WhisperX tag archive

#cpanel

This page collects WhisperX intelligence signals tagged #cpanel. It is designed for humans, search engines, and AI agents: each item links to a canonical source-backed record with sector, source, timestamp, credibility, and exportable structured data.

Latest Signals (14)

The Lab · 2026-04-30 11:24:06 · The Register

1. cPanel Emergency Patch Fails to Confirm Full Scope of Authentication Bypass Zero-Day Exposure

Security teams are racing to apply emergency patches after a critical authentication bypass vulnerability in cPanel and WebHost Manager (WHM) was identified and likely actively exploited in the wild. The flaw grants attackers root-level server access, potentially compromising the millions of domains managed through the...

The Lab · 2026-04-30 19:54:11 · Hacker News

2. Active Exploitation Confirmed: Critical cPanel Vulnerability Under Coordinated Attack, Months-Long Abuse Suspected

Security teams at web hosting providers are racing to patch a critical vulnerability in cPanel, the widely deployed web hosting control panel, after researchers confirmed that threat actors are actively exploiting the flaw in the wild. The scale of exposure is significant: cPanel powers millions of websites and server ...

The Lab · 2026-05-01 00:54:16 · GitHub Issues

3. Critical Auth Bypass Vulnerability CVE-2026-41940 in cPanel/WHM and WP2 WordPress Squared Puts Hosting Infrastructure Under Immediate Pressure

A critical authentication bypass vulnerability, CVE-2026-41940, has been identified in WebPros cPanel & WHM (versions 11.40 through 136.x) and WP2 WordPress Squared (prior to 136.1.7), triggering urgent patching efforts across web hosting environments. The flaw, classified as CWE-306 (Missing Authentication for Critica...

The Lab · 2026-05-01 13:54:08 · The Register

4. Critical cPanel Vulnerability Under Active Exploitation Before Patch Release, CISA Confirms

A critical vulnerability in cPanel, one of the internet's most widely deployed web hosting control panels, is now confirmed under active exploitation with at least one victim reporting a ransomware demand. Security researchers and federal authorities have raised alarm over the timing of the attacks, which began before ...

The Lab · 2026-05-04 09:54:06 · Golem.de

5. Kritische cPanel-Lücke ermöglicht Ransomware-Injektionen in Webportale

Eine kritische Sicherheitslücke in cPanel wird aktiv von Angreifern ausgenutzt, um Ransomware auf Webportale zu schleusen. Betreiber von Webdiensten stehen unter Druck, ihre Installationen umgehend auf Kompromittierungen zu prüfen. Die Schwachstelle erlaubt es Unbefugten, Schadcode in verwaltete Webseiten einzuschleuse...

The Lab · 2026-05-04 18:24:10 · TechCrunch

6. Active Exploitation Confirmed: Critical cPanel Flaw Threatens Thousands of Hosting Environments

Security researchers are tracking an active campaign targeting a critical vulnerability in cPanel and WHM, the widely deployed web hosting control panel software. Days after the flaw entered public disclosure, threat actors have moved swiftly to exploit the weakness, gaining the ability to seize control of affected web...

The Lab · 2026-05-08 04:16:19 · The Hacker News

7. Unidentified Threat Actor Exploits cPanel Flaw to Breach Government Networks Across Southeast Asia

Security researchers at Ctrl-Alt-Intel have identified an active campaign exploiting a recently patched vulnerability in cPanel, the widely deployed web hosting control panel. The operation, detected on May 2, 2026, primarily targets government and military infrastructure across Southeast Asian nations. A secondary clu...

The Lab · 2026-05-09 11:01:41 · Mastodon:mastodon.social:#infosec

8. CVE-2026-29203: cPanel Nova Plugin Symlink Flaw Enables Root Privilege Escalation

A high-severity vulnerability tracked as CVE-2026-29203 (CVSS 8.8) has been disclosed in cPanel's Nova plugin, exposing a symlink-following flaw that could allow authenticated users to manipulate root-level permissions on arbitrary system files. The vulnerability resides in the Cpanel::Nova::Connector component, where ...

The Lab · 2026-05-09 12:31:51 · GitHub Issues

9. cPanel Patches Critical RCE and Privilege Escalation Flaws as ShinyHunters Claims Second Instructure Breach

Two high-severity security developments emerged overnight, exposing critical infrastructure risks across hosting platforms and educational technology. cPanel and WHM released emergency patches for three vulnerabilities, including remote code execution (RCE) and privilege escalation flaws—weaknesses that could allow att...

The Lab · 2026-05-09 14:32:08 · Mastodon:hachyderm.io:#infosec

10. cPanel & WHM Zero-Day Mass Exploited: 40,000+ Servers at Risk as Microsoft Defender and Linux Flaws Also Under Active Attack

Three critical zero-day vulnerabilities are under active exploitation, with cPanel & WHM emerging as the most severe incident: a zero-day flaw has been mass exploited, potentially compromising more than 40,000 servers worldwide. The scale of the cPanel attack positions this as one of the most significant web hosting in...

The Lab · 2026-05-09 18:31:52 · Mastodon:mastodon.social:#cybersecurity

11. cPanel's Black Week: Three Critical Vulnerabilities Patched After Ransomware Attack Hits 44,000 Servers

cPanel, one of the most widely used web hosting control panels globally, has released emergency patches for three newly discovered vulnerabilities following a ransomware attack that compromised approximately 44,000 servers. The timing of the disclosures and the scale of the breach have intensified scrutiny on the platf...

The Lab · 2026-05-09 18:31:53 · Mastodon:mastodon.social:#cybersecurity

12. cPanel's Black Week: Three Critical Vulnerabilities Patched After Ransomware Hits 44,000 Servers

cPanel, one of the most widely used web hosting control panels globally, has patched three newly discovered vulnerabilities following what security observers are calling its "Black Week"—a ransomware campaign that compromised approximately 44,000 servers. The scale of the incident has sent shockwaves through the hostin...

The Lab · 2026-05-10 18:31:51 · r/AskNetsec

13. Massive XMR Mining Operation Discovered on Compromised cPanel Servers; Attacker Exploited Auth Bypass CVE, Staged Credential Harvester Targeting Cloud Infrastructure

Security researchers are tracking an active cryptojacking campaign that has compromised cPanel/WHM servers by exploiting a recent authentication bypass vulnerability. The attacker gained root-level access and established persistence through a backdoor account named "pakchoi" with root group (GID 0) privileges, using it...

The Lab · 2026-05-11 19:48:21 · The Hacker News Echo RSS

14. CVE-2026-41940 Critical Flaw in cPanel Actively Exploited; Threat Actor Mr_Rot13 Deploys Filemanager Backdoor

A critical vulnerability in cPanel and WebHost Manager (WHM) designated CVE-2026-41940 is under active exploitation by a threat actor identified as Mr_Rot13, who is deploying a backdoor named Filemanager on compromised servers. The flaw enables authentication bypass, granting remote attackers elevated control over web ...