Observed Signal · May 4, 2026 · Security Incident · Source: techcrunch · Impact: 4/5 · Sentiment: Negative
Hackers Mass-Exploit cPanel Bug, Compromising Thousands
Days after a critical vulnerability disclosure in cPanel and WebHost Manager (WHM), attackers are mass-exploiting the flaw to compromise thousands of websites and servers. Shadowserver reports more than 550,000 potentially vulnerable cPanel servers and roughly 2,000 likely compromised instances (down from about 44,000). The flaw is tracked as CVE-2026-41940; the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added it to its Known Exploited Vulnerabilities catalog and urged agencies to patch immediately. Some compromised sites displayed ransom notes and evidence of file encryption. KnownHost says attacks may have been occurring since Feb. 23. cPanel acknowledged outreach but did not provide a substantive comment in the article.
Widespread exploitation of a critical web-hosting control-panel vulnerability affects hundreds of thousands of servers and thousands of websites, posing immediate risks to publishers, hosted content, and potentially ad inventory and measurement—prompting CISA emergency action.
Track Google Signals & Market Shifts in Real-Time
Polaris7 autonomous intelligence agents track regulatory filings, primary sources, executive changes, and deal flow 24/7. Create your free Explorer workspace to monitor these entities.
Key Takeaways & Evidence Grounding
- cPanel/WHM vulnerability tracked as CVE-2026-41940 is being actively exploited in the wild.
- Shadowserver reports more than 550,000 potentially vulnerable servers running cPanel.
- Approximately 2,000 cPanel instances are likely compromised, down from around 44,000 earlier in the week.
- CISA added the vulnerability to its Known Exploited Vulnerabilities (KEV) catalog and urged government agencies to patch by Sunday.
- KnownHost detected attacks exploiting the issue as early as February 23, according to its CEO Daniel Pearson.
Connected Companies & Entities
1 Entity mappedOntology Mapping & Concepts
Related Market Signals & Shifts
Recent verified developments and strategic activity across this market segment.
Active Exploits Target cPanel Bug (CVE-2026-41940)
A critical vulnerability (CVE-2026-41940) in widely used server-management software cPanel and WebHost Manager (WHM) is being actively exploited, allowing attackers to bypass the login screen and gain full administrative control of affected servers. The flaw affects all supported versions and could compromise websites on shared hosting. Major hosts have been patching systems and, in some cases, temporarily blocked access to cPanel panels to prevent abuse. Canada’s national cybersecurity agency issued an advisory saying exploitation is "highly probable" and urged immediate action. KnownHost reported attempted exploitation dating back to February 23, and other providers including Namecheap and HostGator implemented mitigations and patches. cPanel and third-party tools such as WP Squared have released fixes or updates.
Hackers Exploit Recently Patched WordPress Flaws
Security researchers and multiple cybersecurity firms warn that attackers are actively exploiting two recently patched critical WordPress vulnerabilities (affecting versions 6.9.0–6.9.4 and 7.0.0–7.0.1). WordPress pushed immediate and, where possible, forced updates after the fixes were released. Firms including Patchstack, Hexastrike, and WatchTowr reported in-the-wild exploitation. Researcher Daniel Card sampled ~4,200 sites and estimates under 15% remain vulnerable, which could extrapolate to roughly 90 million at-risk WordPress sites. The exploit chain includes a vulnerability dubbed WP2Shell, reported by Adam Kues of Searchlight Cyber. Cloudflare and web application firewalls have helped block some attacks while many sites remain exposed.
Security Audit Finds Critical Issues on WHM/cPanel Server
A production WHM/cPanel server used by a web agency was audited and found to have multiple critical security and operational issues, including an OpenSSH version vulnerable to a remote-code-execution CVE, SSH exposed to the internet with root and password logins enabled, end-of-life PHP versions in production, untested and failing backups, and no custom firewall rules. The author provides a concise one-hour checklist: check vulnerable services and pending security updates, harden SSH (disable root, use keys, restrict users), install and configure CSF/LFD firewall, audit PHP versions via WHM/whmapi1, test backup restores, audit user/sudo privileges, enable symlink protection and ModSecurity, and disable or harden unused services. The post emphasizes that these problems are common on long-running cPanel servers where no one actively maintains ownership.
Track Real-Time Market Signals & Shifts
Set up custom watchlists to receive automated, evidence-grounded executive digests whenever material signals or shifts occur across your tracked landscape.
