#cpanel — Web Hosting News

All web hosting articles tagged #cpanel — 40 results.

Other
Automattic Is Not an Owner of the WordPress Marks It Asserted in Court, a Judge Rules
Natalia Nowak · 29 Sep 2026 · 6 min read
#automattic#web-hosting#wordpress
The September 24 order brings back four antitrust claims the same judge had dismissed in an earlier ruling. It also holds that Automattic and Mullenweg are neither owners nor registrants of the WordPress marks, so they cannot assert them in their own right.
Articles tagged #cpanel
1–20 of 40
Software reviews
cPanel AI Is Generally Available. Meridian Is in the License. Nova Runs on Credits Nobody Has Priced.
by Łukasz Nowak · 25 Sep 2026 · 9 min read
cPanel declared cPanel AI generally available on September 17. Meridian, the AI Assistant, AI App Hosting and MCP sit inside the ordinary license, while Nova is partner-only and metered in AI credits whose wholesale price neither cPanel nor WebPros has published.
Security
cPanel Patches a Root Escalation That Starts From an Ordinary Hosting Account
by Natalia Nowak · 24 Sep 2026 · 5 min read
cPanel patched a privilege escalation running from an ordinary hosting account to root, plus a WP Toolkit flaw reaching other accounts' databases. Three builds shipped September 22, no severity score is published, and one researcher is credited on four root-level flaws across cPanel and Plesk.
Security
Three LiteSpeed Security Builds in Six Days: Check Which One Your Servers Run
by Natalia Nowak · 18 Sep 2026 · 7 min read
A cPanel advisory of September 14 covers a LiteSpeed Enterprise flaw that lets a hosting account past CageFS to root. LiteSpeed has since shipped 6.3.7 three times in six days, each build with a security change, and a server patched on the day of the advisory is no longer on the latest one.
Security
Acronis cPanel Backup Plugin: Exploited Privilege-Escalation Flaw on CISA’s List
by Natalia Nowak · 17 Sep 2026 · 5 min read
Acronis has patched CVE-2026-87886 in its backup plugin for cPanel and WHM and says it has been used in limited, targeted attacks, based on one customer report. CISA added it to its Known Exploited Vulnerabilities catalog on September 16 with a three-day deadline for US federal civilian agencies.
Security
A cPanel Account With Mail Privileges Could Reach Root. Every Supported Version Was Affected.
by Natalia Nowak · 9 Sep 2026 · 4 min read
cPanel has patched CVE-2026-67401. An authenticated account with mail-related privileges could create files through EmailTrack and reach code execution as root. All supported versions were affected, and the CVE record scores the flaw 9.9 out of 10, critical.
Security
cPanel Patches a Root-Level Flaw in Domain Parking: One Customer Account With Domain Permissions Was Enough
by Natalia Nowak · 28 Aug 2026 · 3 min read
cPanel patched CVE-2026-65643: an account holder able to add parked or addon domains could create arbitrary files and reach root, taking every site on the server. All supported versions were affected. No CVE record, no CVSS and no exploitation status published so far.
Industry reports
The Field of cPanel Alternatives Keeps Widening. A Brand-New One Comes From Inside cPanel’s Ecosystem.
by Natalia Nowak · 14 Aug 2026 · 6 min read
Since cPanel moved to per-account pricing in 2019 and raised it most years since, the control panel has become a cost decision. Some hosts run their own panel, others license one of a widening set of independents, though the shift is directional rather than a measured stampede.
Security
Roundcube Shipped Eleven Security Fixes Without a Single CVE Number
by Natalia Nowak · 10 Aug 2026 · 5 min read
Roundcube shipped eleven security fixes across its current and LTS branches, including an IMAP command injection and a conditional code execution flaw. The notes name no CVE identifiers, so version-matching scanners stay quiet, and cPanel has historically taken five to nine days to follow.
Industry reports
Hosting’s Next Six Months Are Already Scheduled: Five Dates to Prepare For
by Natalia Nowak · 5 Aug 2026 · 6 min read
September 11 puts vendor silence on a 24-hour clock. Autumn opens the licensing season under a new ownership alignment. Q3 closes the Sedo window. November 1 raises .com to $10.97. January 12 kills egress fees. What prepared operators do before each date.
Security
Two of cPanel’s Three New Flaws Cross the Line Between Accounts
by Natalia Nowak · 29 Jul 2026 · 4 min read
cPanel patched three vulnerabilities on July 29, across every supported branch. Two matter most on shared servers: an unauthenticated request-smuggling bug that can alter other users' responses, and a database flaw that lets an ordinary account reach admin rights and possibly the host itself.
Security
A Malware Campaign Is Using GitHub Actions to Hunt Unpatched cPanel Servers
by Natalia Nowak · 24 Jul 2026 · 6 min read
Three months after cPanel's emergency patch, attackers have turned GitHub Actions into a distributed fleet that scans the internet for servers still exposed to CVE-2026-41940 and harvests their cloud keys, tokens and database logins. How it works, and what to check.
Expert's Voice
The Hosting Price Squeeze, Part 1: Why Your Costs Keep Climbing
by Michiel Grotenhuis · 17 Jul 2026 · 8 min read
Almost everything hosts depend on has gone up fast: energy, hardware, consolidation, and above all software licensing, from cPanel's post-2019 climb to Broadcom's VMware reset. Part one of a three-part series on what is really driving hosting costs up.
Security
Roundcube’s Zero-Click Webmail XSS, and How Fast It Reached cPanel
by Natalia Nowak · 15 Jul 2026 · 4 min read
A zero-click stored XSS in Roundcube webmail, scored CVSS 7.2, lets a crafted plain-text email run script in a victim's session on preview. Roundcube fixed it on July 5, cPanel shipped it in 134.0.45 on July 14, and standalone installs still need patching separately.
Security
The Exploit Record: How Government Networks Keep Getting Breached
by Natalia Nowak · 29 May 2026 · 14 min read
CVE-2026-41940 was exploited as a zero-day for 68 days before a patch existed. CISA was breached via Ivanti vulnerabilities it had just ordered patched. Volt Typhoon had 5-year US infrastructure access. The case-by-case record of how government networks keep getting owned.
Security
CVE-2026-48172: LiteSpeed cPanel Plugin Root Privilege Escalation, CVSS 10.0, Actively Exploited
by Natalia Nowak · 27 May 2026 · 3 min read
CVE-2026-48172 in LiteSpeed User-End cPanel Plugin (2.3-2.4.4) lets any authenticated cPanel user run arbitrary scripts as root. CVSS 10.0, actively exploited, on the CISA KEV list. Patch to WHM Plugin 5.3.1.0 / cPanel Plugin 2.4.7 immediately.
Security
Skynethosting Took Its Entire cPanel Fleet Offline on May 1. Two Weeks Later, Some Are Still Down.
by Natalia Nowak · 15 May 2026 · 10 min read
Skynethosting took its entire cPanel fleet offline on May 1 in response to CVE-2026-41940, and as of May 14 some customer servers had been down for nearly two weeks, with one reseller publicly reporting a 30 percent client loss during the outage.
Security
cPanel Patched Five More CVEs. One Fix Is Already Reported Incomplete.
by Natalia Nowak · 14 May 2026 · 9 min read
cPanel's May 13 patch covers five new CVEs, but security researcher Shubham Shah reported within hours that the fix for CVE-2026-29205 is incomplete and all cPanel instances remain exploitable until a working patch lands.
Security
Three cPanel Patches and DirtyFrag Fixes in One Day. Here Is Where Things Stand.
by Natalia Nowak · 13 May 2026 · 6 min read
On May 8, cPanel closed three new vulnerabilities and Linux distributions shipped DirtyFrag kernel fixes. Two weeks of disclosures left providers with three separate patch tracks. Here is the complete status and the confirmations every shared hosting customer should request.
Security
A Compromised Server Is the Beginning. Here Is What Breach Law Requires Next.
by Łukasz Nowak · 13 May 2026 · 35 min read
Change Healthcare's $3.1 billion in breach costs is the new normal of what a serious compromise sets in motion: parallel notification clocks across GDPR, NIS2, DORA, and HIPAA; personal liability for CISOs and boards; and a cyber insurance market with conditions that can deny coverage at the worst moment.
Security
cPanel Is Patching Three New CVEs Today. Technical Details Come With the Fix.
by Łukasz Nowak · 8 May 2026 · 3 min read
Three new cPanel vulnerabilities, CVE-2026-29201, CVE-2026-29202, and CVE-2026-29203, are being patched today at 12:00pm EST, with technical details withheld until the fix is live.
📬

Stay in the loop

Weekly digest of the best hosting news, reviews and industry moves.

Page 1 of 2