Web hosting administrators must take immediate action, as cPanel has rolled out an emergency security update to address a critical vulnerability.
Disclosed on April 28, 2026, this flaw impacts various authentication paths within the cPanel and WebHost Manager (WHM) ecosystem.
Control panels like cPanel act as the central nervous system for web servers, handling everything from email routing to database management. Threat actors highly prize authentication vulnerabilities in such platforms.
If an attacker successfully bypasses the authentication mechanisms, they could gain administrative privileges.
This level of access allows them to deploy malware, steal sensitive customer data, or launch secondary attacks against other networks using the compromised infrastructure.
Given the severity of the flaw, hosting providers and independent server owners cannot afford to delay patching.
The vulnerability lies deep within the software’s authentication framework, making prompt remediation the only reliable defense against potential intrusions.
Affected cPanel Versions
The security team at cPanel confirmed that this vulnerability affects all currently supported versions of the software.
To secure their infrastructure, administrators must verify their current build and upgrade to a newly released, secure version. The official patch applies to the following specific software tiers.
- Version 11.110.0.97
- Version 11.118.0.63
- Version 11.126.0.54
- Version 11.132.0.29
- Version 11.134.0.20
- Version 11.136.0.5
Servers running older, unsupported releases are highly likely to be vulnerable to this same flaw.
cPanel explicitly warns that users on unsupported software must work toward upgrading their entire server environment immediately, as no security patches will be issued for legacy builds.
Immediate Mitigation Strategies
System administrators must force an update to retrieve and install the patched version of cPanel and WHM. You can run this update directly on the server’s command line.
Run the following command as the root user to initiate the patching process.
/scripts/upcp --force
This command forces the cPanel update script to execute immediately. It ensures the system downloads and applies the latest security patches, overriding standard scheduled update settings.
After the process finishes, administrators should check their WHM interface to confirm the server reflects one of the secured version numbers.
In addition to applying the patch, security teams should actively review their server access logs. Look for any suspicious login attempts, unexpected account creations, or unusual administrative activities that occurred before the patch deployment.
Proactive monitoring helps identify if threat actors attempted to exploit the authentication paths before the system was secured.
Finally, administrators should strengthen their overall security posture by enforcing multi-factor authentication (MFA) and restricting WHM access to trusted IP addresses.
Follow us on Google News, LinkedIn, and X to Get Instant Updates and Set GBH as a Preferred Source in Google.





