Tuesday, August 25, 2026

cPanel Releases Emergency Patch for Critical Authentication Flaw

Web hosting administrators must take immediate action, as cPanel has rolled out an emergency security update to address a critical vulnerability.

Disclosed on April 28, 2026, this flaw impacts various authentication paths within the cPanel and WebHost Manager (WHM) ecosystem.

Control panels like cPanel act as the central nervous system for web servers, handling everything from email routing to database management. Threat actors highly prize authentication vulnerabilities in such platforms.

If an attacker successfully bypasses the authentication mechanisms, they could gain administrative privileges.

This level of access allows them to deploy malware, steal sensitive customer data, or launch secondary attacks against other networks using the compromised infrastructure.

Given the severity of the flaw, hosting providers and independent server owners cannot afford to delay patching.

The vulnerability lies deep within the software’s authentication framework, making prompt remediation the only reliable defense against potential intrusions.

Affected cPanel Versions

The security team at cPanel confirmed that this vulnerability affects all currently supported versions of the software.

To secure their infrastructure, administrators must verify their current build and upgrade to a newly released, secure version. The official patch applies to the following specific software tiers.

  • Version 11.110.0.97
  • Version 11.118.0.63
  • Version 11.126.0.54
  • Version 11.132.0.29
  • Version 11.134.0.20
  • Version 11.136.0.5

Servers running older, unsupported releases are highly likely to be vulnerable to this same flaw.

cPanel explicitly warns that users on unsupported software must work toward upgrading their entire server environment immediately, as no security patches will be issued for legacy builds.

Immediate Mitigation Strategies

System administrators must force an update to retrieve and install the patched version of cPanel and WHM. You can run this update directly on the server’s command line.

Run the following command as the root user to initiate the patching process.

/scripts/upcp --force

This command forces the cPanel update script to execute immediately. It ensures the system downloads and applies the latest security patches, overriding standard scheduled update settings.

After the process finishes, administrators should check their WHM interface to confirm the server reflects one of the secured version numbers.

In addition to applying the patch, security teams should actively review their server access logs. Look for any suspicious login attempts, unexpected account creations, or unusual administrative activities that occurred before the patch deployment.

Proactive monitoring helps identify if threat actors attempted to exploit the authentication paths before the system was secured.

Finally, administrators should strengthen their overall security posture by enforcing multi-factor authentication (MFA) and restricting WHM access to trusted IP addresses.

Follow us on Google NewsLinkedIn, and X to Get Instant Updates and Set GBH as a Preferred Source in Google.

Divya
Divya
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

Google and Bing Search Results Used to Deliver Hidden Banking Phishing Pages

Threat actors are increasingly using Google and Bing as...

North Korean Hackers Hide AnyDesk on Victim PCs to Maintain Secret Remote Access

North Korea-linked Kimsuky operators have targeted organizations in South...

Zimbra Collaboration Suite Flaw Actively Exploited to Execute Arbitrary Commands

Threat actors are actively exploiting a critical operating system...

Open VSX Unblocks 3 IDs Used in 77-Extension Evil-Twin Malware Campaign

Open VSX has removed three extension identifiers from its...

New SynkLoader Malware Uses Fake Windows Lock Screen to Steal Passwords and Pivot Networks

SynkLoader, a newly identified modular malware framework that combines...

New macOS Malware Clones Your Logged-In Browser and Gives Hackers Remote Control.

AmnesiaStealer, a multi-stage macOS infostealer written in Rust that...

Related Articles

Recent News