Compute & Cloud
cPanel vulnerability allows server hijacking
Hackers are actively exploiting a critical cPanel vulnerability, thought to affect tens of millions of websites, allowing them to hijack and take full control of servers.
Security researchers are sounding the alarm on a newly discovered vulnerability in cPanel and WHM, which are suites of web server management software used to manage web servers, host websites, manage emails, and handle configurations and databases. The bug, officially tracked as CVE-2026-41940, allows hackers to remotely bypass login screens to gain full access to the administration panel. Because these suites have deep access to the servers they manage, the bug allows hackers to hijack and take full control of the systems. This vulnerability affects all supported versions of the software, which is thought to be used by tens of millions of website owners around the world. Hackers are actively exploiting the bug, potentially giving a malicious hacker unrestricted access to managed data. While many commercial web hosting companies have already patched their customers’ systems, the cPanel maker urged all customers to ensure their systems are updated.
Canada’s national cybersecurity agency has issued an advisory regarding the flaw, warning that it could be exploited to compromise websites on shared hosting servers. The agency, a national cybersecurity agency, stated that “exploitation is highly probable” and urged immediate action from cPanel customers and web hosts to prevent unauthorized access.
Web hosting companies have moved quickly to secure their infrastructure. Namecheap blocked access to its customers’ cPanel panels to prevent exploitation and allow time to patch its systems. HostGator also patched its systems, characterizing the bug as a critical authentication-bypass exploit. However, evidence suggests that hackers have been abusing the vulnerability for months before discovery. KnownHost observed attempts to exploit the vulnerability as far back as February 23. KnownHost CEO Daniel Pearson stated in a post on Reddit that around 30 servers on the company’s network showed signs of unauthorized attempted access out of thousands of computers. The company briefly blocked access to customer systems before applying patches, and Pearson noted they have not seen signs of active compromise. Additionally, cPanel released a security fix for WP Squared, a tool for managing WordPress websites.
Why it matters
The vulnerability allows hackers to take full control of servers running cPanel and WHM, which are thought to be used by tens of millions of website owners. This has prompted urgent patching warnings from cybersecurity agencies and hosting providers to secure critical web infrastructure.