13 May 2026

Practice managers are being urged to check with their IT support provider or website administrator following a cPanel cyber security alert issued by the Australian Digital Health Agency (ADHA).

The alert relates to a security vulnerability affecting cPanel and Web Host Manager – systems commonly used to manage websites, web hosting and online services.

According to the ADHA, the vulnerability could allow cyber attackers to gain administrator access without needing a password. Practices which use cPanel may be at risk, including websites or other hosted data and services.

What practices should do:

  • contact your IT support provider or website administrator as soon as possible
  • ask them to check whether your practice uses cPanel
  • ensure any affected systems are updated and secured
  • ask them to review for any signs of suspicious activity or compromise

The ADHA advises organisations to apply security patches urgently and restrict external access where required.

 

Read full security alert