preloader

· · digital-security devops cve hosting msp europe vulnerability-management patch-management

A cPanel Bug Patched in April Is Still Breaching Servers Because Nobody Updated

Source: Security Affairs

cPanel and WHM run the control panel behind an enormous share of the world’s shared and reseller web hosting, the software layer a hosting provider uses to manage customer accounts without a system administrator logging into every server by hand. CVE-2026-41940, a CRLF injection flaw in HTTP Basic Authentication handling that lets a remote attacker skip login checks entirely, was exploited as a genuine zero-day from around 23 February 2026 until cPanel shipped an emergency patch on 28 April, an estimated two-month window during which roughly 1.5 million internet-facing servers were exposed with a CVSS score of 9.8.

Patched in April, still being exploited in August

The patch existing does not mean the exposure ended. Researchers have now documented a highly automated “spray-and-check” campaign chaining CVE-2026-41940 with eight other vulnerabilities, including a ProxyShell exploitation path, to compromise 107 endpoints, among them 16 root-level cPanel and WHM takeovers and at least one Domain Admin-level breach. Operators are running Neo-reGeorg web shells layered over pre-existing JSP shell implants and routing traffic through other compromised systems as reverse tunnels, a pattern that only works against servers that were never updated after April, three and a half months ago as of this writing.

The part that should worry European hosting customers

Most businesses running a website through a shared hosting plan or an MSP-managed server have never heard of cPanel and have no visibility into whether the infrastructure underneath their site has been patched. That is the entire point of managed hosting, but it also means the patch cycle for a critical, unauthenticated, remotely exploitable flaw sits entirely with a provider the customer cannot audit and often cannot even identify by name if the hosting was resold through an agency or reseller layer. A hosting provider or MSP that missed the April patch is still exploitable today, and every customer on that server inherits the exposure without ever having made a security decision of their own.

What to actually check

If your organisation runs its own cPanel or WHM instances rather than outsourcing to a managed host, confirm you are on a version patched after 28 April, specifically 11.110.0.97, 11.118.0.63, or 11.126.0.54 or later depending on your release branch, and check for the artefacts of the reGeorg and JSP shell implants researchers have documented if you cannot confirm your patch history with certainty. If you host through a third party, ask them directly which cPanel version they run and when it was last patched, since “we handle hosting” is not the same claim as “we patch on the same week vendors ship a fix.”

If your organisation needs a vulnerability management review of hosting or MSP-managed infrastructure, or wants help verifying whether third-party hosting providers are actually keeping pace with critical patches, contact Excello Digital. We help European businesses close the visibility gap between what they think is patched and what actually is.

These news items are automatically aggregated from industry sources and are not individually reviewed. Any inaccuracies are unintentional — let us know and we'll correct or remove it.

We’ll help you resolve your infrastructure challenges

Our team of experts is ready to help you with your infrastructure challenges. We’ll give you honest and personal treatment. Get in touch to learn more.

Get in touch!