A critical security vulnerability in cPanel and WHM, one of the world’s most widely used web hosting control panels, has triggered a global cybersecurity alert after hackers began actively exploiting the flaw to gain unauthorized access to servers and websites. The vulnerability, identified as CVE-2026-41940, allows attackers to bypass authentication protections and potentially take control of hosting servers without valid login credentials. Cybersecurity researchers say the flaw is already being used in real-world attacks targeting hosting providers, businesses, and website owners across multiple countries. Timeline of Events: February 2026: Security experts believe the vulnerability may have first been exploited secretly by attackers. April 28, 2026: cPanel released emergency security patches and advisories for affected versions. April 29, 2026: The vulnerability was publicly disclosed under CVE-2026-41940. Early May 2026: Reports of mass exploitation, malware infections, phishing pages, and ransomware attacks started increasing globally. According to cybersecurity firms, attackers are using the flaw to: Hijack hosting servers Inject malware into websites Create fake admin accounts Steal databases and customer information Redirect visitors to phishing or scam pages Launch ransomware attacks Because a single cPanel server can host hundreds of websites, one successful breach can impact multiple businesses at the same time. Security researchers estimate that thousands of servers may already have been targeted worldwide. Hosting companies and security agencies are now urging administrators to immediately update cPanel and WHM installations, enable two-factor authentication, rotate passwords, and scan servers for suspicious activity. Experts have warned that organizations delaying updates could face website defacement, data theft, service outages, or complete server compromise. How Website Owners and Server Administrators Can Stay Safe Cybersecurity experts have advised website owners, hosting companies, and server administrators to take immediate precautions to reduce the risk of attacks: Update cPanel and WHM to the latest patched version immediately. Enable Two-Factor Authentication (2FA) for all admin and hosting accounts. Change all passwords including root, WHM, cPanel, FTP, database, and email passwords. Restrict WHM and SSH access using firewall rules or IP allowlists. Regularly monitor server logs for suspicious login attempts or unusual activity. Remove unused plugins, themes, scripts, and inactive hosting accounts. Use security tools such as Imunify360, ClamAV, Maldet, or other malware scanners. Keep daily offsite backups so websites can be restored quickly if attacked. Disable unnecessary services and ports on the server. Train employees and website managers to identify phishing emails and fake login pages. Monitor website files for unexpected changes, redirects, or hidden PHP scripts. Use a Web Application Firewall (WAF) and DDoS protection services for additional security. Experts say proactive monitoring and timely security updates remain the most effective defense against large-scale hosting attacks like the current cPanel vulnerability. Post navigation OpenAI Rolls Out GPT-5: Faster, Smarter, and More Human-Like Than Ever GFT Technologies Teams Up With Google Cloud to Automate Complex Financial Tasks Using Gemini Enterprise