Actively exploited cPanel bug exposes millions of websites to takeover
2026-05-02T20:51:53Z•df4317cd480113eff79b95c04c87e0f5528fa29e6cd915f516dac00ed4789b1f
WHMactively-exploitedauthentication-bypasscPanelpatch-or-mitigatesecurity-alertvulnerabilityweb-hostingwebsite-takeover
What happened
Malwarebytes reports an actively exploited vulnerability in the cPanel/WHM administrative interface that allows unauthenticated access to websites and hosting accounts, enabling site takeover without a username or password. The flaw impacts cPanel-managed sites at scale (millions of websites) and is being abused in the wild; administrators should apply vendor fixes or mitigations immediately, restrict access to WHM/cPanel interfaces, review logs for unauthorized access, and rotate credentials.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- malwarebytes_labs
- Record identifier
- df4317cd480113eff79b95c04c87e0f5528fa29e6cd915f516dac00ed4789b1f
- Enrichment time
- 2026-05-02T20:51:53Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.