Authentication bypass in cPanel

I usually wouldn’t post cPanel news, but this came across my feed and I know there are some folks here who use both Virtualmin and cPanel…and this is pretty serious and needs urgent attention. If you’ve got cPanel systems, update them now.

https://support.cpanel.net/hc/en-us/articles/40073787579671-Security-CVE-2026-41940-cPanel-WHM-WP2-Security-Update-04-28-2026

3 Likes

“One web hosting company says it found evidence that hackers have been abusing the vulnerability for months before the attempts were discovered.”
From article on Slashdot. So you may have some investigating ahead of you. :frowning:
(Slightly off topic? I just blocked a /24 listed as being in Tehran yesterday. Not sure if the timing is coincidental here.)