/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

A bug in popular cPanel, WHM, and WP Squared software has reportedly been exploited since Feb.; CISA it gives a 9.8 CVSS score, tells agencies to patch by May 3

Federal agencies have until May 3 to resolve a security issue impacting a critical system for server and website management.

The Record Jonathan Greig

Context & Ripple Effects

Related coverage has repeatedly tracked active exploitation of critical remote-code-execution flaws in web-hosting control panels, alongside CISA-directed remediation for exposed enterprise infrastructure.

This case fits CISA’s established use of urgent patch mandates when exploitation turns a software flaw into an immediate operational risk for federal networks.

First-order effects

  • Federal civilian agencies must identify affected cPanel, WHM, and WP Squared deployments and remediate them by CISA’s May 3 deadline.
  • Organizations running the affected server- and website-management software face an elevated near-term compromise risk because exploitation has reportedly been ongoing since February.

Second-order effects

  • Hosting providers and administrators are likely to prioritize asset inventory, patch validation, and access review for management-plane systems, where a single vulnerable interface can affect many hosted servers or sites.
  • The episode reinforces pressure on software vendors and managed-hosting operators to shorten the time between vulnerability disclosure, patch availability, and customer deployment.

Third-order effects

  • If actively exploited flaws in administrative control planes continue to drive emergency remediation, vulnerability management will increasingly center on exposure discovery and deployment speed rather than periodic patch cycles.
  • CISA’s intervention points to a broader expectation that critical infrastructure operators maintain demonstrably rapid response processes for vulnerabilities already being used by attackers.

The trend: Active exploitation of high-severity vulnerabilities is pushing patching of shared administrative infrastructure toward an emergency, deadline-driven operating model.

Discussion

  • @theo @theo on x
    cPanel, lightning (on PyPi), and intercom-client (on npm) were all pwn'd in the last 24 hours. We also had a brutal Linux zero day go public. I fear this is only the beginning.
  • @lukashozda Lukáš Hozda on x
    It's been so many years since I last touched cPanel. As a kid, I thought that's how every website was made. On a thing managed with cPanel
  • @wazzcrypto @wazzcrypto on x
    cPanel and WHM exploit that affects every supported version and let's anyone become root admin without a password This is like a 9/11 + Pearl Harbor for the web hosting industry
  • @pirat_nation @pirat_nation on x
    Hackers are actively exploiting a critical vulnerability in cPanel and WHM known as CVE-2026-41940. This authentication bypass allows attackers to gain full admin access to web servers without needing any login information, the issue affects all currently supported versions of [i…
  • @icesolst @icesolst on x
    Holy shit how is cPanel still in use It was released the same month as ActiveX (1996) and should have died with it. But I guess you can't decommission a web admin portal as easily. [image]
  • @vxunderground @vxunderground on x
    > new cpanel cve thingie > proof of concept released > neat > check on internet degenerates > tons of united states gov thingies compromised > tax places compromised > another day of internet schizophrenia [video]
  • r/cybersecurity r on reddit
    Hackers are actively exploiting a bug in cPanel, used by millions of websites