/04\/30\/hackers-are-actively-exploiting-a-bug-in-cpanel-used-by-millions-of-websites\/\" \/>\n<meta property=\"og:site_name\" content=\"bondahx\" \/>\n<meta property=\"article:published_time\" content=\"2026-04-30T19:55:40+00:00\" \/>\n<meta name=\"author\" content=\"yawyaw111\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"yawyaw111\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/bondahx.com\/index.php\/2026\/04\/30\/hackers-are-actively-exploiting-a-bug-in-cpanel-used-by-millions-of-websites\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/bondahx.com\/index.php\/2026\/04\/30\/hackers-are-actively-exploiting-a-bug-in-cpanel-used-by-millions-of-websites\/\"},\"author\":{\"name\":\"yawyaw111\",\"@id\":\"https:\/\/bondahx.com\/#\/schema\/person\/46dc9a4646c23a602cea23ce9f4681e8\"},\"headline\":\"Hackers are actively exploiting a bug in cPanel, used by millions of websites\",\"datePublished\":\"2026-04-30T19:55:40+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/bondahx.com\/index.php\/2026\/04\/30\/hackers-are-actively-exploiting-a-bug-in-cpanel-used-by-millions-of-websites\/\"},\"wordCount\":465,\"commentCount\":0,\"image\":{\"@id\":\"https:\/\/bondahx.com\/index.php\/2026\/04\/30\/hackers-are-actively-exploiting-a-bug-in-cpanel-used-by-millions-of-websites\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/bondahx.com\/wp-content\/uploads\/2026\/04\/cpanel-security-flaw-bug.jpeg\",\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\/\/bondahx.com\/index.php\/2026\/04\/30\/hackers-are-actively-exploiting-a-bug-in-cpanel-used-by-millions-of-websites\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/bondahx.com\/index.php\/2026\/04\/30\/hackers-are-actively-exploiting-a-bug-in-cpanel-used-by-millions-of-websites\/\",\"url\":\"https:\/\/bondahx.com\/index.php\/2026\/04\/30\/hackers-are-actively-exploiting-a-bug-in-cpanel-used-by-millions-of-websites\/\",\"name\":\"Hackers are actively exploiting a bug in cPanel, used by millions of websites - bondahx\",\"isPartOf\":{\"@id\":\"https:\/\/bondahx.com\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/bondahx.com\/index.php\/2026\/04\/30\/hackers-are-actively-exploiting-a-bug-in-cpanel-used-by-millions-of-websites\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/bondahx.com\/index.php\/2026\/04\/30\/hackers-are-actively-exploiting-a-bug-in-cpanel-used-by-millions-of-websites\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/bondahx.com\/wp-content\/uploads\/2026\/04\/cpanel-security-flaw-bug.jpeg\",\"datePublished\":\"2026-04-30T19:55:40+00:00\",\"author\":{\"@id\":\"https:\/\/bondahx.com\/#\/schema\/person\/46dc9a4646c23a602cea23ce9f4681e8\"},\"breadcrumb\":{\"@id\":\"https:\/\/bondahx.com\/index.php\/2026\/04\/30\/hackers-are-actively-exploiting-a-bug-in-cpanel-used-by-millions-of-websites\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/bondahx.com\/index.php\/2026\/04\/30\/hackers-are-actively-exploiting-a-bug-in-cpanel-used-by-millions-of-websites\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/bondahx.com\/index.php\/2026\/04\/30\/hackers-are-actively-exploiting-a-bug-in-cpanel-used-by-millions-of-websites\/#primaryimage\",\"url\":\"https:\/\/bondahx.com\/wp-content\/uploads\/2026\/04\/cpanel-security-flaw-bug.jpeg\",\"contentUrl\":\"https:\/\/bondahx.com\/wp-content\/uploads\/2026\/04\/cpanel-security-flaw-bug.jpeg\",\"width\":1200,\"height\":784},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/bondahx.com\/index.php\/2026\/04\/30\/hackers-are-actively-exploiting-a-bug-in-cpanel-used-by-millions-of-websites\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/bondahx.com\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Hackers are actively exploiting a bug in cPanel, used by millions of websites\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/bondahx.com\/#website\",\"url\":\"https:\/\/bondahx.com\/\",\"name\":\"bondahx\",\"description\":\"Tech Centeral\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/bondahx.com\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/bondahx.com\/#\/schema\/person\/46dc9a4646c23a602cea23ce9f4681e8\",\"name\":\"yawyaw111\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/bondahx.com\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/64df2cff919388543bb55a93bc7d10a019fbb2b0ecaa20225f6cc6c58203d565?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/64df2cff919388543bb55a93bc7d10a019fbb2b0ecaa20225f6cc6c58203d565?s=96&d=mm&r=g\",\"caption\":\"yawyaw111\"},\"sameAs\":[\"https:\/\/bondahx.com\"],\"url\":\"https:\/\/bondahx.com\/index.php\/author\/yawyaw111\/\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"Hackers are actively exploiting a bug in cPanel, used by millions of websites - bondahx","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/bondahx.com\/index.php\/2026\/04\/30\/hackers-are-actively-exploiting-a-bug-in-cpanel-used-by-millions-of-websites\/","og_locale":"en_US","og_type":"article","og_title":"Hackers are actively exploiting a bug in cPanel, used by millions of websites","og_description":"Security researchers are sounding the alarm on a newly discovered vulnerability in the widely used web server management software cPanel","og_url":"https:\/\/bondahx.com\/index.php\/2026\/04\/30\/hackers-are-actively-exploiting-a-bug-in-cpanel-used-by-millions-of-websites\/","og_site_name":"bondahx","article_published_time":"2026-04-30T19:55:40+00:00","author":"yawyaw111","twitter_card":"summary_large_image","twitter_misc":{"Written by":"yawyaw111","Est. reading time":"2 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/bondahx.com\/index.php\/2026\/04\/30\/hackers-are-actively-exploiting-a-bug-in-cpanel-used-by-millions-of-websites\/#article","isPartOf":{"@id":"https:\/\/bondahx.com\/index.php\/2026\/04\/30\/hackers-are-actively-exploiting-a-bug-in-cpanel-used-by-millions-of-websites\/"},"author":{"name":"yawyaw111","@id":"https:\/\/bondahx.com\/#\/schema\/person\/46dc9a4646c23a602cea23ce9f4681e8"},"headline":"Hackers are actively exploiting a bug in cPanel, used by millions of websites","datePublished":"2026-04-30T19:55:40+00:00","mainEntityOfPage":{"@id":"https:\/\/bondahx.com\/index.php\/2026\/04\/30\/hackers-are-actively-exploiting-a-bug-in-cpanel-used-by-millions-of-websites\/"},"wordCount":465,"commentCount":0,"image":{"@id":"https:\/\/bondahx.com\/index.php\/2026\/04\/30\/hackers-are-actively-exploiting-a-bug-in-cpanel-used-by-millions-of-websites\/#primaryimage"},"thumbnailUrl":"https:\/\/bondahx.com\/wp-content\/uploads\/2026\/04\/cpanel-security-flaw-bug.jpeg","inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/bondahx.com\/index.php\/2026\/04\/30\/hackers-are-actively-exploiting-a-bug-in-cpanel-used-by-millions-of-websites\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/bondahx.com\/index.php\/2026\/04\/30\/hackers-are-actively-exploiting-a-bug-in-cpanel-used-by-millions-of-websites\/","url":"https:\/\/bondahx.com\/index.php\/2026\/04\/30\/hackers-are-actively-exploiting-a-bug-in-cpanel-used-by-millions-of-websites\/","name":"Hackers are actively exploiting a bug in cPanel, used by millions of websites - bondahx","isPartOf":{"@id":"https:\/\/bondahx.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/bondahx.com\/index.php\/2026\/04\/30\/hackers-are-actively-exploiting-a-bug-in-cpanel-used-by-millions-of-websites\/#primaryimage"},"image":{"@id":"https:\/\/bondahx.com\/index.php\/2026\/04\/30\/hackers-are-actively-exploiting-a-bug-in-cpanel-used-by-millions-of-websites\/#primaryimage"},"thumbnailUrl":"https:\/\/bondahx.com\/wp-content\/uploads\/2026\/04\/cpanel-security-flaw-bug.jpeg","datePublished":"2026-04-30T19:55:40+00:00","author":{"@id":"https:\/\/bondahx.com\/#\/schema\/person\/46dc9a4646c23a602cea23ce9f4681e8"},"breadcrumb":{"@id":"https:\/\/bondahx.com\/index.php\/2026\/04\/30\/hackers-are-actively-exploiting-a-bug-in-cpanel-used-by-millions-of-websites\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/bondahx.com\/index.php\/2026\/04\/30\/hackers-are-actively-exploiting-a-bug-in-cpanel-used-by-millions-of-websites\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/bondahx.com\/index.php\/2026\/04\/30\/hackers-are-actively-exploiting-a-bug-in-cpanel-used-by-millions-of-websites\/#primaryimage","url":"https:\/\/bondahx.com\/wp-content\/uploads\/2026\/04\/cpanel-security-flaw-bug.jpeg","contentUrl":"https:\/\/bondahx.com\/wp-content\/uploads\/2026\/04\/cpanel-security-flaw-bug.jpeg","width":1200,"height":784},{"@type":"BreadcrumbList","@id":"https:\/\/bondahx.com\/index.php\/2026\/04\/30\/hackers-are-actively-exploiting-a-bug-in-cpanel-used-by-millions-of-websites\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/bondahx.com\/"},{"@type":"ListItem","position":2,"name":"Hackers are actively exploiting a bug in cPanel, used by millions of websites"}]},{"@type":"WebSite","@id":"https:\/\/bondahx.com\/#website","url":"https:\/\/bondahx.com\/","name":"bondahx","description":"Tech Centeral","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/bondahx.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/bondahx.com\/#\/schema\/person\/46dc9a4646c23a602cea23ce9f4681e8","name":"yawyaw111","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/bondahx.com\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/64df2cff919388543bb55a93bc7d10a019fbb2b0ecaa20225f6cc6c58203d565?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/64df2cff919388543bb55a93bc7d10a019fbb2b0ecaa20225f6cc6c58203d565?s=96&d=mm&r=g","caption":"yawyaw111"},"sameAs":["https:\/\/bondahx.com"],"url":"https:\/\/bondahx.com\/index.php\/author\/yawyaw111\/"}]}},"_links":{"self":[{"href":"https:\/\/bondahx.com\/index.php\/wp-json\/wp\/v2\/posts\/47175","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/bondahx.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/bondahx.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/bondahx.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/bondahx.com\/index.php\/wp-json\/wp\/v2\/comments?post=47175"}],"version-history":[{"count":0,"href":"https:\/\/bondahx.com\/index.php\/wp-json\/wp\/v2\/posts\/47175\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/bondahx.com\/index.php\/wp-json\/wp\/v2\/media\/47176"}],"wp:attachment":[{"href":"https:\/\/bondahx.com\/index.php\/wp-json\/wp\/v2\/media?parent=47175"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/bondahx.com\/index.php\/wp-json\/wp\/v2\/categories?post=47175"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/bondahx.com\/index.php\/wp-json\/wp\/v2\/tags?post=47175"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}