First reports come in of victims of critical cPanel vuln as 'millions' of sites potentially exposed
2026-05-01T19:23:57Z•f2c124810f329c93653cfe727c31cc9b7d68435e62a55add81654c168576adc2
0-dayCISA-known-exploitedWHMauthentication-bypasscPanelincident-responselocal-rootpatch-nowransomwareremote-exploitationweb-hosting
What happened
A critical authentication-bypass vulnerability in cPanel/WHM that can lead to root access is being actively exploited (likely as a 0‑day) and has been added to CISA’s known‑exploited vulnerabilities list. Emergency patches are available but exploitation began before fixes landed; at least one victim reported a ransomware demand. Millions of hosted sites could be exposed — administrators must apply vendor updates and investigate potential compromises immediately.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- theregister_security
- Record identifier
- f2c124810f329c93653cfe727c31cc9b7d68435e62a55add81654c168576adc2
- Enrichment time
- 2026-05-01T19:23:57Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.