Over 40,000 servers have likely been compromised in ongoing attacks targeted at a recently patched cPanel zero-day.
Panel patched three vulnerabilities, including two 8.8 CVSS flaws, reducing risks of code execution and privilege escalation.
Web hosts are scrambling to fix the bug under active attack by hackers. One company said hackers have been abusing the bug for months.
The vulnerability has been given a severity score of 9,8, and administrators should patch immediately.
Days after the disclosure of a critical vulnerability in popular web hosting software cPanel and WHM, hackers keep targeting ...
The critical CVE-2026-41940 authentication bypass vulnerability in cPanel, WHM, and WP Squared is being actively exploited in the wild and has been leveraged in attempts since late February. It is ...
A critical vulnerability affecting all but the latest versions of cPanel and the WebHost Manager (WHM) dashboard could be exploited to obtain access to the control panel without authentication. The ...
Security researchers have identified a critical flaw in cPanel and WebHost Manager that could allow attackers to bypass ...