Service Security Update: Ongoing Global cPanel Attack & Mitigation Measures
-
Monday, 4th May, 2026
-
23:32pm
We would like to inform all our clients about a widespread global attack currently targeting cPanel servers, linked to a recently disclosed Login-Authentication vulnerability (CVE-2026-41940) affecting cPanel & WHM environments.
Read official advisory here:
https://support.cpanel.net/hc/en-us/articles/40073787579671-Security-CVE-2026-41940-cPanel-WHM-WP2-Security-Update-04-28-2026
Our Response & Security Status
Enet Support team was able to promptly apply all security patches released by cPanel as soon as they were made available. This ensured that our cPanel infrastructure was not compromised during the initial vulnerability exposure window.
However, beginning Saturday, a large-scale automated attack campaign has been targeting cPanel servers globally, including our infrastructure. This has resulted in:
-
Increased server load and resource consumption
-
Slower response times on some websites
-
Intermittent delays in accessing cPanel and Webmail services
Mitigation Measures Implemented
To counter these attacks and stabilize services, we have actively reinforced multiple security layers including:
-
Enhanced CSF firewall rules and connection limits
-
Deployment and tuning of Imunify360 protection rules
-
Strengthened ModSecurity WAF rulesets
-
Implementation of Fail2Ban automated intrusion blocking
-
Continuous real-time monitoring and traffic filtering
Our team continues to actively block malicious traffic and adjust security rules as attack patterns evolve.
Service Impact
-
Some cPanel-related services may experience temporary slowness
-
Occasional delays may be observed on Webmail and hosting dashboards
-
Website hosting services remain operational, though performance may vary under load
Important Note
All services hosted on DirectAdmin or non-cPanel environments are NOT affected by this attack and continue to operate normally.
Ongoing Work
We are actively:
-
Monitoring server performance 24/7
-
Fine-tuning firewall and rate-limiting rules
-
Blocking new attack vectors as they emerge
-
Working with upstream security advisories for updates
Our Commitment
We understand the inconvenience caused by intermittent service slowdowns and sincerely appreciate your patience. Our priority remains service stability, security, and uninterrupted access for all clients.
We will continue to provide updates as the situation evolves.
Enet Support Team