Hackers are still exploiting the cPanel bug to gain control of thousands of websites

TL;DR AI
2 min readKey summary
Attackers are actively exploiting a critical cPanel/WHM flaw to seize control of websites and servers.
Security researchers say more than 550,000 servers may be exposed, with around 2,000 likely already compromised.
CISA confirmed CVE-2026-41940 is being used in the wild and urged immediate patching, especially for government systems.
Evidence suggests the campaign may have begun weeks before public disclosure, increasing the risk of widespread impact.



