Three new cPanel vulnerabilities, CVE-2026-29201, CVE-2026-29202, and CVE-2026-29203, are being patched today at 12:00pm EST, with technical details withheld until the fix is live.
DirtyFrag, a Linux kernel local privilege escalation that gives any local user root access on Ubuntu, RHEL, Fedora, CentOS Stream, AlmaLinux, and openSUSE Tumbleweed, went fully public on May 8 after an embargo break, with no CVE assigned and no patches available for any affected distribution.
Apache 2.4.67, released May 4, patches 11 CVEs including a CVSS 8.8 HTTP/2 remote code execution flaw and a shared hosting privilege escalation that lets customers read each other's files.
CVE-2026-41940, the cPanel authentication bypass exploited for 64 days before disclosure, is still developing. 44,000 servers likely compromised, a public exploit on GitHub, three active campaigns. This page is updated in real time as new information surfaces.
CVE-2026-41940, the cPanel authentication bypass from April 28, was being exploited since February 23, operated as a zero-day for 64 days, and was added to CISA's Known Exploited Vulnerabilities list with 1.5 million internet-exposed instances counted by Rapid7.
Copy Fail (CVE-2026-31431) is a Linux kernel privilege escalation giving any unprivileged local user root access, affecting virtually all distributions since 2017, with shared hosting and multi-tenant environments at highest risk.
cPanel disclosed a critical authentication bypass on April 28 affecting nearly all versions of cPanel and WHM, with active exploits confirmed in the wild before the patch was released, forcing hosting.com, Namecheap, KnownHost, HostPapa, and InMotion Hosting to take cPanel access offline globally.
The market for running OpenClaw splits cleanly into providers that have made it accessible and providers that have made it secure, and those are currently different products at different price points.
Vercel confirmed unauthorized access to its internal systems on April 19, 2026, while a threat actor claiming affiliation with ShinyHunters posted on BreachForums offering to sell the alleged dataset including GitHub tokens, NPM tokens, API keys, and source code for $2 million.
Flippa celebrated the six-figure sale of the Essential Plugin portfolio; eight months later the buyer activated a backdoor across 20,000+ WordPress sites using Googlebot cloaking and a C2 routed through an Ethereum smart contract.
Website hacks are no longer rare incidents. They are a growing operational challenge for web hosts and digital agencies. When a client’s site gets compromised, the immediate expectation is clear: fast resolution
Let's Encrypt issues approximately ten million certificates per day and is closing in on protecting one billion websites, making its May 13 root certificate switch a change that affects the majority of SSL certificates in any hosting provider's customer base. The two deadlines that require immediate action are May 13, when renewal automation must be verified to handle future shorter lifetimes correctly, and July 8, when client authentication certificates issued by Let's Encrypt stop working entirely. Providers whose automation relies on acme.sh face an additional gap: acme.sh does not yet support ACME Renewal Information (RFC 9773), the mechanism that lets Let's Encrypt communicate renewal windows directly to clients.
Cloudflare's 2026 Threat Report describes attackers who log in rather than break in, using stolen session tokens that bypass MFA entirely. On World Backup Day, the question worth asking is not whether you have a backup, but whether the attacker who logged into your environment three weeks ago has already found it.
The European Commission confirmed attackers accessed its AWS-hosted Europa.eu infrastructure and took data. AWS says its platform was not the issue, the customer account configuration was.
Cloudflare blocks AI bots by default and is testing a pay-per-crawl model. SiteGround silently filters training crawlers at the server level. IONOS rate-limits AI agents on shared hosting. As AI crawler traffic surges, hosting providers are splitting into those who have acted and those who have not - and the gap is becoming a competitive differentiator.
China's amended Cybersecurity Law, Hong Kong's first critical infrastructure statute, and Singapore's expanded compliance framework have all taken effect. For hosting businesses operating in the region, the compliance cost of inaction is now measured in millions.
High-profile breaches in South Korea, a near-universal shift toward outsourced security operations in Vietnam, and an evolving ransomware threat profile are defining the security reality for Asian hosting providers this quarter.
by WebhostingToday Security Team · 6 Mar 2026 · 3 min read
Security doesn’t stand still, and neither should the hosting industry. Welcome to the February 2026 WebHosting.Today Monthly Security Update, created in partnership with our trusted security sponsors, Monarx and Patchstack. Together, we’re
by Damian Andruszkiewicz · 23 Feb 2026 · 4 min read
A community-led forensic investigation links the attacks to a reported breach of 21 million records from PrestaShop's own Addons Marketplace. PrestaShop has not confirmed or denied the connection, only issued a security