Part of situation:
Software vulnerability exploits & patch response, July 2026 (32 clusters)
Millions of websites at risk as cPanel zero-day is actively exploited
Hackers are actively exploiting a bug in cPanel, a web-hosting control panel used by millions of websites, prompting web hosts to scramble to fix the flaw.
The flaw is a critical authentication bypass, CVE-2026-41940. Attackers have been exploiting it in the wild since February 23, and likely earlier; they did not need to wait for watchTowr security researchers to disclose technical details about the vulnerability.
Patches have been released to address CVE-2026-41940, and the issue is tied to shared hosting environments typically provided by multiple providers.
Sources
3 months ago
cPanel zero-day exploited for months before patch release (CVE-2026-41940)
[www.helpnetsecurity.com]
3 months ago