Three new cPanel vulnerabilities, CVE-2026-29201, CVE-2026-29202, and CVE-2026-29203, are being patched today at 12:00pm EST, with technical details withheld until the fix is live.
Author: Łukasz Nowak
DirtyFrag, a Linux kernel local privilege escalation that gives any local user root access on Ubuntu, RHEL, Fedora, CentOS Stream, AlmaLinux, and openSUSE Tumbleweed, went fully public on May 8 after an embargo break, with no CVE assigned and no patches available for any affected distribution.
CVE-2026-41940, the cPanel authentication bypass exploited for 64 days before disclosure, is still developing. 44,000 servers likely compromised, a public exploit on GitHub, three active campaigns. This page is updated in real time as new information surfaces.
CVE-2026-41940, the cPanel authentication bypass from April 28, was being exploited since February 23, operated as a zero-day for 64 days, and was added to CISA's Known Exploited Vulnerabilities list with 1.5 million internet-exposed instances counted by Rapid7.
Copy Fail (CVE-2026-31431) is a Linux kernel privilege escalation giving any unprivileged local user root access, affecting virtually all distributions since 2017, with shared hosting and multi-tenant environments at highest risk.
Matt Mullenweg called WordPress development "boring or mediocre crap," then overruled core committers to add Akismet to the WordPress 7.0 Connectors screen, weeks before the May 20 release.
HostPapa acquired Hostwinds on April 29, adding self-owned data centers in Seattle and Amsterdam and a developer and reseller customer base to its portfolio, twelve days after acquiring Tailor Made Servers in Dallas.
cPanel disclosed a critical authentication bypass on April 28 affecting nearly all versions of cPanel and WHM, with active exploits confirmed in the wild before the patch was released, forcing hosting.com, Namecheap, KnownHost, HostPapa, and InMotion Hosting to take cPanel access offline globally.
South African ISP Axxess acquired Absolute Hosting as part of a deliberate 2026 strategy to grow hosting revenues, with founder Jade Benson remaining managing director and the company continuing to operate independently under its own brand.
Automattic launched Studio Code in public beta, a CLI agent built on Anthropic's Claude Sonnet 4.6 that builds, configures, and publishes WordPress sites from natural language commands, running on top of MCP write capabilities launched in March 2026.