Hackers are still exploiting the cPanel bug to gain control of thousands of websites


Nearly a week after the makers of the popular web server management software cPanel and WebHost Manager (WHM) alerted users of a critical flaw in its software, hackers are still targeting thousands of websites that use the vulnerable software. 

As of Monday there are more than 550,000 potentially vulnerable servers running cPanel, a number that has remained stable for days. And there are now around 2,000 cPanel instances likely compromised, down from around 44,000 on Thursday. These statistics are published by Shadowserver, a nonprofit organization that scans and monitors the internet for cyberattacks. 

On Thursday, security researchers alerted that hackers started compromising servers running cPanel and WHM, taking advantage of a bug that allowed the attackers to take full control of and hijack the vulnerable servers via their control panels. 

As Bleeping Computer reported, the extent of the damage is visible by the fact that Google has indexed dozens of websites that at some point displayed a message from a group of hackers that claimed to have encrypted the victim’s files in an apparent ransomware attack. Some of those sites now load normally.  

The ransom note included a chat ID for the victims to contact the hackers, who did not immediately respond to TechCrunch’s request for comment. 

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned on Thursday that the vulnerability — tracked as CVE-2026-41940 — was being exploited in the wild, and added it to its Known Exploited Vulnerabilities (KEV) catalog. CISA asked government agencies to patch by Sunday. CISA did not immediately respond to a request for comment, asking whether it could confirm that government agencies have patched their servers. 

The attacks against web servers running cPanel and WHM have likely been ongoing since much earlier than the vulnerability was disclosed. According to KnownHost CEO Daniel Pearson, his company detected attacks as far back as February 23.

Techcrunch event

San Francisco, CA
|
October 13-15, 2026

Executives at Webpros, the company that develops cPanel and WHM and says it powers 60 million domains, did not respond to a request for comment. 

When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.



Source link

  • Related Posts

    Nvidia says its AI data center design runs hotter to use a lot less water

    Public pushback against data centers has emphasized their water and energy consumption, and now Nvidia is highlighting its claim that the Rubin generation reference design for a fully liquid-cooled data…

    GM installs robots at flagship EV factory after laying off 1,300 workers

    Dozens of new robot arms have been installed at General Motors’ flagship electric vehicle factory in Detroit—even as 1,300 workers remain out of work following what was supposed to be…

    Leave a Reply

    Your email address will not be published. Required fields are marked *

    You Missed

    Ford government denies editing Ford Fest photo, says it corrected ‘orange hue’

    Ford government denies editing Ford Fest photo, says it corrected ‘orange hue’

    Trump says proof of his allegations that vandals cut Reflecting Pool paint will be provided in court

    Trump says proof of his allegations that vandals cut Reflecting Pool paint will be provided in court

    Mbappé aprovecha grave error de Irak y llega a 16 goles en Copas del Mundo

    Mbappé aprovecha grave error de Irak y llega a 16 goles en Copas del Mundo

    Nvidia says its AI data center design runs hotter to use a lot less water

    Nvidia says its AI data center design runs hotter to use a lot less water

    France vs. Iraq becomes first 2026 World Cup game delayed due to weather in Philly

    France vs. Iraq becomes first 2026 World Cup game delayed due to weather in Philly

    The 2026 Way to Wear a Lace-Trimmed Slip Skirt

    The 2026 Way to Wear a Lace-Trimmed Slip Skirt