< Back to all clusters
[TECHNOLOGY] · 2 sources

Millions of websites at risk as cPanel zero-day is actively exploited

Hackers are actively exploiting a bug in cPanel, a web-hosting control panel used by millions of websites, prompting web hosts to scramble to fix the flaw.

The flaw is a critical authentication bypass, CVE-2026-41940. Attackers have been exploiting it in the wild since February 23, and likely earlier; they did not need to wait for watchTowr security researchers to disclose technical details about the vulnerability.

Patches have been released to address CVE-2026-41940, and the issue is tied to shared hosting environments typically provided by multiple providers.