cPanel published security advisories SEC-73728 and SEC-73755 covering vulnerabilities in cPanel & WHM and WP Squared, prompting follow-on guidance from the Canadian Centre for Cyber Security. The advisories affect multiple cPanel & WHM releases, including 11.86.0.45, 11.94.0.32, 11.102.0.43, 11.110.0.120 (cl6110), 11.110.0.121, 11.118.0.68, 11.124.0.41, 11.126.0.62, 11.130.0.26, 11.132.0.35, 11.134.0.29, and 11.136.0.13, along with WP Squared 11.136.1.16 and earlier.
Canada’s Cyber Centre advised administrators to review both vendor bulletins and apply the required patches to exposed systems. The notices indicate that organizations running affected hosting management platforms and WordPress management components should prioritize updates across supported branches to remediate the disclosed flaws.

See real exploitation activity before you spend the cycle.
4 events from the most recent confirmed update back to the earliest known activity.
On 2026-05-21, cPanel published new security advisories addressing vulnerabilities in cPanel & WHM, WP Squared, and EasyApache4. The advisories identified affected release lines including cPanel & WHM 11.126.0.63+, 11.134.0.30+, 11.136.0.14+, WP Squared 11.138.1.1+, and EasyApache4 versions prior to 25.62, and referenced CVE-2026-33278 and a cpanel-unbound 1.25.1 security release.
On 2026-05-20, the Canadian Centre for Cyber Security published advisory AV26-488 referencing cPanel's May 19 security advisories. It urged administrators to review the advisories and apply the necessary updates.
On 2026-05-19, cPanel published security advisories SEC-73728 and SEC-73755 for vulnerabilities affecting cPanel & WHM and WP Squared. The advisories covered affected cPanel & WHM versions through 11.136.0.13 and WP Squared 11.136.1.16 and prior.
On 2026-05-11, cPanel disclosed and patched three vulnerabilities affecting cPanel & WHM and WP Squared: CVE-2026-29201, CVE-2026-29202, and CVE-2026-29203. The flaws included path traversal, Perl code injection, and symlink-handling privilege escalation issues that could be chained for full server compromise from an authenticated shared-hosting account.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
6 references tracked. Mallory keeps watching after this page renders.
cyber.gc.ca
Open sourcecyber.gc.ca
Open sourcesupport.cpanel.net
Open sourcesupport.cpanel.net
Open sourcethecybersecguru.com
Open sourceinfosec.exchange
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.