cPanel Authentication Bypass Exploitation Active | MSSP Advisory

Critical
DateMay 4, 2026
📋Executive Summary
Multiple proof-of-concept exploits have emerged targeting a critical authentication bypass vulnerability in cPanel, with claims of zero-day exploitation occurring for at least a month before public disclosure. The vulnerability allows attackers to bypass authentication mechanisms in cPanel installations. One researcher indicates active exploitation preceded the public vulnerability disclosure.
⚠️Why It Matters for MSSPs
Your hosting clients running cPanel are sitting ducks right now, and if you manage any cPanel instances for web hosting clients, your access credentials could hand attackers the keys to multiple client environments simultaneously. The month-long exploitation window before disclosure means compromised systems are already out there, and your clients expect you to know about threats hitting their hosting infrastructure before they read about it on Twitter.
Recommended Action
Contact all clients using cPanel hosting within 24 hours to verify patch status and force password resets on all cPanel accounts immediately.
🔒
Partner content — get access free
The recommended action is included in your white-labeled advisory — ready to send to clients under your name.
Get your first advisory free →
🏷️Threat Category
Vulnerability Disclosure

Partner MSSPs receive the full advisory — talking points, actions, and social posts — under their own brand.