We are carrying out emergency security maintenance on the server that hosts your website and email.
Window opens: Friday 18 September, 20:00 WAT / 19:00 GMT / 3:00 PM ET
Expected duration: 24 to 48 hours. We expect to finish well before the upper end of that range and will confirm as soon as we do.
What to expect
- Early in this window there should be little or no disruption — we are completing full backups first.
- Your website and email will then be unavailable while the server is rebuilt. We will keep that period as short as we can.
- Email sent to you during the outage will not be lost. Sending mail servers queue messages and retry automatically for several days; your mail will arrive once we are back.
- No action is required from you. No passwords, settings, addresses or DNS records will change.
Why we are doing this
Following a security review of our hosting platform, we have decided to rebuild the server on a clean, fully licensed installation rather than continue patching in place.
Part of the context is the cPanel & WHM authentication-bypass vulnerability disclosed earlier this year — CVE-2026-41940 — which was being exploited in the wild before a fix existed and affected an estimated 1.5 million servers worldwide. Our systems were updated to the patched version as soon as it was released, and we have no indication of any impact to your account. However, the accepted practice after a vulnerability of that class is to rebuild on a clean platform rather than assume a patched system is a clean one.
Independent coverage, if you would like to read more:
- Australian Cyber Security Centre — Active exploitation of cPanel/WHM critical vulnerability
- Rapid7 — CVE-2026-41940: cPanel & WHM Authentication Bypass
- The Hacker News — Critical cPanel Vulnerability Weaponized to Target Government and MSP Networks
- Malwarebytes — Actively exploited cPanel bug exposes millions of websites to takeover
- watchTowr Labs — technical analysis of the authentication bypass
- Picus Security — CVE-2026-41940 explained
The same review identified third-party components we are removing as part of this work. Rebuilding lets us address all of it at once and bring the entire stack onto current, supported versions.
If you are a reseller
If you host client websites or email under your own brand on our platform, please pass this notice on to them as soon as possible so they can plan around the window. You are welcome to forward this message.
We will email again as soon as service is fully restored. If you have something time-critical in the next 48 hours: a launch, a campaign, an important send, a client deadline, reply to this message and we will work around it.
Thank you for your patience.
