cPanel issues emergency patch for critical authentication flaw
cPanel has disclosed a critical vulnerability in the authentication mechanisms of supported versions of cPanel and WHM. The flaw could allow unauthorised access through the way authentication is handled. The vendor has released emergency patches for all supported versions and urges customers to update immediately.
What this means for your organisation
cPanel and WHM manage hosting and servers for a large number of Norwegian businesses, usually through a hosting provider rather than in house. A control panel with a broken authentication path hands an attacker the keys to everything that panel administers: websites, mail, databases and customer data. The question for management is not whether you run cPanel yourselves, but whether your provider does, and when they actually patched.
Berigo recommends
- Update every cPanel and WHM installation to the patched version now, not at the next scheduled window.
- Ask your hosting provider to confirm in writing that the update is done, with date and version number.
- Review panel login logs and user accounts for access you do not recognise.
- Enable two-factor authentication for all administrator accounts, and restrict panel access to known IP addresses where practical.
Source
Security that is understood, governed and works.
Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.
Get in touch