Close Menu
AI News TodayAI News Today

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Congress keeps kicking surveillance reform down the road

    Legal AI startup Legora hits $5.6 valuation and its battle with Harvey just got hotter

    The most severe Linux threat to surface in years catches the world flatfooted

    Facebook X (Twitter) Instagram
    • About Us
    • Contact Us
    Facebook X (Twitter) Instagram Pinterest Vimeo
    AI News TodayAI News Today
    • Home
    • Shop
    • AI News
    • AI Reviews
    • AI Tools
    • AI Tutorials
    • Chatbots
    • Free AI Tools
    AI News TodayAI News Today
    Home»Chatbots»Hackers are actively exploiting a bug in cPanel, used by millions of websites
    Chatbots

    Hackers are actively exploiting a bug in cPanel, used by millions of websites

    By No Comments3 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    a cPanel login screen showing the username and password prompt
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Security researchers are sounding the alarm on a newly discovered vulnerability in the widely used web server management software cPanel and WebHost Manager (WHM). 

    The bug allows hackers to hijack and take full control of the servers running the affected software, which is thought to be used by tens of millions of website owners around the world.

    Many commercial web hosting companies have patched their customers’ systems already. But the cPanel maker urged customers to ensure that their systems are patched as the bug affects all supported versions of the software.

    cPanel and WHM are two software suites used for managing web servers that host websites, manage emails, and handle important configurations and databases needed to maintain an internet domain. The two suites have deep-access to the servers that they manage, allowing a malicious hacker potentially unrestricted access to data managed by the affected software.

    The bug, officially tracked as CVE-2026-41940, allows malicious hackers to remotely bypass its login screen to gain full access to the software’s administration panel. 

    Given the ubiquity of the cPanel and WHM software across the web hosting industry, hackers could compromise potentially large numbers of websites that haven’t patched the bug.

    Canada’s national cybersecurity agency said in an advisory that the bug could be exploited to compromise websites on shared hosting servers, such as large web hosting companies.

    The agency said that “exploitation is highly probable” and that immediate action from cPanel customers, or their web hosts, is necessary to prevent malicious access.

    Web hosting giant Namecheap, which uses cPanel to allow its customers to manage their web servers, said the company blocked access to customers’ cPanel panels after learning of the flaw to prevent exploitation, and to give it time to patch its customers’ systems. 

    Hostgator also said it patched its systems and is considering the bug a “critical authentication-bypass exploit.”

    One web hosting company says it found evidence that hackers have been abusing the vulnerability for months before the attempts were discovered.

    KnownHost CEO Daniel Pearson said in a post on Reddit that his company has seen attempts to exploit the vulnerability as far back as February 23. The company said it also briefly began blocking access to customer systems before applying patches.

    According to Pearson, around 30 servers at KnownHost showed signs of unauthorized attempted access out of thousands of computers on its network. Pearson likened the efforts to attempts, and has not seen signs of active compromise. cPanel also said it rolled out a security fix for WP Squared, a similar tool for managing WordPress websites.

    When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.

    actively bug cPanel exploiting hackers millions websites
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleResearchers try to cut the genetic code from 20 to 19 amino acids
    Next Article The most severe Linux threat to surface in years catches the world flatfooted
    • Website

    Related Posts

    Chatbots

    Congress keeps kicking surveillance reform down the road

    Chatbots

    Beijing bans drone sales even as rest of world buys Chinese drones

    Chatbots

    Xbox owners can now disable Quick Resume for specific games

    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    Congress keeps kicking surveillance reform down the road

    0 Views

    Legal AI startup Legora hits $5.6 valuation and its battle with Harvey just got hotter

    0 Views

    The most severe Linux threat to surface in years catches the world flatfooted

    0 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews
    AI Tutorials

    Quantization from the ground up

    AI Tools

    David Sacks is done as AI czar — here’s what he’s doing instead

    AI Reviews

    Judge sides with Anthropic to temporarily block the Pentagon’s ban

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Most Popular

    Congress keeps kicking surveillance reform down the road

    0 Views

    Legal AI startup Legora hits $5.6 valuation and its battle with Harvey just got hotter

    0 Views

    The most severe Linux threat to surface in years catches the world flatfooted

    0 Views
    Our Picks

    Quantization from the ground up

    David Sacks is done as AI czar — here’s what he’s doing instead

    Judge sides with Anthropic to temporarily block the Pentagon’s ban

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Terms & Conditions
    • Privacy Policy
    • Disclaimer

    © 2026 ainewstoday.co. All rights reserved. Designed by DD.

    Type above and press Enter to search. Press Esc to cancel.