Hacking Ping Test News Last 48 Hours cPanel mademanministries

cPanel and WHM are currently under active exploitation for a critical zero-day authentication bypass vulnerability (CVE-2026-41940) with a CVSS score of 9.8.  Discovered and patched in late April 2026, this flaw allows attackers to bypass login screens and gain full administrative control over hosting systems, potentially compromising millions of websites. 

Key Details

  • Vulnerability Mechanism: The bug stems from improper session handling and CRLF injection in the login process, where user-controlled input in the Authorization header is written to server-side session files before authentication. 
  • Active Exploitation: Evidence suggests hackers have been abusing this vulnerability for months, with some providers detecting attempts as early as February 23, 2026.  Proof-of-concept (PoC) code is currently circulating online.
  • Affected Systems: The flaw impacts all supported versions of cPanel and WHM (specifically v11.40 and later), as well as WP Squared v136.1.7.  Shodan data indicates approximately 1.5 million cPanel instances are exposed to the internet. 
  • Mitigation: cPanel has released emergency patches. Until updated, administrators are urged to block inbound traffic on ports 2083, 2087, 2095, and 2096 at the firewall and restart the cpsrvd service.  Simply closing ports may be insufficient due to alternative access mechanisms identified by security researchers. 

As of May 1, 2026, a critical, actively exploited zero-day vulnerability in cPanel & WHM (CVE-2026-41940) dominates cybersecurity news, with reports indicating it has been exploited for months. The vulnerability, which carries a maximum CVSS score of 9.8, allows unauthenticated remote attackers to bypass login screens and gain full administrative (root) control over servers.

48-Hour News Summary: cPanel CVE-2026-41940

  • Active Exploitation: The bug was disclosed on April 28, 2026, but reports suggest malicious exploitation began as early as February 23, 2026.
  • Mass Impact: Roughly 1.5 million cPanel instances are exposed online, with millions of websites potentially affected.
  • Emergency Patches: cPanel released patches for all supported versions (11.40+) on April 28-29, 2026.
  • Industry Response: Major hosts like Namecheap, HostGator, and KnownHost quickly blocked port access (2083/2087) to apply patches.
  • Technical Details: The vulnerability is a Carriage Return Line Feed (CRLF) injection, allowing attackers to manipulate session files and elevate privileges.

10 Examples of Recent cPanel Hacking Incidents & Findings (Last 48 Hours)

Example/IncidentDetails
1Root Takeover (Feb 23-April 28)Hackers exploited the zero-day to gain root access without credentials over a 2-month period.
2CRLF Injection ExploitationAttackers used specifically crafted HTTP headers to inject malicious values into session files.
3KnownHost Breach AttemptsCEO confirmed ~30 servers showed signs of unauthorized access attempts in late April.
4Namecheap Port BlockingNamecheap blocked port 2083/2087, disabling customer cPanel access to apply emergency patches.
5PoC Exploit ReleaseSecurity firm watchTowr released technical details and a detection script, confirming the exploit path.
6WP Squared TargetedThe bug affected WP Squared (WordPress hosting), prompting a specific update to v136.1.7.
7CISA KEV AdditionCISA added CVE-2026-41940 to its Known Exploited Vulnerabilities catalog on April 30.
8Session File ManipulationAttackers bypassed auth by creating a dummy session file, then updating it to grant admin rights.
9Rapid7 AnalysisRapid7 confirmed the issue affects all supported cPanel versions after 11.40.
10Shared Hosting CompromisePotential for attackers to access all websites on a shared server, not just one account.

Recommendations for Administrators

  • Update Immediately: Run /scripts/upcp --force to apply emergency patches.
  • Check Logs: Review access logs for suspicious whostmgrsession cookie behavior.
  • Restart Service: Restart cpsrvd to finalize the security patch.

Disclaimer: This information is based on reports from security news sources and vendor advisories published around April 28-May 1, 2026.

How To Protect Your Website Against cPanel Hack

Immediate patching is the only definitive protection against CVE-2026-41940; update your cPanel & WHM to a patched version immediately using the command /scripts/upcp --force.  Supported patched versions include 11.86.0.4111.110.0.9711.118.0.6311.126.0.5411.130.0.1911.132.0.2911.134.0.20, and 11.136.0.5.  After updating, restart the cpsrvd service with /scripts/restartsrv_cpsrvd to ensure the new authentication logic is loaded. 

If you cannot patch immediately, apply these temporary mitigations to block exploitation:

  • Firewall Rules: Block inbound traffic on TCP ports 2083, 2087, 2095, and 2096 at your firewall level. 
  • Service Stop: Stop the cPanel and DAV services entirely using the commands: whmapi1 configureservice service=cpsrvd enabled=0 monitored=0 && whmapi1 configureservice service=cpdavd enabled=0 monitored=0 && /scripts/restartsrv_cpsrvd --stop && /scripts/restartsrv_cpdavd --stop

You must also audit your server for compromise, as the vulnerability was exploited as a zero-day for at least 30 days prior to the patch. 

  • Run the official cPanel detection script to check for indicators of compromise (IoCs) in session files.
  • Manually inspect /var/cpanel/sessions/raw/ for pre-auth sessions containing user=roottfa_verified=1, or token_denied=1.
  • Purge all affected sessions by clearing the /var/cpanel/sessions directory and force password resets for root and all WHM users. 

Note: We do use YouTube Video’s under the “Fair Use” Act under the Copyright Law:

“Fair use is a doctrine in the United States copyright law codified in Section 107 of the Copyright Act of 1976.1 It provides for the legal, non-licensed citation or incorporation of copyrighted material in another author’s work without requiring permission from the rights holders, such as for commentary, criticism, news reporting, research, teaching or scholarship.01 The U.S. Copyright Office Fair Use Index should prove helpful in understanding what courts have to date considered to be fair or not fair but it is not a substitute for legal advice.2

Check out our last minute travel deals: Travelanycountry.com

travelancountry thebookongonefishing
Save Up To 60% Off Hotels, Flights, Cruises, Rental Cars  thebookongonefishing

Save Up To 60% Off Hotels, Flights, Cruises, Rental Cars More…

Product Reviews Ebay.com, Walmart.com, Clickbank, Cabela’s And More…

Women Product Reviews

Product Reviews – Apples Phones, TV, Ipads, Laptops, Watches

Product Reviews – Camera’s, Gimbal’s, Video Equipment.

DF DIGITALFOTO Thanos Pro Video Camera Gimbal Support Vest Stabilizer System with Adapter Arm 5.5-26 lbs Compatible with ZHIYUN Crane 3S/FeiyuTech Scorp Pro Gimbal

DJI Ronin-SC – Camera Stabilizer, 3-Axis Handheld Gimbal for DSLR and Mirrorless Cameras, Up to 4.4lbs Payload, Sony, Panasonic Lumix, Nikon, Canon, Lightweight Design, Cinematic Filming, Black

DJI RS 3, 3-Axis Gimbal for DSLR and Mirrorless Camera Canon/Sony/Panasonic/Nikon/Fujifilm, 3 kg (6.6 lbs) Payload, Automated Axis Locks, 1.8″ OLED Touchscreen, Professional Video Stabilizer

Carbon Fiber Tripod-RT75CM Super Professional Tripod Monopod Heavy Duty Compact Stand Support with 44mm/1.73in Low Gravity Center 360°Panoramic ballhead for Digital DSLR Camera, max Load 20kg/44lb

Manbily 63″ Carbon Fiber DSLR Camera Tripod Monopod Kit,Compact and Lightweight,360-degree Panoramic Ball Head Quick Release Plate,5 Seconds Quickly Invert The Center Column,for Travel Work(YS-254C)

EMART Photo Video Studio 10x7Ft (WxH) Adjustable Background Stand Backdrop Support System Kit with Carry Bag

Canon EOS M50 Mark II + EF-M 15-45mm is STM Kit Black Product Review

UBeesize LED Video Light Kit, 2Pcs Dimmable Continuous Portable Photography Lighting with Adjustable Tripod Stand & Color Filters for Tabletop/Low-Angle Shooting, for Zoom, Game Streaming, YouTube

Aureday 74’’ Camera Tripod with Travel Bag,Cell Phone Tripod with Wireless Remote and Phone Holder, Compatible with DSLR Cameras,Cell Phones,Projector,Webcam,Spotting Scopes

Other Product Reviews – Lawncare, Tools, Fishing Gear.

LeanBiome – BRAND NEW Weight Loss Offer!! – Product Review – Clickbank

Liv Pure – Product Review From Clickbank

Troy-Bilt Pony 42″ Riding Lawn Mower Tractor with 42-Inch Deck and 439cc 17HP Troy-Bilt Engine

Call Mike Richards Today At Ashley Furniture At Polaris Columbus, Ohio Today!

Costway 6.3 Quart Tilt-Head Food Stand Mixer 6 Speed 660W w/Dough Hook, Whisk Black

I COMPARE 4 RVs: Campervan, Class C, 5th Wheel & Truck Camper. 20 Factors to Consider

Offshore Angler Tightline II Spinning Reel

Lodge Tall Boy Camp Dutch Oven Tripod

Bear Archery Species EV RTH Compound Bow Package

Minn Kota Terrova Bow Mount Freshwater Trolling Motor with i-Pilot GPS Trolling System

Cabela’s Treadfast GORE-TEX Insulated Hunting Boots for Men

Classic Accessories Over Drive RV Sway Bar Hitch Tote, Black

Hughes Autoformers Power Watchdog Portable RV Bluetooth Surge Protector, 30 Amp

3 Pack Waterproof RV Hose, Cable & Equipment Storage Utility Bag w/ Rubber Identification Tags To Organize Fresh, Sewer, Black Water Hoses, Electrical Cords & Accessories

Lenovo Ideapad Flex 5i, 15.6″, Intel Core i5-1135G7, 8GB, 512GB M.2 NVMe SSD, Intel Iris Xe Graphics, Platinum Grey, Windows 11 Home, 82HT007VUS

2021 Apple 10.2-inch iPad Wi-Fi 64GB – Space Gray (9th Generation)

2022 Apple 10.9-inch iPad Wi-Fi 64GB – Silver (10th Generation)

Black Max 21-inch 3-in-1 Self-Propelled Gas Mower with Perfect Pace Technology

Best Choice Products 6V Portable Sewing Machine, 42-Piece Beginners Kit w/ 12 Stitch Patterns – Teal

Real Relax Massage Chair, Full Body Recliner with Zero Gravity Chair, Air Pressure, Bluetooth, Heat and Foot Roller Included, Black

Cate & Chloe McKenzie 18k White Gold Plated Dangling Earrings with Swarovski Crystals, Solitaire Crystal Dangle Earrings, Best Silver Drop Earrings for Women, Horseshoe Shape

Audew 2000A Peak 20000mAh Car Jump Starter for All Gas Engines or Up To 8.5L Diesel Engines with LCD Power Display , Ep155 – Red

Allewie Light Grey Queen Platform Bed Frame with 4 Drawers Storage and Square Stitched Button Tufted Upholstered Headboard

HART 20-Volt Cordless 4-Tool Combo Kit with 200-Piece Accessory Kit and 16-inch Storage Bag, (2) 20-Volt 1.5Ah Lithium-Ion Battery

Please visit our Sponsors:

HeimVision-HM241-Wireless-Security-Camera-System-8CH-1080P-NVR-System-cipads freeads
Hyper Bicycles E-Ride Electric Pedal Assist Mountain Bike, 29″ Wheels, Black at Walmart.com $598.00 cipads freeads
Impact Canopy Folding Utility Wagon, Collapsible, All Terrain Beach Wagon, Black at Walmart.com cipads
WALMART AD LINK TACKLE SUPPLIES cipads freeads
PocketJuice Endurance AC 20K, Portable Power Bank and Charger at Walmart cipads freeads
Groove-Funnels-Review-YouTube-cipads freeads
PENN Squall Lever Drag Conventional Reel and Fishing Rod Combo cipads freeads
Mach Inshore Baitcast SLP 7.5 1 7 1 Left Hand Baitcast Combo cipads freeds
The-Feather-Benders-Flytying-Techniques-A-Comprehensive-Guide-to-cipads freeads

About Author