Days after a critical vulnerability in cPanel and WebHost Manager (WHM) was publicly disclosed, hackers continue to actively exploit the flaw to gain unauthorised control over thousands of websites globally. The widespread nature of cPanel, a popular control panel for web hosting, means a vast number of websites are potentially at risk if they have not yet applied the necessary security patches.
The vulnerability allows attackers to execute arbitrary code with root privileges on affected servers, effectively giving them full control. This level of access could enable malicious actors to deface websites, steal sensitive data, inject malware, or disrupt online services. Security researchers have observed a sustained campaign of attacks targeting unpatched systems, highlighting the urgency for administrators to update their software.
For UK businesses, particularly small and medium-sized enterprises (SMEs) that often rely on shared hosting providers utilising cPanel, this poses a significant threat. Many online shops, service providers, and information portals could be powered by cPanel, making them potential targets. A successful hack could lead to financial losses, damage to customer trust, and regulatory penalties if personal data is compromised.
Consumers in the UK are also indirectly affected. If a website they use for online shopping, banking, or general information is compromised, their personal data could be exposed, or they might be redirected to malicious sites. The integrity of online transactions and the security of personal information depend on the robustness of the underlying web infrastructure, including software like cPanel.
Web hosting providers and individual website administrators are being urged to prioritise applying the security updates released by cPanel to mitigate the risk. The window of opportunity for attackers remains open as long as unpatched systems are connected to the internet.