Navigation indicator

Securing Your Websites Against 0-Day Threats: How Varial Hosting Responded to This Week’s Critical Security Vulnerabilities

May 1, 2026

Securing Your Websites Against 0-Day Threats

TLDR; Our servers are fully patched against this week’s high-profile cPanel (CVE-2026-41940) and “Copy Fail” Linux (CVE-2026-31431) security threats. No action is required on your part; our team has already handled these updates for you.

This week was a busy one for our security team.

Rapid Response to the cPanel Authentication Vulnerability

On Tuesday, April 28th, a critical vulnerability was identified in cPanel (CVE-2026-41940). This flaw was particularly serious because it allowed for an “authentication bypass”—essentially meaning an attacker could gain administrative access to a server without needing a password.

Because we stay active in core industry security circles, we were alerted to this risk early. Following best practices, we took the proactive step of temporarily restricting access to cPanel, WHM and Webmail. This “closed the door” while we waited for the official software patch to be finalized.

Once the patch was released that afternoon, our team tested and deployed it across our entire network immediately—finishing the work many hours before standard nightly maintenance would have even begun.

By the time cPanel’s official email alert reached most server owners the following day, the digital landscape was already seeing a massive spike in exploit attempts. We are pleased to report that because of our team’s early intervention, Varial Hosting servers were fully secured before these global attacks even began.

Protecting Server Integrity Against the “Copy Fail” Threat

The very next day, Wednesday, April 29th, a second global threat emerged.

A vulnerability nicknamed “Copy Fail” (CVE-2026-31431) was discovered, affecting almost all Linux-based systems worldwide. This flaw could allow a low-level user to “escalate” their permissions to gain total control of a server.

Because the primary risk involved secure shell (SSH) access, we took the immediate precaution of temporarily disabling customer SSH and implementing early defenses while waiting for an official fix from our OS vendors.

When it became clear that a final patch would take some time to arrive, we decided not to wait. We implemented a “kernel-level” mitigation—a deep-system fix that required a full server reboot to activate.

Prioritizing Security Over Uptime

While we take pride in our ability to perform “rebootless” updates (some of our servers hadn’t needed a restart in over two years!), the emerging risk was too high to ignore. Security experts warned that hackers might try to use outdated or compromised WordPress sites as a “back door” to trigger this exploit. To ensure your data remained 100% isolated and secure, we performed a controlled reboot across our fleet last night.

As of this morning, we are happy to confirm that all servers are now running the fully patched kernel, and this vulnerability is closed.

Our Commitment to Your Security

At Varial Hosting, we know that you count on us to manage the complex world of server security so you don’t have to. While “0-day” threats like these make headlines, they are a routine part of our workday. Our team remains vigilant, monitoring global threat feeds 24/7 and testing patches before they are even officially announced to the general public.

We take these proactive steps to ensure that your business remains online and your data remains private, without you ever having to lift a finger.

Questions?

If you have any questions about these updates or our security protocols, our support team is always here to help. Feel free to open a support ticket or reach out to us directly.

Scheduled Maintenance: MariaDB (MySQL) Upgrade on Tonks [Completed]

May 20, 2025

In the evening of Sunday, June 1, 2025 we will be upgrading the MariaDB (MySQL) database server on our Tonks server from MariaDB 10.5 to MariaDB 10.6.

Websites utilizing MariaDB/MySQL databases will be temporarily unavailable for approximately 10-15 minutes until the upgrade is complete.

Snape Server Shutdown Notice [Completed]

May 30, 2024

We have scheduled the migration of all customers off of our Snape server and will be shutting down the server on Sunday, June 30, 2024.

Customers using 3rd party DNS services to point their domains to our servers have been notified by email with instructions on how to point their domains to their new server IP. This action must be completed by Saturday, June 29, 2024 at the latest to prevent any service interruptions.

Malfoy Server Shutdown Notice [Completed]

May 13, 2024

We have scheduled the migration of all customers off of our Malfoy server and will be shutting down the server on Friday, June 14, 2024.

Customers using 3rd party DNS services to point their domains to our servers have been notified by email with instructions on how to point their domains to their new server IP. This action must be completed by Thursday, June 13, 2024 at the latest to prevent any service interruptions.

Hermione Server Shutdown Notice [Completed]

April 15, 2024

We have scheduled the migration of all customers off of our Hermione server and will be shutting down the server on Tuesday, May 14, 2024.

Customers using 3rd party DNS services to point their domains to our servers have been notified by email with instructions on how to point their domains to their new server IP. This action must be completed by Monday, May 13, 2024 at the latest to prevent any service interruptions.

Sirius Server Shutdown Notice [Completed]

April 1, 2024

We will be completing the migration of all customers off of our Sirius server this week and will be shutting down the server on Sunday, April 14, 2024.

Customers using 3rd party DNS services to point their domains to our servers have been notified by email with instructions on how to point their domains to their new server IP. This action must be completed by Saturday, April 13, 2024 at the latest to prevent any service interruptions.

Upcoming Server Migration and Upgrade Notice

March 13, 2024

Over the next 3 months, all customers hosted on our Hermione, Malfoy, Sirius and Snape servers will be migrated to new servers.

Affected customers will receive an additional email with more information when their date of migration has been scheduled.

The operating system on these servers will reach its end of life later this year, requiring all customers hosted on these servers to be moved to new servers to accommodate our server upgrade plans.

In addition to the new operating system, customers will benefit from significantly faster SSD storage available on our new servers following the migration.

What can I do now to get ready?

If you use our email service and connect to your email using applications like Outlook or Apple Mail, please verify that you are connecting to mail.yourdomain.com (*replace yourdomain.com with your actual domain name) as both your incoming and outgoing mail servers.

This will allow your email to seamlessly transition from the old server to the new server during the migration process. If you are currently connecting to addresses like servername.varialhosting.com, we recommend changing your incoming and outgoing mail server addresses to mail.yourdomain.com prior to your scheduled migration date. All other email settings can remain the same.

If you are using a 3rd party email service, no changes are required.

More information will be given in an additional email when the date of your migration is scheduled.

Scheduled Network Maintenance [Completed]

November 21, 2023

Data center technicians will be performing network maintenance on Thursday, November 23, 2023 from 8PM-9PM CST.

The network connection that is provided to our equipment will simply be moved to a different port on our upstream provider’s equipment during this maintenance.

Estimated downtime for all services is expected to be within 30 seconds to 5 minutes while our network connection is moved from one port to another.

Scheduled Maintenance: MySQL (MariaDB) Upgrades on Malfoy and Sirius [Completed]

September 19, 2023

In the evening of Saturday, October 7, 2023 we will be upgrading the MySQL database server on our Malfoy and Sirius servers from MySQL 5.7 to MariaDB 10.5.

MariaDB is an optimized, drop-in replacement for MySQL.

This upgrade will be completed in two steps, first the migration from MySQL 5.7 to MariaDB 10.3, and then the upgrade from MariaDB 10.3 to MariaDB 10.5.

Websites utilizing MySQL databases will be temporarily unavailable for approximately 15-30 minutes until the upgrades are completed on each server.

Upon the completion of this maintenance, all of our servers will now be migrated to MariaDB.

Scheduled Maintenance: MariaDB (MySQL) Upgrades on Hermione, Snape and Tonks [Completed]

May 5, 2023

In the evening of Saturday, May 20, 2023 we will be upgrading the MariaDB (MySQL) database server on our Hermione, Snape and Tonks servers from MariaDB 10.3 to MariaDB 10.5.

Websites utilizing MariaDB/MySQL databases will be temporarily unavailable for approximately 10-15 minutes until the upgrades are completed on each server.