Rashid.Developer

Security

The cPanel hack of 2026: what happened and how to protect your sites

The cPanel hack of 2026: what happened and how to protect your sites

If you host websites on shared hosting or run your own server, there is a good chance cPanel sits between you and your sites. That is why the vulnerability patched in late April 2026 hit so hard. CVE-2026-41940 let attackers log in to cPanel & WHM as an administrator without a password, and by the time most people heard about it, it had already been exploited for weeks.

Server cooling fans in a data centre
Photo: Winston Chen on Unsplash

What happened

cPanel released patches on 28 April 2026, and the CVE was published a day later with a CVSS score of 9.8 out of 10. Hosting providers later found exploit attempts going back to around 23 February 2026, so this was a zero-day for about two months. CISA added it to its Known Exploited Vulnerabilities catalogue, which means real attacks, not just a theoretical risk.

The scale was huge. Shadowserver counted more than 550,000 cPanel servers that were potentially vulnerable, and around 44,000 instances that looked compromised at the peak of the attacks. Some attackers encrypted files and left ransom notes on the websites. Search engines indexed dozens of those notes.

How the bug worked

Researchers traced it to CRLF injection in session handling. By sending a crafted authorisation header with raw line breaks in it, an attacker could write extra properties, such as user=root, into a session file that cPanel then trusted. No password, no two-factor prompt: the server simply believed the attacker was already logged in as root.

Why shared hosting was hit hardest

On shared hosting, one server holds hundreds of accounts. Once an attacker controls WHM, every website on that machine is exposed: files, databases, email and backups stored on the same server. Many site owners did nothing wrong; their host had simply not patched in time.

If you manage a server

  • Update now. Fixed builds include 11.136.0.5, 11.134.0.20, 11.132.0.29, 11.130.0.19, 11.126.0.54, 11.118.0.63, 11.110.0.97 and 11.86.0.41, plus WP Squared 136.1.7.
  • If you cannot patch immediately, block TCP ports 2083 and 2087 from the internet as a temporary measure.
  • Assume compromise if you were unpatched after February: look for unknown WHM or cPanel users, API tokens, SSH keys, cron jobs and recently modified files.
  • Rotate root, WHM, cPanel, database and email passwords, and restore from clean backups where needed.

If your sites are on shared hosting

  • Ask your host directly whether they patched CVE-2026-41940, and when.
  • Change your cPanel, FTP, database and WordPress admin passwords, and turn on two-factor authentication everywhere you can.
  • Check for strange files, especially .php files inside wp-content/uploads, and admin users you did not create.
  • Keep backups off the server. A backup on a hacked server is not a backup.

The lesson

Your website is only as secure as the server it runs on. Keeping WordPress and plugins updated matters, but so does choosing a host that patches quickly and tells you what happened. When I talk to businesses about getting online, this is one of the first things I ask: who is responsible for your server, and how fast do they move when something like this lands?

Sources

Leave a Reply

Your email address will not be published. Required fields are marked *

the newsletter

Stay in the loop

A short monthly email on WordPress, the web in Uganda and what I’m learning from real client projects.

  • Practical WordPress & WooCommerce tips
  • Lessons and fixes from real projects
  • New plugins, talks and events first

Get it in your inbox

Once a month. No spam, unsubscribe any time. Privacy