CISA has added a critical cPanel bug to its known-exploited list, confirming that attackers are already poking holes in one of the internet's most widely used hosting stacks. The vulnerability, tracked as CVE-2026-41940, carries a near-worst-case CVSS score of 9.8 and affects all supported versions of cPanel and Web[Host Manager (WHM) released after version 11.40, along with WP Squared, a WordPress management layer built on top of the same platform. In plain terms, a successful exploit can hand over full control of the server. The US government's cybersecurity agency added the flaw to its Known Exploited Vulnerabilities catalog on Thursday, confirming attackers are not waiting around. By the time cPanel shipped a patch on Tuesday, exploitation was already underway. Hosting provider KnownHost has been more explicit about what that looked like in practice, warning customers it had seen successful exploitation attempts before any fix was available. In a Reddit post, the company's CEO, Daniel Pearson, said the provider had "seen execution attempts as early as 2/23/2026" and urged users to restrict access and assume systems could already be compromised if left unpatched. Another hosting provider, Namecheap, says it temporarily blocked access to cPanel and WHM, effectively slamming the door shut until fixes were ready. It has since begun rolling out updates. There are also early signs of what those attackers are up to once they get in. A small business owner posting on Reddit said ...
First reports come in of victims of critical cPanel vuln as 'millions' of sites potentially exposed
The Register
·Carly Page
·Published May 1, 2026
·Updated
Affected Software
3 affected components
Cpanel Cpanel
Cpanel WebHost Manager (WHM)
WP Squared WP Squared
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses a critical vulnerability in cPanel that has been added to CISA's list of known exploited vulnerabilities.
2
What security implications are discussed in the article?
The article highlights that the vulnerability exposes potentially millions of websites to attacks as malicious actors exploit the flaw.
3
What products or software are affected by the cPanel vulnerability?
The vulnerability affects cPanel and WebHost Manager (WHM), which are widely used in web hosting environments.
4
Who has confirmed the exploitation of the cPanel bug?
CISA has confirmed that attackers are actively exploiting the cPanel vulnerability.
5
What steps should users take in response to this security issue?
Users should promptly update their cPanel and WHM software to mitigate the risk of exploitation.