Over 40,000 Servers Compromised in cPanel Exploitation, Urgent Patching Required
A critical vulnerability in cPanel & WebHost Manager (WHM), identified as CVE-2026-41940, has led to the compromise of over 40,000 servers. This security flaw allows unauthenticated attackers to gain administrative access, potentially taking over host systems and compromising configurations, databases, and websites. The vulnerability was disclosed on April 28, and exploitation has been ongoing since late February, with a significant increase in activity following public disclosure. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added this vulnerability to its Known Exploited Vulnerabilities catalog, urging immediate patching.