Switch language한국어
Back to the list

cPanel vulnerability leads to massive hacks

TL;DR AI

Key summary

2 min read
  1. Attackers are widely exploiting a newly disclosed cPanel/WebHost Manager flaw, CVE-2026-41940, to take over unpatched servers and websites.

  2. Monitoring groups said more than 550,000 servers may be vulnerable, though suspected compromises dropped from about 44,000 to 2,000 as some systems were patched or recovered.

  3. CISA added the bug to its actively exploited vulnerabilities list after signs of website defacement and ransomware-like tampering.

  4. The issue is high risk because cPanel powers many hosting environments and exposed servers can be fully controlled by attackers.

Read the original