Monday, August 3, 2026

Compute & Cloud

Hackers exploit cPanel vulnerability to hijack thousands of sites

Hackers are mass-compromising thousands of websites via a critical cPanel vulnerability, with CISA warning that the flaw is being actively exploited in the wild.

Hackers exploit cPanel vulnerability to hijack thousands of sites

Hackers are mass-compromising thousands of websites by exploiting a critical vulnerability in cPanel, a web server management software. The scale of the exposure remains significant. According to Shadowserver, a nonprofit organization that monitors the internet for cyberattacks, there are more than 550,000 potentially vulnerable servers running cPanel. While the number of potentially vulnerable systems has remained stable for days, the number of active compromises has fluctuated. Shadowserver reported that as of Monday, there are around 2,000 cPanel instances likely compromised, representing a decrease from around 44,000 instances likely compromised on Thursday.

The security threat prompted immediate federal intervention in the U.S. On Thursday, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued a warning and added the vulnerability, tracked as CVE-2026-41940, to its Known Exploited Vulnerabilities (KEV) catalog. CISA asserted that the vulnerability was being exploited in the wild and established a patch deadline of Sunday for government agencies to secure their affected systems. The vulnerability allows attackers to bypass standard protections and take full control of vulnerable servers via their control panels.

Evidence indicates that the exploitation of web servers running cPanel and WebHost Manager (WHM) began long before the public disclosure. KnownHost, a web hosting company, detected attacks as far back as February 23. According to KnownHost CEO Daniel Pearson, attacks against web servers running cPanel and WHM have likely been ongoing since much earlier than the vulnerability was disclosed.

The consequences of these compromises have already disrupted active sites. Some of the compromises involved an apparent ransomware attack where hackers encrypted victim files. Google has indexed websites displaying ransomware messages from a group of hackers claiming to have encrypted the files. These ransom notes included a chat ID for the victims to contact the attackers. While some of those websites have since returned to loading normally, the threat remains active for unpatched systems.

Why it matters

The vulnerability highlights the systemic risk posed by widely used server management software, forcing a scramble among administrators to patch before further ransomware incidents occur.