Dear customer,
Today, April 28, 2026, the vendor of cPanel/WHM has published a critical security advisory affecting every currently supported version
of the control panel. The vulnerability can, under certain conditions, allow an attacker to bypass cPanel/WHM authentication. At the
time of this notice, the official patch has not yet been released.
Following the vendor's official mitigation guidance to the letter, we have applied two preventive measures across all of our servers:
- Perimeter firewall block on Internet access to the control panel ports:
- 2082, 2083 — cPanel interface
- 2086, 2087 — WHM interface (resellers and administrators)
- 2095, 2096 — Webmail (Roundcube / Horde)
- 2077, 2078 — cpdavd (calendar, contacts and file sync over WebDAV)
- Service Subdomains (Proxy Subdomains) disabled on every cPanel server. This means the automatic control-panel subdomains will no
longer resolve:
- cpanel.yourdomain.com
- webmail.yourdomain.com
- whm.yourdomain.com
- webdisk.yourdomain.com
What is NOT affected
- Your websites continue to operate normally (ports 80 and 443 to yourdomain.com and www.yourdomain.com).
- Email continues to send and receive without interruption through your usual clients (Outlook, Thunderbird, mobile) using IMAP, POP3
and SMTP on their standard ports (110, 143, 993, 995, 25, 465, 587).
- SSH, FTP and database access have not been changed.
- DirectAdmin (port 2222) and Webuzo (2002/2003), where applicable, are also unaffected.
What IS affected
- It is not possible to log in to cPanel or WHM from the Internet by any route (neither through ports 2083/2087 nor through
cpanel.yourdomain.com).
- Browser-based Webmail is out of service for the duration of this advisory.
- The cpanel., webmail., whm.* and webdisk.* subdomains will not resolve while the mitigation is in place.
- Calendar, contacts and file clients using WebDAV (cpdavd) will be unable to sync.
Alternatives during the mitigation window
- Email: continue using your usual mail client (Outlook, Thunderbird, mobile app) with your standard IMAP/POP3 + SMTP configuration.
Email itself is not affected at any point.
- Urgent panel-side requests (create a mailbox, change a password, restore from backup, switch PHP version, etc.): please open a support
ticket and our team will perform the action on your behalf during this contingency.
- No action is required from you on your server or your website: the mitigations have already been applied at the infrastructure level.
Next steps
We are actively monitoring the release of the official patch from cPanel and will deploy the update across every server as soon as it
becomes available. Once installed and verified, we will automatically restore normal access to the control panel, the service
subdomains, and all affected ports, and a follow-up notice will be sent confirming closure of the incident.
Thank you for your understanding. The security of your data and your site is our top priority, and we prefer to temporarily restrict a
service rather than leave it exposed to a known risk.
For any urgent inquiries, please reply to this ticket or contact us through the usual channels.
Sincerely,
Support Team