#cpanel


CISA gives feds 4 days to patch actively exploited cPanel plugin flaw

May 27, 2026 // 13:16

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has given U.S. federal agencies four days to secure their servers against a critical vulnerability in the […]

LiteSpeed cPanel Plugin CVE-2026-48172 Exploited to Run Scripts as Root

May 23, 2026 // 10:48

A maximum-severity security vulnerability impacting LiteSpeed User-End cPanel Plugin has come under active exploitation in the wild. The flaw, tracked as CVE-2026-48172 (CVSS score: 10.0), […]

LiteSpeed cPanel Plugin CVE-2026-48172 Exploited to Run Scripts as Root

May 23, 2026 // 10:46

A maximum-severity security vulnerability impacting LiteSpeed User-End cPanel Plugin has come under active exploitation in the wild. The flaw, tracked as CVE-2026-48172 (CVSS score: 10.0), […]

cPanel CVE-2026-41940 Under Active Exploitation to Deploy Filemanager Backdoor

May 12, 2026 // 00:07

A threat actor named Mr_Rot13 has been attributed to the exploitation of a recently disclosed critical cPanel flaw to deploy a backdoor codenamed Filemanager on […]

cPanel, WHM Release Fixes for Three New Vulnerabilities — Patch Now

May 9, 2026 // 10:48

cPanel has released updates to address three vulnerabilities in cPanel and Web Host Manager (WHM) that could be exploited to achieve privilege escalation, code execution, […]

Critical cPanel Vulnerability Weaponized to Target Government and MSP Networks

May 4, 2026 // 12:34

A previously unknown threat actor has been observed targeting government and military entities in Southeast Asia, alongside a smaller cluster of managed service providers (MSPs) […]

Critrical cPanel flaw mass-exploited in “Sorry” ransomware attacks

May 3, 2026 // 00:56

A new disclosed cPanel flaw tracked as CVE-2026-41940 is being mass-exploited to breach websites and encrypt data in “Sorry” ransomware attacks. This week, an emergency […]

Critical cPanel Authentication Vulnerability Identified — Update Your Server Immediately

May 1, 2026 // 00:41

cPanel has released security updates to address a security issue impacting various authentication paths that could allow an attacker to obtain access to the control […]

Critical cPanel and WHM bug exploited as a zero-day, PoC now available

May 1, 2026 // 00:17

The critical CVE-2026-41940 authentication bypass vulnerability in cPanel, WHM, and WP Squared is being actively exploited in the wild and has been leveraged in attempts […]

cPanel, WHM emergency update fixes critical auth bypass bug

Apr 29, 2026 // 18:57

A critical vulnerability affecting all but the latest versions of cPanel and the WebHost Manager (WHM) dashboard could be exploited to obtain access to the […]