Story perspectives
Critical cPanel Flaw Exploited, Hosts Patch Amid Global Attacks
5/1/2026
1 of 1
Story summary
- Canada’s national cybersecurity agency warned that CVE-2026-41940 in cPanel and WHM lets hackers bypass login screens and hijack servers worldwide.
- cPanel urged customers to patch all supported versions immediately, prompting Namecheap to block cPanel access while applying patches.
- HostGator patched its systems, labeling the flaw a critical authentication-bypass exploit, while KnownHost CEO Daniel Pearson reported exploitation attempts on about 30 servers since February 23.
