cPanel and WebHost Manager (WHM) released an emergency update to fix a critical authentication bypass vulnerability affecting nearly all versions. The flaw could allow attackers to gain unauthorized access to hosting control panels.
cPanel issued an urgent security patch addressing a critical vulnerability in its control panel and WHM dashboard software. The bug affects all versions except the latest release and permits attackers to bypass authentication mechanisms entirely.
The vulnerability allows unauthenticated users to access cPanel and WHM interfaces without valid credentials, potentially granting full control over hosting accounts. This represents a severe risk for web hosting providers and their customers, as attackers could modify configurations, steal data, or deploy malicious content.
What's affected:
Virtually all cPanel and WHM versions prior to the patched release are vulnerable. The company strongly recommends immediate updates for all users running older builds.
Action required:
Administrators should prioritize applying the emergency patch to all affected systems. cPanel has not disclosed extensive technical details about the vulnerability to prevent exploitation before patching is complete. Users unable to update immediately should monitor their systems for suspicious activity.
The timing of this disclosure follows growing scrutiny of cPanel's security practices. As one of the most widely used web hosting control panels globally, vulnerabilities in cPanel impact millions of websites across countless hosting providers.
Hosting companies dependent on cPanel are expected to deploy fixes urgently. Delay risks exposing customer accounts to compromise. The patch is available through standard cPanel update channels.
Security researchers and hosting providers have been urged to verify patch deployment across their infrastructure. Given the critical nature of the flaw and its broad impact, this represents one of the more serious cPanel vulnerabilities in recent years.
Threat actors are leveraging the legitimate Faronics Deploy endpoint-management platform to gain administrative control over targeted computers and install ScreenConnect remote support software.
X is investigating a surge of unsolicited password reset emails following the launch of its X Money payments service. The company believes the incidents may be connected to the new platform.
Aesto Health disclosed a data breach affecting over 9.5 million individuals. The company discovered the unauthorized access to patient information recently.
Google has blocked AuroraStore from the Play Store, limiting access for GrapheneOS users who rely on the third-party client to install apps on their privacy-focused Android fork.