First reports come in of victims of critical cPanel vuln as 'millions' of sites potentially exposed

2026-05-01T19:23:57Zf2c124810f329c93653cfe727c31cc9b7d68435e62a55add81654c168576adc2
0-dayCISA-known-exploitedWHMauthentication-bypasscPanelincident-responselocal-rootpatch-nowransomwareremote-exploitationweb-hosting

What happened

A critical authentication-bypass vulnerability in cPanel/WHM that can lead to root access is being actively exploited (likely as a 0‑day) and has been added to CISA’s known‑exploited vulnerabilities list. Emergency patches are available but exploitation began before fixes landed; at least one victim reported a ransomware demand. Millions of hosted sites could be exposed — administrators must apply vendor updates and investigate potential compromises immediately.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
theregister_security
Record identifier
f2c124810f329c93653cfe727c31cc9b7d68435e62a55add81654c168576adc2
Enrichment time
2026-05-01T19:23:57Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.