Bonum Certa Men Certa

cPanel is Not Linux, cPanel is Proprietary Software

posted by Roy Schestowitz on May 02, 2026,
updated May 02, 2026

cPanel

I believe (from some very distant recollection) that the first time I used cPanel was in 2003 or 2004. Prior to that FreeBSD hosting was used for my personal site, but I had heard of cPanel and it sounded rather useful. It is written in Perl and it turned 30 just 2 weeks ago.

cPanel as a software (not LLC) isn't bad. I won't lie. Some things in cPanel I found very useful and I used cPanel extensively when I was a student. Some time around 2006 I used it less and less, even if it was generally 'there'... available in case command line-based server administration had a high learning curve.

It's fair to say I've used cPanel for 23 years (the software was first released in 1996) and still have it on about 7 sites. I'm no longer a 'cPanel guru' because I've not "kept up" with its features for many years and I generally dislike all the redesign and bloat they added to it (first it was not mandatory because there was a 'classic' mode, then they took away that mode).

cPanel nowadays feels like bloatware and I don't easily find my way around it (they're moved everything around).

That cPanel has security issues is neither new nor surprising. It's even less surprising these days given the bloating effect. The more functionality or the more lines of code get added to cPanel, the higher the risk of defects including severe security holes.

Connor Jones at The Register MS has just published this article entitled "Critical cPanel, WHM flaw probs exploited as 0-day, pros say". "For the uninitiated," he says, "cPanel and WHM are both Linux-based control panels. The former is used to manage websites, databases, file transfers, email configurations, and domains, while WHM is used for servers."

Calling them "Linux-based" is like calling WordPress "Linux-based". cPanel runs on top of systems, typically GNU/Linux systems like RHEL or CentOS. cPanel has no kernel, so it's not "Linux-based" and this sort of phrasing encourages a confusion, at the very least a baffling and misleading misconception.

As we sometimes say, as we have many times before, Microsoft money corrupts the press (the above publisher is controlled by a Microsofter now); the media wants us to think that anything not Windows or Microsoft is "Linux" - more so when it's in some negative context like a system breach (which may be due to some rogue WordPress extension, neither WordPress 'core' nor Linux... or PHP, MariaDB etc.) and it's not an accident.

"cPanel is proprietary software," a reader said, yet "the Reg tries to spin this as a "Linux" problem" (a topic we've explored a lot in past year).

So basically there's some proprietary piece of software with a bug in it. It is exploited before a patch is made available and because it is proprietary the users (or sometimes someone they collectively hire) cannot fix it themselves, they're at the mercy of some company that can exercise control over them (e.g. charge them more for a faster delivery of a much-needed patch).

The main lesson here is, proprietary has security problems. We'll say more about this in relation to the NHS in a separate article.

Other Recent Techrights' Posts

SLAPP Censorship - Part 64 Out of 200: Not Amused by Repeated Threats (to "Shut Down" My "Existence" While Mentioning My Wife Too)
it's about censorship
The NHS is Under Attack by Anthropic and Microsoft (or Their Lemmings That Infect the NHS)
They are kidding themselves if they seriously believe Web-facing source code repositories are the real threat to patients
cPanel is Not Linux, cPanel is Proprietary Software
It's fair to say I've used cPanel for 23 years
Storage and Memory Prices Are Rising Not Because of High Demand (Production Can Match Demand), It's Partly Because of Price-Fixing (Same as Food Price Increases)
Sophisticated robberies are still robberies
Thousands of Layoffs at IBM, So IBM Pays Mainstream Media to Claim That IBM is Hiring (Paid Lies)
This is a story about the media failing us, not just IBM failing as a company
A Look at DataStax Bluewashing (IBM and Layoffs)
IBM is a place that many people leave or get pushed out of
 
A Month Since Mass Layoffs at Red Hat (400+ Engineers Laid Off), The Media Didn't Cover It
We are very concerned about the state of the media
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Saturday, May 02, 2026
IRC logs for Saturday, May 02, 2026
Gemini Links 02/05/2026: Strange Psychosis and TUIs
Links for the day
Links 02/05/2026: Microsoft Has Begun Rebranding Vista 11 as 'XBox' (Because the Console is Dying), Slop Rejected by Oscars
Links for the day
IBM's CEO 10 Years Ago in IBM-Sponsored Forbes: "For those willing to embrace [blockchains], the future will indeed be bright."
How well did this prediction materialise?
RightsCon Cancellation as a Data Point in a World Gone Astray
RightsCon should not even be controversial
Links 02/05/2026: Gen Z is Turning Against Slop and OpenAI/Microsoft Rift Explained
Links for the day
Gemini Links 02/05/2026: Leaving Session, Alhena 5.5.7, and Slop Failing Customers
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Friday, May 01, 2026
IRC logs for Friday, May 01, 2026
Links 01/05/2026: Microsoft 'Headcount' Decreasing, Apple Quietly Killing Vision Pro
Links for the day
Oracle's Debt Grew by Over 50 Billion Dollars in 6 Months
Larry Ellison spent a lot of money buying a lot of the corporate media
In Praise of Debian
30 hours ago we began an upgrade
What Linus (Torvalds, the Linux Dude) Meant by "Show Me the Code"
"Show Me the Code" is a common cultural reference
Yes, GNU/Linux Can Run on Playstation 5, But Don't Buy It, Learn From Sony's Past of Rootkit and PS3 Betrayal
Millions of Playstation 3 owners will never forget what Sony did to them
XBox Will Not Last Much Longer, XBox Chief Admits Problems
Microsoft's latest "results"
Dealing With Demagogue in Free Software
Don't spread their ideology and never participate in any of their projects
What May 1 Means to Us (and to Many Others)
To me, May 1 means something
Microsoft Lunduke is 'Pulling a Garrett' by Turning Technical and Legal Debate Over Rust Into a 'Trans Debate'
Don't fall for the demagogue
Links 01/05/2026: Regulatory Trouble for Apple, Now Even Mozilla Pushes Back Against Google
Links for the day
Microsoft "Buyout" Offer is Less Than One Year's Salary
So our assumption about this was correct
The Corrupt Lecture the Non-Corrupt - Part X - European Patent Office Managers Have Crossed Red Lines, According to Themselves
The girlfriend of the President of the European Patent Office (EPO) is trying to muzzle EPO critics
Techrights is Still Growing, Attacking Techrights Does Not Weaken the Community
Bullying us for 2+ years does not result in fear, it results in us feeling more emboldened and motivated
SLAPP Censorship - Part 63 Out of 200: Graveley as a Stripped-Down Version of Garrett in the Particulars of Claim (5RB Barrister Could Do This in One Minute)
Lazily and sloppily, it looks like the barrister took Garrett's claims and tweaked them a little (shortened) for Graveley
Lots of People Leave IBM, Today IBM Has About 1,000 Workers Fewer Than Yesterday
Confluent "last day" for 800+ people
Been a Very Busy Week
Next week, as we have no upgrades to prepare for, we should be able to publish at the usual pace of 20+ pages per day
In New Letter Sent to Chair and Heads of Delegation of the Administrative Council of the European Patent Organisation the Staff Union Explains How to End European Patent Office Strikes
If Campinos continues to behave as he does right now, the Council can show him the door
Links 01/05/2026: Poems and Continuous Privacy Policy
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Thursday, April 30, 2026
IRC logs for Thursday, April 30, 2026
Microsoft Debt Rose Almost $50 Billion Since We Moved to Debian
GAFAM has a new name for debt