Wow, when I checked just now, my low-rent hosting provider had already upgraded to a fixed version. I wasn’t expecting that!
First reports come in of victims of critical cPanel vuln as 'millions' of sites potentially exposed
CISA has added a critical cPanel bug to its known-exploited list, confirming that attackers are already poking holes in one of the internet's most widely used hosting stacks. The vulnerability, tracked as CVE-2026-41940, carries a near-worst-case CVSS score of 9.8 and affects all supported versions of cPanel and Web[Host …
COMMENTS
-
This post has been deleted by its author
-
Sunday 3rd May 2026 16:22 GMT Anonymous Coward
Let the flaming commence
Correct me if I'm wrong, but cPanel is a tool that either elevates incompetent people to web administrators or makes website admin easier for people lacking the necessary skills ... take your pick.
Clearly there is a good reason for gaining a better understanding of the underlying systems you are responsible for managing.
-
Sunday 3rd May 2026 19:04 GMT Anonymous Coward
Re: Let the flaming commence
Yes, it means that you can have some beginning admins do the easy work and leave time for the more senior people to ensure everything stays up to date, but the main benefit is (or, for the moment, was) that customers can self-administer without too much handholding.
Don't be too dismissive of UIs, when well set up they can lower the workload considerably. Or the reverse if they're designed by Mictosoft, but I digress.
-
-
Monday 4th May 2026 07:31 GMT Mishak
Lucky for me...
I terminated the contract for my hosting a week before as I'm closing the business on the way to retirement (mainly because I really, really can't be bothered with the layers of additional HMRC reporting that are coming in over the next few years)...
Though I'm sure the lot I've been using will have patched by now, as they've always been well ahead of the curve.