{"id":12471,"date":"2026-04-29T10:01:27","date_gmt":"2026-04-29T10:01:27","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/04\/29\/cpanel-warns-of-critical-authentication-flaw-emergency-patch-released\/"},"modified":"2026-04-29T10:01:27","modified_gmt":"2026-04-29T10:01:27","slug":"cpanel-warns-of-critical-authentication-flaw-emergency-patch-released","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/04\/29\/cpanel-warns-of-critical-authentication-flaw-emergency-patch-released\/","title":{"rendered":"cPanel Warns of Critical Authentication Flaw \u2013 Emergency Patch Released"},"content":{"rendered":"<p>    cPanel Warns of Critical Authentication Flaw \u2013 Emergency Patch Released<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>Web hosting control panel giant cPanel has issued an emergency security update to address a critical vulnerability affecting its core software.<\/p>\n<p>The security flaw directly impacts multiple authentication paths within the cPanel and <a href=\"https:\/\/cybersecuritynews.com\/password-managers-vulnerability\/\" target=\"_blank\" rel=\"noreferrer noopener\">Web Host Manager (WHM)<\/a> ecosystem.<\/p>\n<p>System administrators and web hosting providers are strongly urged to apply the patch immediately to secure their environments against potential unauthorized access.<\/p>\n<p>The development team confirmed the security issue on April 28, 2026, noting that it affects all currently supported versions of the platform.<\/p>\n<p>While specific technical details of exploitation methods remain restricted to protect users, <a href=\"https:\/\/cybersecuritynews.com\/thousand-of-honeywell-controllers-exposed\/\" id=\"https:\/\/cybersecuritynews.com\/thousand-of-honeywell-controllers-exposed\/\" target=\"_blank\" rel=\"noreferrer noopener\">vulnerabilities in authentication paths<\/a> have historically been severe.<\/p>\n<p>If exploited, an attacker could potentially bypass login mechanisms to gain administrative control over the server.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-attack-surface-and-potential-impact\"><strong>Attack Surface and Potential Impact<\/strong><\/h2>\n<p>Because cPanel and WHM are universally used to manage web hosting infrastructure, the attack surface is vast.<\/p>\n<p>WHM provides root-level access to the server, allowing administrators to configure security protocols, <a href=\"https:\/\/cybersecuritynews.com\/types-of-ssl-certificates\/\" target=\"_blank\" rel=\"noreferrer noopener\">manage SSL certificates<\/a>, and create individual hosting accounts.<\/p>\n<p>A compromised authentication path at this level grants threat actors complete control over all hosted websites, sensitive databases, and email communications.<\/p>\n<p>Such access frequently leads to severe security incidents, including mass website defacement, ransomware deployment, and the exfiltration of confidential customer data.<\/p>\n<p>Furthermore, compromised servers are often absorbed into botnets to launch distributed <a href=\"https:\/\/cybersecuritynews.com\/android-zero-interaction-vulnerability\/\" target=\"_blank\" rel=\"noreferrer noopener\">denial-of-service attacks<\/a> or distribute malicious spam campaigns.<\/p>\n<p>Securing these administrative entry points is critical to maintaining the integrity of the broader web hosting supply chain.<\/p>\n<p>To neutralize this threat, the <a href=\"https:\/\/support.cpanel.net\/hc\/en-us\/articles\/40073787579671-cPanel-WHM-Security-Update-04-28-2026\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">cPanel security team has pushed out emergency patches<\/a> across all supported release tiers.<\/p>\n<p>Administrators must verify that their servers are running one of the following secure builds:<\/p>\n<p>Released versions: 11.110.0.97, 11.118.0.63, 11.126.0.54, 11.132.0.29, 11.134.0.20, and 11.136.0.5.<\/p>\n<p>Server operators can manually enforce the update process using the command-line interface.<\/p>\n<p>Executing the\u00a0<code>\/scripts\/upcp --force<\/code>\u00a0command will instruct the server to fetch and install the latest patched release directly from the official repositories.<\/p>\n<p>Administrators should also monitor their authentication logs for any unusual login attempts that may have occurred before patching.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-warnings-for-unsupported-systems\"><strong>Warnings for Unsupported Systems<\/strong><\/h2>\n<p>The security advisory includes a critical warning for environments running <a href=\"https:\/\/cybersecuritynews.com\/microsoft-defender-flags-sql-server\/\" target=\"_blank\" rel=\"noreferrer noopener\">end-of-life<\/a> or unsupported iterations of the software.<\/p>\n<p>Older versions are highly likely to contain the same authentication flaw but will not receive this emergency fix.<\/p>\n<p>Administrators managing legacy servers must plan a migration to a supported release track as soon as possible.<\/p>\n<p>In the interim, deploying strict firewall rules, enforcing <a href=\"https:\/\/cybersecuritynews.com\/new-sophisticated-attack-exploits-google-app-passwords\/\" target=\"_blank\" rel=\"noreferrer noopener\">multi-factor authentication<\/a>, and utilizing IP allowlisting for WHM access can help mitigate the immediate risk of exploitation.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 94%,rgb(169,184,195) 100%)\"><strong>Follow us on <a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>, <a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>, and <a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a> for daily cybersecurity updates. <a href=\"https:\/\/cybersecuritynews.com\/contact-us\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Contact us<\/a> to feature your stories.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/cpanel-authentication-flaw\/\">cPanel Warns of Critical Authentication Flaw \u2013 Emergency Patch Released<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Abinaya<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/cpanel-authentication-flaw\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>cPanel Warns of Critical Authentication Flaw \u2013 Emergency Patch Released Web hosting control panel giant cPanel has issued an emergency security update to address a critical vulnerability affecting its core software. The security flaw directly impacts multiple authentication paths within the cPanel and Web Host Manager (WHM) ecosystem. System administrators and web hosting providers are [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,648],"tags":[130],"class_list":["post-12471","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-vulnerability-news","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/12471"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=12471"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/12471\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=12471"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=12471"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=12471"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}