[URGENT] Cyberpanel ERROR 404

Hello Community!

I have an urgent problem. Cyberpanel on :8090 suddenly thows an error 404 and I can’t access the panel.

I have a VPS and I’m using latest versions of Ubuntu and CyberPanel. The resources are good.

  1. No emails are working for none of the websites.
  2. I can access WebAdmin on :7080 without any issues.
  3. No changes has been made for weeks on the server.
  4. I can’t SSH to the server through the terminal: port 22: Connection refused
  5. The SSL for the server panel is intact.
  6. All the websites on the frontend are working.
  7. All listeners are good in WebAdmin.

I’m pretty much locked out! Any direction to the solution will be greatly appreaciated!
I have searched alot and can’t find any related topic.

The most urgent thing here is that the email-accounts arent working so I have multiple businesses DOWN.

Thank you for any ideas!

I have a similar situation. No SSH access, I can log into the panel. (License)
On another server, the site is 404, I can’t log into the panel. (Without a license)

  • abnormal CPU load - 100%

Thank you for your answer. How do you see the CPU load?

Same Problem for me for 3 different servers, others looks good. Does anyone know root cause of the problem and how to solve?

Seems to be a virus: Critical Security Alert: Vulnerable CyberPanel Instance Detected on Your Network - #2 by bcat95

But I cant know for sure because I can’t SSH…

Hello

I have 40+ servers all are down. Feeling very very very very Great :slightly_smiling_face:

I found this process “/var/tmp/kdevtmpfsi” using my full cpu, which is identified as a crypto miner.


To check cpu usage use command “htop”

Thank You.

Ah! I have only one server, but 20 sites and 10 of them are good businesses that need their email-accounts to always work.

How do I use the command without being able to connect to the server through SSH?

Hello

Sharing something…

I have wasted my 10+ hours just checking the data center, network cables, dns, public dns etc. And at the end of the day, I found that cyberpanel is down. I am in a deep pain right now.


You can’t run this without SSH Access.

Thank You

1 Like

Bro I feel your pain,

I only have about 7 and it’s headache so I can imagine in your case.
I had to access via KVM to re-enable sshd and try to cleanup.

I am done with this.

12 of my server owners are asking for refund :slightly_smiling_face:


Do you know whether the issue has been resolved or changes implemented from cyberpanel team? Because I am not getting anything like this.

Then I can try updating and do some steps. My team is also trying to access via rescue mode and trying to fix this.

Thank You

This seems to be the cause: What Are My OPTIONS? CyberPanel v2.3.6 pre-auth RCE

I have seen no response from Cyberpanel.
It looks like you have to lock down 7080, 8090 and cleanup while u can.
On the second hit, one of my servers they started removing system files and packages.

In my case, I’m providing the hosting for free so I guess I don’t have to do the refund-thing hehe. But I have like 20 messages a minute.

I haven’t heard anything yet. My hosting company is on it, just because I can’t access anything. My hopes are on them at the moment…

Yes! They should post something as a note. So that I can also notify my hosting community about it.

500+ websites on cyberpanel and other around 3000+ domains are on cpanel. So its a big thing for me.

I have to update the policies also for this. And I have to told them that the issues is not actually caused because of our server or datacenter anything.


I know that accidents can’t be guessed, but at least they should write some information around it on the Internet. Like a status page or sometime. Isn’t it?

Thank You

1 Like

Hi, everyone

Note: In this hard time we would really appreciate all the help from community because everyone is in panic and if any users can help each other please do.

We do know about the security issue and patch was released last week.

We did not update in this community last week so that maximum users can update their servers before anyone can know (any malicious user, because if they do they will start attacking servers.) .

We are also preparing a detailed blog post, I am getting 100s of messages, tickets so I won’t be able to reply to each individual user (sorry regarding that)

We are working 24/7 with everyone to get it sorted.

We are going to release alternate methods of update too.

Any one who can upgrade their servers please do, anyone who can’t can reach out to us by directly emailing to [email protected] with root ssh access.

Method to upgrade: How to Upgrade CyberPanel? A Comprehensive Guide in 2024

Please be patient and let us help you.
Really appreciate your co-operation.
thank you

2 Likes

Hello

Thank You for your response, I respect it.

I have just updated cyberpanel 2 days ago.

Do you know the way or have the way to restore the services if ssh is not working.

Thank You.

@Ariyan Create a shell script and run it on your cron job every minute.

This will reduce the load on your CPU. After that, just restart the services that are down. If your ssh doesn’t open, try changing the ssh port through the panel. It will start working again.

This is a temporary solution… it is recommended that you restore the backup on a server with a clean installation… see the shell script below.

I found this script and it helped me.

sh <(curl https://raw.githubusercontent.com/managingwp/kinsing-cleanup/refs/heads/main/kinsing-cleanup.sh)

The hosing github account

@BradWFresno yes, This will give more time to get the services operational, but the correct thing to do is to restore the services in a clean installation.

We also do not know if this problem has been resolved in the latest version of Cyberpanel.

Hello

Thank You for your help. But the issue is - The hacker or something removed the SSH Key and also changed the root password. Then removed the qemu-guest, So reset password via gui is not possible.

I am kinda stuck, no access to server. Server is from Hetzner. Asked them and still waiting for their response.

Also port 80, 443, 8090, 7080 seems closed!

Thank You

It doesn’t actually change your root password, it kills the SSH process, and other services may not be working due to high server load.

You can enter recovery mode, change your root password, create the shell script, put it in cron, restart the server and it will work.