Signal

Critical cPanel vulnerability actively exploited, exposing millions of websites to takeover

Evidence first: scan the strongest sources, then decide whether to go deeper.

Published 2026-05-01 10:48 UTCUpdated 2026-05-01 18:20 UTC
rss
cveexploitssecurity_toolingincident_responsesecurity_policy
Source links open
Source links and full evidence are open here. Pro adds archive history, compare-over-time, alerts, exports, and workflow. Business adds Feed API integrations and team usage.
No card needed for the free brief.
Evidence trail (top sources)
top sources (4 domains)domains are deduped. counts indicate coverage, not truth.
4 top sources shown
Attacks Surge Against Vulnerable cPanel and WHM Software
BankInfoSecurity · News · bankinfosecurity.com · 2026-05-01 18:20 UTC
Federal agencies must patch cPanel bug by Sunday, CISA says
The Record (Recorded Future News) · News · therecord.media · 2026-05-01 16:20 UTC
Actively exploited cPanel bug exposes millions of websites to takeover
Malwarebytes Threat Analysis · News · malwarebytes.com · 2026-05-01 10:48 UTC
Overview

A critical authentication bypass vulnerability (CVE-2026-41940) in cPanel and WebHost Manager (WHM) is being actively exploited, allowing attackers to gain administrative access without credentials.

Entities
cPanelNamecheapHostGatorKnownHost
Score total
1.22
Momentum 24h
4
Posts
4
Origins
4
Source types
1
Duplicate ratio
0%
Why now
  • Exploitation began before patches were released on April 28, 2026.
  • CISA has issued urgent patching orders to federal agencies to mitigate risk.
  • Hosting providers have temporarily blocked access to cPanel interfaces to prevent further attacks.
Why it matters
  • The vulnerability allows attackers to gain full administrative control over millions of websites.
  • Critical infrastructure sectors like banking and healthcare are at risk due to widespread cPanel use.
  • Unpatched systems have already been compromised, leading to ransomware demands.
LLM analysis
Topic mix: lowPromo risk: lowSource quality: medium
Recurring claims
  • CVE-2026-41940 is a critical authentication bypass vulnerability in cPanel/WHM actively exploited in the wild.
  • CISA has added CVE-2026-41940 to its Known Exploited Vulnerabilities catalog and ordered federal agencies to patch it urgently.
  • Tens of thousands of hosting dashboards have been compromised, with reports of ransomware demands following exploitation.
How sources frame it
  • Malwarebytes Threat Analysis: neutral
This ongoing exploitation of a critical cPanel vulnerability demands immediate attention from hosting providers and organizations using cPanel/WHM to apply patches and mitigate risk.
All evidence
All evidence
Attacks Surge Against Vulnerable cPanel and WHM Software
BankInfoSecurity · bankinfosecurity.com · 2026-05-01 18:20 UTC
Federal agencies must patch cPanel bug by Sunday, CISA says
The Record (Recorded Future News) · therecord.media · 2026-05-01 16:20 UTC
First reports come in of victims of critical cPanel vuln as 'millions' of sites potentially exposed
theregister_security · go.theregister.com · 2026-05-01 13:10 UTC
Actively exploited cPanel bug exposes millions of websites to takeover
Malwarebytes Threat Analysis · malwarebytes.com · 2026-05-01 10:48 UTC
Show filters & breakdown
Posts loaded: 0Publishers: 4Origin domains: 4Duplicates: -
Showing 4 / 4
Top publishers (this list)
  • BankInfoSecurity (1)
  • The Record (Recorded Future News) (1)
  • theregister_security (1)
  • Malwarebytes Threat Analysis (1)
Top origin domains (this list)
  • bankinfosecurity.com (1)
  • therecord.media (1)
  • go.theregister.com (1)
  • malwarebytes.com (1)