We are facing frequent cpanel/WHM password changes for most of the accounts on the server, is there any vulnerability? is there any security patch available?
Hey there! Can you get me more details about what you're seeing? Are users being prompted to change passwords, or are the passwords being reset without their knowledge?
users are not being prompted to change passwords, but the passwords are being reset without their knowledge and after resetting to the default working fine.
and this happens to all servers ....
how to check which files are exactly being compromised for this password change for all accounts.
I'm afraid I don't have a good explanation for this problem, especially if the issue is happening on multiple servers. I suppose it is always possible that a certain user infected multiple systems, but it would be best to submit a ticket to our team so we could review at least one of the affected machines and see if there are any obvious issues.