Signal

Critical cPanel vulnerability actively exploited, exposing millions of websites to takeover

Evidence first: scan the strongest sources, then decide whether to go deeper.

Published 2026-05-01 10:48 UTCUpdated 2026-05-01 18:20 UTC
rss
cveexploitssecurity_toolingincident_responsesecurity_policy
Trend in the last 24h
Source links open
Source links and full evidence are open here. Archive history, compare-over-time, alerts, exports, API, integrations, and workflow are paid.
No card needed for the free brief.
Evidence trail (top sources)
top sources (4 domains)domains are deduped. counts indicate coverage, not truth.
4 top sources shown
Attacks Surge Against Vulnerable cPanel and WHM Software
BankInfoSecurity · News · bankinfosecurity.com · 2026-05-01 18:20 UTC
Federal agencies must patch cPanel bug by Sunday, CISA says
The Record (Recorded Future News) · News · therecord.media · 2026-05-01 16:20 UTC
Actively exploited cPanel bug exposes millions of websites to takeover
Malwarebytes Threat Analysis · News · malwarebytes.com · 2026-05-01 10:48 UTC
Overview

A critical authentication bypass vulnerability (CVE-2026-41940) in cPanel and WebHost Manager (WHM) is being actively exploited, allowing attackers to gain administrative access without credentials.

Entities
cPanelNamecheapHostGatorKnownHost
Score total
1.22
Momentum 24h
4
Posts
4
Origins
4
Source types
1
Duplicate ratio
0%
Why now
  • Exploitation began before patches were released on April 28, 2026.
  • CISA has issued urgent patching orders to federal agencies to mitigate risk.
  • Hosting providers have temporarily blocked access to cPanel interfaces to prevent further attacks.
Why it matters
  • The vulnerability allows attackers to gain full administrative control over millions of websites.
  • Critical infrastructure sectors like banking and healthcare are at risk due to widespread cPanel use.
  • Unpatched systems have already been compromised, leading to ransomware demands.
LLM analysis
Topic mix: lowPromo risk: lowSource quality: medium
Recurring claims
  • CVE-2026-41940 is a critical authentication bypass vulnerability in cPanel/WHM actively exploited in the wild.
  • CISA has added CVE-2026-41940 to its Known Exploited Vulnerabilities catalog and ordered federal agencies to patch it urgently.
  • Tens of thousands of hosting dashboards have been compromised, with reports of ransomware demands following exploitation.
How sources frame it
  • Malwarebytes Threat Analysis: neutral
This ongoing exploitation of a critical cPanel vulnerability demands immediate attention from hosting providers and organizations using cPanel/WHM to apply patches and mitigate risk.
All evidence
All evidence
Attacks Surge Against Vulnerable cPanel and WHM Software
BankInfoSecurity · bankinfosecurity.com · 2026-05-01 18:20 UTC
Federal agencies must patch cPanel bug by Sunday, CISA says
The Record (Recorded Future News) · therecord.media · 2026-05-01 16:20 UTC
First reports come in of victims of critical cPanel vuln as 'millions' of sites potentially exposed
theregister_security · go.theregister.com · 2026-05-01 13:10 UTC
Actively exploited cPanel bug exposes millions of websites to takeover
Malwarebytes Threat Analysis · malwarebytes.com · 2026-05-01 10:48 UTC
Show filters & breakdown
Posts loaded: 0Publishers: 4Origin domains: 4Duplicates: -
Showing 4 / 0
Top publishers (this list)
  • BankInfoSecurity (1)
  • The Record (Recorded Future News) (1)
  • theregister_security (1)
  • Malwarebytes Threat Analysis (1)
Top origin domains (this list)
  • bankinfosecurity.com (1)
  • therecord.media (1)
  • go.theregister.com (1)
  • malwarebytes.com (1)