Back to Feed
Zero-dayMay 4, 2026

Exploit Cyber-Frenzy Threatens Millions via Critical cPanel Vulnerability

Critical cPanel authentication-bypass flaw exploited in wild with PoC code and suspected month-long zero-day activity.

Vendor Watch

Run cPanel?

Get an email when a reviewed story names cPanel, usually within the hour.

Free. Your list stays private and never appears in a subject line. One click stops it. How Vendor Watch works

Summary

A critical authentication-bypass vulnerability in cPanel has been disclosed and rapidly weaponized with public proof-of-concept exploits appearing immediately after disclosure. Security researchers report evidence of zero-day exploitation activity occurring for at least one month prior to the public advisory, potentially affecting millions of users relying on cPanel for web hosting and server management.

Indicators of Compromise

  • malware — cPanel authentication-bypass exploit

Entities

cPanel (product)Authentication bypass (technology)