Közlemények
- Csütörtök, 30cs Április, 2026
- 14:26du
Critical Security Advisory – cPanel/WHM (CVE-2026-41940)
We are issuing an important security notice regarding a critical vulnerability identified in cPanel & WHM.
Official notice: https://support.cpanel.net/hc/en-us/articles/40073787579671-Security-CVE-2026-41940-cPanel-WHM-WP2-Security-Update-04-28-2026
Vulnerability ID: CVE-2026-41940
Severity: Critical (CVSS 9.8)
Type: Authentication Bypass (Unauthorized Access)
What is the issue?
This vulnerability allows an attacker to bypass authentication mechanisms and potentially gain administrative or root-level access without valid login credentials.
If exploited, an attacker may:
-
Access or modify hosted websites
-
Read or manipulate databases
-
Create or delete accounts
-
Execute malicious code
-
Access sensitive server-level data
This issue is especially critical because it does not require valid credentials and has been reported as actively exploited.
Who is affected?
-
Servers running outdated or unpatched versions of cPanel & WHM
-
Unmanaged VPS or dedicated servers
-
Systems not updated after April 28, 2026
Actions taken by HostRainbow
-
All managed servers have been updated with the latest security patches
-
Additional firewall and WAF protections have been applied
-
Logs and systems have been reviewed for suspicious activity
-
Preventive monitoring has been strengthened
All HostRainbow managed infrastructure is secured against this vulnerability.
Required actions for unmanaged or root users
If you manage your own server, follow these steps immediately:
1. Update cPanel/WHM
Run the following command:
/scripts/upcp --force
2. Restart cPanel service
/scripts/restartsrv_cpsrvd
3. Clear all active cPanel sessions (Important)
This vulnerability is related to session handling, so clearing sessions is strongly recommended:
rm -rf /var/cpanel/sessions/*
4. Check for suspicious activity
Review logs:
-
/usr/local/cpanel/logs/access_log
-
/usr/local/cpanel/logs/error_log
-
/var/log/secure
Look for:
-
Unknown IP access
-
Suspicious login patterns
-
Unauthorized privilege actions
5. Rotate all credentials
Immediately update:
-
Root password
-
All cPanel and WHM user passwords
-
API tokens and access keys
-
SSH keys (if reused elsewhere)
6. Secure SSH access
-
Disable password authentication (use SSH keys only)
-
Change default SSH port
-
Restrict SSH access to specific IPs
7. Strengthen server protection
Recommended security measures:
-
Enable firewall (CSF, Fail2Ban, or Imunify360)
-
Enable ModSecurity rules
-
Keep automatic updates enabled
-
Monitor server activity regularly
8. Verify backups
-
Ensure backups are working and not modified
-
Keep at least one offsite backup copy
-
Test restore functionality
Important note
If your server was not patched immediately after disclosure, it may have been exposed.
In such cases, you should:
-
Perform a full malware scan
-
Check cron jobs and startup scripts
-
Audit all user accounts and permissions
-
Consider full server reinstallation if compromise is suspected
Need assistance?
If you are unsure about your server security or need help applying these fixes, please contact our support team.
Team HostRainbow
Hostrainbow is a web hosting provider offering shared hosting, VPS, dedicated servers, and domain registration. Known for reliability, security, and user-friendly services, they cater to both individuals and businesses seeking robust online solutions.