Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsTraining
StudyProjectsNewsletterHire MeAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Training
Study
Projects
Newsletter
Hire Me
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

1451+ Articles
151+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Checklists
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
  1. Home
  2. News
  3. cPanel & WHM Emergency Update Fixes Critical Auth Bypass Bug
cPanel & WHM Emergency Update Fixes Critical Auth Bypass Bug
NEWS

cPanel & WHM Emergency Update Fixes Critical Auth Bypass Bug

cPanel and WebHost Manager have released an emergency patch for a critical authentication bypass vulnerability that allows attackers to gain control panel...

Dylan H.

News Desk

April 29, 2026
3 min read

Emergency Patch Released

cPanel has issued an emergency out-of-band security update addressing a critical authentication bypass vulnerability affecting all versions of the cPanel and WebHost Manager (WHM) control panel prior to the latest release. The flaw could be exploited by unauthenticated remote attackers to gain unauthorized access to the web hosting control panel — one of the most widely deployed hosting management platforms globally.

The vulnerability is rated critical due to its low attack complexity and the complete loss of access control it enables. Because cPanel and WHM power millions of shared hosting environments, the blast radius of exploitation is significant.

What Is cPanel & WHM?

cPanel is the industry-standard web hosting control panel used by hosting providers worldwide to manage websites, email accounts, databases, DNS, and server configurations. WHM (WebHost Manager) is the reseller and server administrator interface layered on top.

Hosting providers, web agencies, and enterprises running self-managed hosting infrastructure rely heavily on these tools, making critical flaws in cPanel a high-priority target for attackers seeking to compromise large numbers of websites and customer accounts in a single operation.

Vulnerability Details

The authentication bypass allows an attacker to obtain access to a cPanel or WHM account without providing valid credentials. Based on the nature of the disclosure, the flaw likely resides in the session validation or token verification logic used by cPanel's API or web interface.

Key characteristics of the vulnerability:

  • Authentication requirement: None — the vulnerability is pre-authentication
  • Attack complexity: Low — can be exploited without specialized knowledge
  • Privileges required: None — no prior access needed
  • Scope: Full control panel access, including file manager, email, databases, and server configuration
  • Affected versions: All versions prior to the emergency patch release

Successful exploitation could give attackers the ability to:

  • Access, modify, or delete all website files hosted on the server
  • Read sensitive configuration files, database credentials, and email
  • Create new administrative accounts for persistent access
  • Deploy web shells or malware to hosted websites
  • Reconfigure DNS to redirect web traffic or intercept email

Who Is Affected

Any hosting provider or system administrator running an unpatched version of cPanel or WHM is at risk. Given the widespread deployment of these tools — cPanel is reported to run on hundreds of thousands of servers — the potential attack surface is enormous.

Shared hosting environments are at particular risk, as a single compromised WHM instance can expose thousands of customer accounts hosted on the same server.

Remediation

cPanel has released an emergency update and strongly urges all users to apply it immediately:

  1. Update cPanel/WHM to the latest version via the update interface or by running /scripts/upcp on the server
  2. Review server access logs for any suspicious authentication attempts or anomalous session activity prior to patching
  3. Audit user accounts — check for any newly created accounts that were not authorized
  4. Enable two-factor authentication (2FA) on all administrative accounts as a defense-in-depth measure
  5. Restrict WHM access by IP address if remote access is not needed from all locations

References

  • BleepingComputer: cPanel, WHM emergency update fixes critical auth bypass bug
  • cPanel Security Advisories

Related Reading

  • Critical cPanel and WHM Bug Exploited as Zero-Day, PoC Now
  • Exploit Frenzy Threatens Millions via Critical cPanel
  • cPanel & WHM Release Fixes for Three New Vulnerabilities
#Vulnerability#cPanel#authentication#Web Hosting#Security Updates

Related Articles

CISA Gives Feds 4 Days to Patch Actively Exploited cPanel Plugin Flaw

CISA's emergency directive gives federal agencies four days to patch the actively exploited LiteSpeed cPanel plugin flaw being weaponized in the wild.

5 min read

CISA Urges Immediate Patching of Exploited LiteSpeed cPanel

CISA has added a LiteSpeed cPanel plugin zero-day to its Known Exploited Vulnerabilities catalog after active exploitation allowed attackers to execute scripts.

4 min read

Exploit Frenzy Threatens Millions via Critical cPanel

A critical authentication bypass flaw in cPanel/WHM has triggered a wave of exploit activity, with multiple proof-of-concept exploits now public and...

4 min read
Back to all News