Hackers are actively exploiting a bug in cPanel, used by millions of websites
Summary
TechCrunch reports a critical vulnerability in cPanel/WHM (CVE-2026-41940) that allows remote authentication bypass and full admin access on affected servers. The article notes widespread impact, ongoing exploitation, and rapid patching by providers, with advisories from national cybersecurity authorities and multiple hosting companies taking action.