cPanel Security Crisis: Multiple Exploits Prompt Emergency Patches and Ransomware Attack
Apply the latest cPanel and WHM security update immediately.
Apply the latest cPanel and WHM security update immediately to close the authentication flaw.
Summary
A series of critical vulnerabilities in the widely used cPanel and Web Host Manager (WHM) control panels has triggered a global security emergency. On 12 May 2026, cPanel released a patch that addressed three CVEs—CVE‑2026‑29201, CVE‑2026‑29202, and CVE‑2026‑29203—each affecting file‑handling routines in the admin interface. The flaws, ranging from insufficient input validation to buffer overflows and race conditions, could allow attackers to elevate privileges, execute arbitrary code, or overwrite configuration files. The update, available as cPanel 11.0.4 and WHM 11.0.4, also introduced a new audit‑log module to track failed logins and file‑upload anomalies.
Shortly after the public disclosure, the critical CVE‑2026‑41940 authentication bypass was exploited by a threat actor known as Mr_Rot13. The attacker deployed a backdoor named Filemanager, granting persistent remote code execution and enabling data exfiltration from compromised servers. The backdoor’s silent re‑authentication mechanism made detection difficult, and the incident highlighted the need for continuous log monitoring. Within days, the flaw was actively exploited against thousands of cPanel/WHM installations, with a ransomware campaign reportedly compromising 44,000 web‑hosting servers.
In response, cPanel issued a second emergency patch on 8 May 2026, ten days after the initial breach. The update closed three additional vulnerabilities—likely involving authentication, privilege escalation, and remote code execution—though specific details were not disclosed. The patch also included minor bug fixes and performance improvements. Administrators were urged to apply the latest version immediately and verify that all components were updated, as many sites, especially WordPress and WooCommerce hosts, remained vulnerable.
The ongoing exploitation underscores the critical importance of timely patch management for hosting providers. cPanel’s rapid release cycle and the introduction of audit‑log features aim to mitigate future attacks, but the incident serves as a stark reminder that even well‑established platforms can become targets when security gaps are left unpatched.
Key changes
- Security update addresses authentication path flaw in cPanel/WHM
- Affects all currently supported cPanel and WHM versions
- No official CVE ID assigned
- Patch prevents unauthorized control panel access
- Update available for all supported releases
- Older unsupported versions remain vulnerable