Critical cPanel Vulnerability Exposes Millions of Websites – Here’s What You Need to Know

Critical cPanel Vulnerability Exposes Millions of Websites – Here’s What You Need to Know

If you’re a Switchweb customer: we don’t use cPanel. Our hosting platform has never relied on cPanel or WHM, which means our customers are completely unaffected by this week’s critical security vulnerability. If you’re among the many website owners now wondering whether your hosting provider is safe, we’d like to help – read on for the full story, and find out why Switchweb could be the right move for you.

What happened?

On 28 April 2026, cPanel – one of the most widely used web hosting control panel platforms in the world – issued an emergency security update to fix a critical flaw that allows attackers to take full administrative control of a web server without knowing any passwords.

The vulnerability, tracked as CVE-2026-41940, has been assigned a CVSS score of 9.8 out of 10 – as serious as it gets.

How does the exploit work?

The flaw lives in how cPanel handles the login and session process. In short, an attacker doesn’t need valid credentials at all.

Before a login attempt is authenticated, cPanel’s service daemon (cpsrvd) writes a session file to disk. The exploit works by injecting special characters (a carriage return and line feed, or CRLF) into a malicious HTTP authorisation header. Because the system doesn’t sanitise this input before writing the session file, the attacker can insert arbitrary values – such as user=root – directly into that file.

When the session is subsequently loaded, the server reads those injected values as legitimate and grants the attacker full administrator-level access. No password required.

At the code level, the underlying authentication function skips password validation entirely once certain timestamp fields are present in the session – fields the attacker can write there themselves using this technique.

Why is this so serious?

cPanel is the control panel software used by an enormous proportion of the shared hosting industry worldwide. A Shodan search reveals approximately 1.5 million cPanel instances currently exposed to the internet.

Successful exploitation doesn’t just compromise a single website. An attacker who gains access through cPanel’s WHM (WebHost Manager) interface can:

  • Take full root-level control of the entire server
  • Access every website, database, and email account hosted on that server
  • Modify server configurations or install malware
  • Exfiltrate customer data
  • Use the server as a launchpad for further attacks

For shared hosting environments – where dozens or hundreds of websites sit on a single server – one successful attack could affect every one of those sites and their visitors.

This was a zero-day – exploited for months before the patch

What makes this particularly troubling is the timeline. Managed hosting provider KnownHost confirmed that the vulnerability was being actively exploited in the wild as far back as 23 February 2026 – more than two months before cPanel issued a fix. There is speculation that exploitation may have begun even earlier than that.

The vulnerability was reportedly disclosed to cPanel roughly two weeks before the public advisory, with cPanel’s initial response suggesting they didn’t believe anything was wrong. No advance warning was issued to hosting providers while a fix was developed.

When the public advisory did land on 28 April, major hosting companies including Namecheap, KnownHost, HostGator, HostPapa, and InMotion Hosting immediately blocked customer access to cPanel and WHM ports at the firewall while they rushed to apply patches. cPanel released a fix approximately two to three hours after the advisory went public. CISA (the US Cybersecurity and Infrastructure Security Agency) has since added CVE-2026-41940 to its Known Exploited Vulnerabilities catalogue.

What should cPanel users do right now?

If your hosting provider uses cPanel and you manage your own server, you should:

  1. Update immediately by running /scripts/upcp --force to apply the latest cPanel version
  2. Verify your cPanel build number and restart the cpsrvd service
  3. Block ports 2083, 2087, 2095, and 2096 at the firewall if you cannot patch immediately
  4. Check your access logs for suspicious activity going back to at least late February 2026 – look for authentication events that don’t match known legitimate users, unexpected administrative changes, or new accounts being created

If you’re on shared hosting, contact your provider to confirm they have patched and to ask whether your account was among those that showed signs of unauthorised access. If you do find evidence that your site has already been compromised, our guide on what to do next if your WordPress site has been hacked walks through containment, cleanup, and recovery step by step.

There is a compliance angle too. If your organisation holds Cyber Essentials, the security update management control requires anything rated critical or high, or scoring 7 or above on CVSS v3, to be patched within 14 days. At CVSS 9.8, CVE-2026-41940 sits well inside that, and since the April 2026 update a missed patch window is an automatic fail rather than something you can explain around. Our guide to Cyber Essentials and your web hosting covers how your host’s patching practices feed into your own certification.

Why Switchweb doesn’t use cPanel – and why that matters

Switchweb has been providing web hosting since 2002. We’ve always used a different hosting infrastructure rather than relying on cPanel.

That means our customers had nothing to worry about this week. No emergency patches, no port blocks, no scramble to assess whether their data had been accessed by unknown parties.

Thinking about a cPanel alternative?

If this week’s events have left you questioning whether your current hosting is as secure as it should be, we’d be glad to talk.

We offer:

  • UK-based hosting with UK support – no outsourced helpdesks
  • No cPanel dependency – our infrastructure is managed independently
  • WordPress hosting suited for a range of websites
  • Over 20 years of experience supporting all types of organisations
  • Straightforward pricing with no hidden upsells

Migration from cPanel hosting is something we can help with. We can transfer your website, email accounts, and databases, and make the move as smooth as possible.

Get in touch with the Switchweb team to find out more, or visit switchweb.co.uk to see our hosting plans.

CVE-2026-41940 affects cPanel & WHM versions after 11.40 and WP Squared versions prior to 136.1.7. The fixed versions are cPanel & WHM 11.136.0.5 and WP Squared 136.1.7. Technical analysis and a proof-of-concept exploit have been published by security firm watchTowr.

If you think your own site may already have been compromised, our step-by-step guide to what to do when your WordPress site has been hacked covers the first hour onwards. To reduce the risk in the first place, see our WordPress security checklist.


Looking to get started on Switchweb? Take a look at our website hosting plans or message us about a free trial.


Pete White

Pete White has worked in the UK web hosting industry for over 20 years, supporting businesses, charities, grassroots campaigns, and non-profit organizations to launch their digital presence with secure, high-performance hosting.

Post Your Comment

SWITCHWEB 7 DAY FREE TRIAL

โ€” No Credit Card Requiredโ€”

7 Day Free Trial
Not ready to commit just yet? That is completely fine. We are confident that once you try Switchweb, you will not want to leave.