Critical cPanel Flaw Actively Exploited

A critical cPanel vulnerability, CVE-2026-41940, is actively exploited, allowing hackers to gain full server control, impacting millions of websites.

Jason Kwon ·

Critical cPanel Flaw Actively Exploited

cPanel Vulnerability Under Active Exploitation A critical vulnerability in cPanel and WebHost Manager (WHM) software, identified as CVE-2026-41940, is under active exploitation by hackers as of April 30, 2026. This flaw allows unauthorized remote access to server administration panels, impacting potentially millions of websites globally that utilize these web server management tools.

The vulnerability enables attackers to bypass login screens and gain full control over affected servers. Given cPanel's widespread use in web hosting, this poses a significant risk for data compromise and website hijacking across numerous platforms. Canada's national cybersecurity agency has issued an advisory, stating that exploitation is highly probable and necessitates immediate patching.

While many commercial web hosting providers have already applied necessary patches, cPanel has urged all customers to ensure their systems are updated. The vulnerability affects all supported versions of the software, making comprehensive patching essential to mitigate the risk of malicious actors gaining unrestricted access to managed data and hosted websites.

More stories