cPanel Security Incident — Recovery Progress & Live Updates
This page is the official Hostao source for incident progress updates related to the current cPanel security issue. We will continue updating this page as recovery work moves forward.
Update 8
03 May 2026 | 04:05 PM GMTRecovery is moving forward in phases. Around half of the affected SEO environments are now back online, and roughly one-third of the impacted Baremetal and SmartCloud systems have completed restoration. The remaining systems are still going through controlled rebuild, security review, and staged service return checks before access is reopened.
Update 7
02 May 2026 | Additional security validationAn additional kernel-level security review is being applied across relevant systems as part of the recovery track. Systems that were already brought back online are also being rechecked against the latest hardening requirements. No customer action is required, but these extra safeguards may slightly extend the overall restoration timeline.
Update 6
02 May 2026 | 12:37 PMRecovery continued to expand across the affected estate, with about 40% of impacted servers restored and a large portion of USA reseller capacity returned. On recovered systems, websites and email may already be available, while cPanel and webmail remain temporarily restricted until the final security clearance is completed.
Update 5
02 May 2026 | 10:30 AMEarly restoration milestones were achieved across the affected platform, including a meaningful portion of reseller environments. At that stage, systems were still moving through patching, hardening, and service validation before normal access could resume.
Update 4
02 May 2026 | 08:00 AMRebuild and patch work continued through the night. Affected environments are being reloaded, upgraded, and fully checked before being returned to production use.
Update 3
01 May 2026 | 11:30 PMThe first recovery wave began after containment was completed. Isolated systems moved into verification and staged restoration.
Update 2
01 May 2026 | 06:00 PMAs a safety measure, affected cPanel-related services were temporarily taken offline while the incident was being contained and reviewed.
Update 1
01 May 2026 | 03:30 PMHostao activated incident response procedures immediately after identifying a serious cPanel security event that required containment, review, and controlled recovery planning.
