All supported cPanel versions hit by critical auth bug, now patched


All supported cPanel versions hit by critical auth bug, now patched

Pierluigi Paganini
April 29, 2026

cPanel fixed a critical authentication flaw that could let attackers access servers. The issue affects all supported versions.

cPanel released security updates to address a critical authentication vulnerability that could allow attackers to gain unauthorized access to its control panel. The flaw affects all supported versions, raising serious risks for exposed servers.

cPanel is a widely used web hosting control panel that lets users manage websites and servers through a graphical interface instead of command-line tools.

The company has patched the issue in updated releases and urges administrators to apply updates immediately to reduce the risk of compromise.

Namecheap applied a temporary firewall rule blocking TCP ports 2083 and 2087, limiting access to cPanel and WHM until a full patch is released. The company warns that the mitigation may block access to cPanel and WHM and disrupt Webmail, Webdisk, and both SSL and non-SSL connections during this period.

“We regret to inform you that a critical security vulnerability has been identified in cPanel software affecting all currently supported versions. This vulnerability relates to an authentication login exploit that could allow unauthorized access to the control panel.” reads the advisory. “The fix has been successfully applied to all the remaining servers as well.”

The following versions address the vulnerability:

  • 11.110.0.97
  • 11.118.0.63
  • 11.126.0.54
  • 11.132.0.29
  • 11.136.0.5
  • 11.134.0.20

“If your server is not running a supported version of cPanel that is eligible for this update, it is highly recommended that you work toward updating your server as soon as possible, as it may also be affected,” cPanel noted.

As of April 29, 2026, 02:42 a.m. UTC, the fix has been deployed across Reseller, Stellar Business, and other servers, according to the Namecheap Support Team.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Namecheap)







Source link

Leave a Reply

Subscribe to Our Newsletter

Get our latest articles delivered straight to your inbox. No spam, we promise.

Recent Reviews


Strike action is planned for 3 and 4 March, and 7-17 March 2026. Discussions with UNISON are ongoing.

We have made a clear and constructive offer to establish a union recognition agreement, following the standard process led by Acas. As part of our offer, a final agreement on recognition would be subject to a whole-staff ballot. This is to ensure all staff have a say in this important decision.

Regarding pay, we cannot offer any uplift for the financial year 2025/2026 as this would put our service delivery at unacceptable risk and is not sustainable. We have made our tight financial situation clear to UNISON at every stage of our negotiations.

Our clients’ wellbeing continues to be our priority

While we respect the right of union members to take lawful industrial action, our focus remains on maintaining safe, continuous support for the people who rely on our services every day.

We are working with our teams to put our updated business continuity plans into action. Team managers and senior leaders are supporting colleagues, and despite strike action, services are continuing with minimal disruption. 

We remain committed to resolving this dispute and we are working with UNISON, via Acas, to see if we can resolve our differences.

This is not without its challenges, particularly at this time of year, and we are grateful to our hundreds of colleagues and clients for their understanding and support. 

If people have questions or concerns, they can contact us on 0117 909 6630 or email reception@second-step.co.uk. You can also visit our Answers to key questions about the strike page for more information.

For media queries, please contact PR & Communications Manager Jane Edmonds on 07841777401 or email jane.edmonds@second-step.co.uk. For out-of-hours queries, please call 07846377292.



Source link