Actively exploited cPanel bug exposes millions of websites to takeover

2026-05-02T20:51:53Zdf4317cd480113eff79b95c04c87e0f5528fa29e6cd915f516dac00ed4789b1f
WHMactively-exploitedauthentication-bypasscPanelpatch-or-mitigatesecurity-alertvulnerabilityweb-hostingwebsite-takeover

What happened

Malwarebytes reports an actively exploited vulnerability in the cPanel/WHM administrative interface that allows unauthenticated access to websites and hosting accounts, enabling site takeover without a username or password. The flaw impacts cPanel-managed sites at scale (millions of websites) and is being abused in the wild; administrators should apply vendor fixes or mitigations immediately, restrict access to WHM/cPanel interfaces, review logs for unauthorized access, and rotate credentials.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
malwarebytes_labs
Record identifier
df4317cd480113eff79b95c04c87e0f5528fa29e6cd915f516dac00ed4789b1f
Enrichment time
2026-05-02T20:51:53Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.