黑客正在积极利用 cPanel 和 WHM 中的一个漏洞。
Hackers are actively exploiting a bug in cPanel and WHM

原始链接: https://techcrunch.com/2026/04/30/hackers-are-actively-exploiting-a-bug-in-cpanel-used-by-millions-of-websites/

cPanel和WebHost Manager (WHM) 发现了一个严重漏洞 (CVE-2026-41940)。该软件被全球大量网站使用。此漏洞允许黑客绕过登录安全,并完全控制受影响的服务器,可能导致数据和网站被破坏。 虽然Namecheap和HostGator等许多托管服务提供商已经修补了系统,但cPanel敦促*所有*用户确保他们的软件是最新的。包括加拿大在内的网络安全机构警告说,漏洞被利用的可能性“非常高”,需要立即采取行动。 有证据表明,攻击者可能已经尝试利用此漏洞数月,一些提供商报告早在二月份就出现了尝试入侵的情况。此漏洞授予了深度访问权限,使得未修补的服务器尤其容易受到攻击,尤其是在共享托管环境中。WP Squared,一个相关的WordPress管理工具,也已发布了修复程序。

黑客新闻 新 | 过去 | 评论 | 提问 | 展示 | 招聘 | 提交 登录 黑客正在积极利用 cPanel 和 WHM 中的一个漏洞 (techcrunch.com) 7点 由 dotmanish 50分钟前 | 隐藏 | 过去 | 收藏 | 讨论 帮助 考虑申请YC 2026年夏季项目!申请截止至5月4日 指南 | 常见问题 | 列表 | API | 安全 | 法律 | 申请YC | 联系 搜索:
相关文章

原文

Security researchers are sounding the alarm on a newly discovered vulnerability in the widely used web server management software cPanel and WebHost Manager (WHM). 

The bug allows hackers to hijack and take full control of the servers running the affected software, which is thought to be used by tens of millions of website owners around the world.

Many commercial web hosting companies have patched their customers’ systems already. But the cPanel maker urged customers to ensure that their systems are patched as the bug affects all supported versions of the software.

cPanel and WHM are two software suites used for managing web servers that host websites, manage emails, and handle important configurations and databases needed to maintain an internet domain. The two suites have deep-access to the servers that they manage, allowing a malicious hacker potentially unrestricted access to data managed by the affected software.

The bug, officially tracked as CVE-2026-41940, allows malicious hackers to remotely bypass its login screen to gain full access to the software’s administration panel. 

Given the ubiquity of the cPanel and WHM software across the web hosting industry, hackers could compromise potentially large numbers of websites that haven’t patched the bug.

Canada’s national cybersecurity agency said in an advisory that the bug could be exploited to compromise websites on shared hosting servers, such as large web hosting companies.

The agency said that “exploitation is highly probable” and that immediate action from cPanel customers, or their web hosts, is necessary to prevent malicious access.

Web hosting giant Namecheap, which uses cPanel to allow its customers to manage their web servers, said the company blocked access to customers’ cPanel panels after learning of the flaw to prevent exploitation, and to give it time to patch its customers’ systems

HostGator also said it patched its systems and is considering the bug a “critical authentication-bypass exploit.”

One web hosting company says it found evidence that hackers have been abusing the vulnerability for months before the attempts were discovered.

KnownHost CEO Daniel Pearson said in a post on Reddit that his company has seen attempts to exploit the vulnerability as far back as February 23. The company said it also briefly began blocking access to customer systems before applying patches.

According to Pearson, around 30 servers at KnownHost showed signs of unauthorized attempted access out of thousands of computers on its network. Pearson likened the efforts to attempts, and has not seen signs of active compromise. cPanel also said it rolled out a security fix for WP Squared, a similar tool for managing WordPress websites.

When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.

联系我们 contact @ memedata.com