Critical cPanel Vulnerability Exploited by Hackers, Prompting Urgent Patch
Patch cPanel immediately to stop exploitation.
Patch cPanel to the latest version and monitor logs for suspicious activity.
Summary
A critical remote‑code‑execution flaw in the widely used web‑hosting control panel cPanel and its WHM component has been weaponised by attackers to target government and managed service provider (MSP) networks. The vulnerability, identified as CVE‑2026‑xxxx, allows unauthenticated attackers to gain shell access to hosting accounts on affected servers, enabling the injection of malware and theft of sensitive data. The flaw was first disclosed in early May 2026 and has already been exploited against thousands of websites, with recent incident reports confirming ongoing attacks.
cPanel versions 11.96 and earlier are vulnerable; the vendor released a patch, cPanel 11.96.1, on 2 May 2026. The update requires a server reboot to take effect and must be applied immediately to halt further exploitation. Despite the patch, security advisories warn that the vulnerability remains active and that attackers continue to use it to compromise sites. Hosting providers and site owners are urged to update to 11.96.1 or later, reboot their servers, and conduct a thorough review of server logs for suspicious SSH activity. Failure to patch could lead to data loss, prolonged downtime, and significant reputational damage.
The incident underscores the critical importance of timely security updates in shared‑hosting environments. cPanel’s popularity—serving millions of websites worldwide—means that a single unpatched flaw can have widespread repercussions. The advisory also highlights the need for continuous monitoring and incident response plans, especially for organisations that rely on third‑party hosting services. As attackers adapt to new defensive measures, the cybersecurity community remains vigilant, urging all users of cPanel to act swiftly and maintain robust patch management practices.
Key changes
- Threat actor targeting government and military in Southeast Asia
- Also targeting MSPs and hosting providers in Philippines, Laos, Canada, South Africa, U.S.
- Exploiting cPanel vulnerability
- Detected May 2, 2026
- Active exploitation evidence