Service Security Update: Ongoing Global cPanel Attack & Mitigation Measures

  • Monday, 4th May, 2026
  • 23:32pm

We would like to inform all our clients about a widespread global attack currently targeting cPanel servers, linked to a recently disclosed Login-Authentication vulnerability (CVE-2026-41940) affecting cPanel & WHM environments.

Read official advisory here:
https://support.cpanel.net/hc/en-us/articles/40073787579671-Security-CVE-2026-41940-cPanel-WHM-WP2-Security-Update-04-28-2026

Our Response & Security Status

Enet Support team was able to promptly apply all security patches released by cPanel as soon as they were made available. This ensured that our cPanel infrastructure was not compromised during the initial vulnerability exposure window.

However, beginning Saturday, a large-scale automated attack campaign has been targeting cPanel servers globally, including our infrastructure. This has resulted in:

  • Increased server load and resource consumption

  • Slower response times on some websites

  • Intermittent delays in accessing cPanel and Webmail services

Mitigation Measures Implemented

To counter these attacks and stabilize services, we have actively reinforced multiple security layers including:

  • Enhanced CSF firewall rules and connection limits

  • Deployment and tuning of Imunify360 protection rules

  • Strengthened ModSecurity WAF rulesets

  • Implementation of Fail2Ban automated intrusion blocking

  • Continuous real-time monitoring and traffic filtering

Our team continues to actively block malicious traffic and adjust security rules as attack patterns evolve.

Service Impact
  • Some cPanel-related services may experience temporary slowness

  • Occasional delays may be observed on Webmail and hosting dashboards

  • Website hosting services remain operational, though performance may vary under load

Important Note

All services hosted on DirectAdmin or non-cPanel environments are NOT affected by this attack and continue to operate normally.

Ongoing Work

We are actively:

  • Monitoring server performance 24/7

  • Fine-tuning firewall and rate-limiting rules

  • Blocking new attack vectors as they emerge

  • Working with upstream security advisories for updates

Our Commitment

We understand the inconvenience caused by intermittent service slowdowns and sincerely appreciate your patience. Our priority remains service stability, security, and uninterrupted access for all clients.

We will continue to provide updates as the situation evolves.

Enet Support Team

« Back