Security Update for Domain of One's Own and Managed Hosting with cPanel Administrators

Security Update for Domain of One's Own and Managed Hosting with cPanel Administrators
‼️
This announcement is relevant to administrators of Domain of One's Own and Managed Hosting servers that run cPanel/WHM.

Two days ago, we became aware of a critical vulnerability in cPanel that had just been patched:

Security: CVE-2026-41940 - cPanel & WHM / WP2 Security Update 04/28/2026

This vulnerability in cPanel's authentication system affected all recent versions. We mitigated the issue on all servers by deploying a software update released concurrently with the public announcement. The update was applied to all relevant servers on the same day the vulnerability was disclosed.

Since then, cPanel has released a detection script to identify indicators of compromise related to this vulnerability. We have run their script and conducted our own internal investigation. No evidence of exploitation has been found on any cPanel servers managed by Reclaim Hosting.

Out of an abundance of caution, we have reset all administrator passwords for WHM servers. If you are an administrator for Domain of One's Own or a Managed Hosting service running cPanel and are experiencing difficulty logging into WHM, please contact our support team so we can assist you in regaining access.

If you notice any suspicious behavior, or have any other questions please let us know!