Known Exploited Vulnerability
9.8
CRITICAL CVSS 3.1
CVE-2026-41940
WebPros cPanel & WHM and WP2 (WordPress Squared) Missing Authentication for Critical Function Vulnerability - [Actively Exploited]
Description

cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.

INFO

Published Date :

April 29, 2026, 4:16 p.m.

Last Modified :

June 17, 2026, 10:47 a.m.

Remotely Exploit :

Yes !
CISA Notification
CISA KEV (Known Exploited Vulnerabilities)

For the benefit of the cybersecurity community and network defenders—and to help every organization better manage vulnerabilities and keep pace with threat activity—CISA maintains the authoritative source of vulnerabilities that have been exploited in the wild.

Description :

WebPros cPanel & WHM (WebHost Manager) and WP2 (WordPress Squared) contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.

Required Action :

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Known Ransomware Campaign Use:

Known Detected May 06, 2026

Notes :

https://support.cpanel.net/hc/en-us/articles/40073787579671-cPanel-WHM-Security-Update-04-28-2026 ; https://docs.cpanel.net/release-notes/release-notes/ ; https://docs.wpsquared.com/changelogs/versions/changelog/#13617 ; https://nvd.nist.gov/vuln/detail/CVE-2026-41940"

Affected Products

The following products are affected by CVE-2026-41940 vulnerability. Even if cvefeed.io is aware of the exact versions of the products that are affected, the information is not represented in the table below.

ID Vendor Product Action
1 Cpanel cpanel
2 Cpanel whm
3 Cpanel wp_squared
CVSS Scores
The Common Vulnerability Scoring System is a standardized framework for assessing the severity of vulnerabilities in software and systems. We collect and displays CVSS scores from various sources for each CVE.
Score Version Severity Vector Exploitability Score Impact Score Source
CVSS 134c704f-9b21-4f2e-91b3-4a467353bcc0
CVSS 3.1 CRITICAL 83251b91-4cc7-4094-a5c7-464a1b83ea10
CVSS 3.1 CRITICAL [email protected]
CVSS 3.1 CRITICAL MITRE-CVE
CVSS 4.0 CRITICAL 83251b91-4cc7-4094-a5c7-464a1b83ea10
CVSS 4.0 CRITICAL [email protected]
Solution
Update cPanel and WHM to a patched version to fix authentication bypass.
  • Update cPanel and WHM to a patched version.
  • Verify successful update.
Public PoC/Exploit Available at Github

CVE-2026-41940 has a 138 public PoC/Exploit available at Github. Go to the Public Exploits tab to see the list.

CWE - Common Weakness Enumeration

While CVE identifies specific instances of vulnerabilities, CWE categorizes the common flaws or weaknesses that can lead to vulnerabilities. CVE-2026-41940 is associated with the following CWEs:

Common Attack Pattern Enumeration and Classification (CAPEC)

We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).

pemisah versi cpanel untuk yang vuln

Python

Updated: 2 weeks, 3 days ago
1 stars 0 fork 0 watcher
Born at : July 22, 2026, 4:29 a.m. This repo has been linked 1 different CVEs too.

CVE-2026-6875 ServiceNow Pre-Auth RCE Framework 🔥 JS Injection → Sandbox Escape → RCE → Root. Features: --detect, --exec, reverse/interactive shell, batch threading, WAF bypass, persistence, lateral movement, credential dump, fileless exec, clean tracks. 🛡️ CVSS 9.5 actively exploited. Authorized & Legal use only. Stay Legal. 🔒

Python

Updated: 2 weeks, 3 days ago
0 stars 0 fork 0 watcher
Born at : July 21, 2026, 6:07 p.m. This repo has been linked 5 different CVEs too.

A cPanel and WHM authentication bypassing tool

aunthentication cpanel cve-2026-41940 proof-of-concept python

Python

Updated: 2 weeks, 4 days ago
1 stars 0 fork 0 watcher
Born at : July 20, 2026, 2:15 p.m. This repo has been linked 1 different CVEs too.

AI-native security research platform — 46 MCP tools connecting Claude to real offensive security tooling

active-directory claude-ai cybersecurity docker mcp penetration-testing post-quantum-cryptography python

Dockerfile Python Shell

Updated: 3 weeks ago
1 stars 0 fork 0 watcher
Born at : July 18, 2026, 7:12 a.m. This repo has been linked 2 different CVEs too.

Technical analysis of the cPanel/WHM auth bypass

Updated: 3 weeks ago
0 stars 0 fork 0 watcher
Born at : July 18, 2026, 5:44 a.m. This repo has been linked 1 different CVEs too.

【赛博57库】 公众号欢迎大家关注

Python HTML JavaScript

Updated: 3 weeks, 5 days ago
2 stars 0 fork 0 watcher
Born at : July 13, 2026, 8:57 a.m. This repo has been linked 11 different CVEs too.

Live CVE PoC (Proof-of-Concepts) Aggregator with Smart Search & Threat Intelligence

Python HTML

Updated: 2 weeks, 5 days ago
1 stars 0 fork 0 watcher
Born at : July 6, 2026, 8:57 p.m. This repo has been linked 78 different CVEs too.

주요 CVE 분석

Updated: 2 weeks, 5 days ago
0 stars 0 fork 0 watcher
Born at : July 3, 2026, 5:27 a.m. This repo has been linked 154 different CVEs too.

CVE-2026-41940 authentication bypass vulnerability proof-of-concept

cpanel cve cve-2026-41940 cve-2026-41940-poc

Python

Updated: 3 weeks, 3 days ago
192 stars 14 fork 14 watcher
Born at : June 28, 2026, 7:13 a.m. This repo has been linked 1 different CVEs too.

CVE-2026-41940 exploitation proof-of-concept project

cpanel cve cve-2026-41940 cve-2026-41940-poc

Python

Updated: 1 month, 2 weeks ago
62 stars 8 fork 8 watcher
Born at : June 16, 2026, 5:49 p.m. This repo has been linked 1 different CVEs too.

Ping7 defensive CVE tools, GitHub pages, and repair guides

cve incident-response ping7 security-tools vulnerability-management

Updated: 1 month, 3 weeks ago
0 stars 0 fork 0 watcher
Born at : June 16, 2026, 10:47 a.m. This repo has been linked 3 different CVEs too.

Senior Structural Engineer (14Y+ exp) & Tech Founder. Bridging engineering precision with AI automation. Building vertical calculation web tools and crafting custom Python/AI workflows. Advanced Obsidian PKM builder. Optimized Windows LTSC user. Driven by logic, automated by code.

Updated: 1 month ago
1 stars 0 fork 0 watcher
Born at : June 16, 2026, 8:28 a.m. This repo has been linked 1 different CVEs too.

None

Updated: 1 month, 3 weeks ago
0 stars 0 fork 0 watcher
Born at : June 12, 2026, 4:59 p.m. This repo has been linked 1 different CVEs too.

Security research portfolio and responsible disclosure profile

Updated: 2 months ago
0 stars 0 fork 0 watcher
Born at : June 6, 2026, 1:24 p.m. This repo has been linked 2 different CVEs too.

Redacted cPanel/WHM authentication bypass analysis and authorized checker

Updated: 2 months ago
0 stars 0 fork 0 watcher
Born at : June 6, 2026, 12:49 p.m. This repo has been linked 1 different CVEs too.

Results are limited to the first 15 repositories due to potential performance issues.

The following list is the news that have been mention CVE-2026-41940 vulnerability anywhere in the article.

  • The Cyber Express
Critical wp2shell Vulnerability Hits WordPress Core, Patch Released

WordPress has released security updates to address the wp2shell vulnerability, a critical flaw that allowed attackers to achieve remote code execution (RCE) on vulnerable sites using a single anonymou ... Read more

Published Date: Jul 30, 2026 (1 week, 2 days ago)
  • The Hacker News
Attackers Weaponize GitHub Actions Runners to Target cPanel and WHM Servers

Cybersecurity researchers have shed light on a large-scale campaign that has turned compromised GitHub repositories into distributed attack infrastructure designed to target cPanel and WebHost Manager ... Read more

Published Date: Jul 23, 2026 (2 weeks, 2 days ago)
  • The Cyber Express
ServiceNow Flaw Exploited by Threat Actors to Access Customer Instances

A recently disclosed ServiceNow flaw has come under scrutiny after the company confirmed that unknown threat actors exploited the vulnerability to gain unauthorized access to a number of customer inst ... Read more

Published Date: Jun 11, 2026 (1 month, 4 weeks ago)
  • Proofpoint
More CVEs, Same Playbook: 2026 Vulnerability Exploitation in the Wild

Executive Summary The CVE Landscape Has Changed. The Threat Actors Haven't. Proofpoint's dual telemetry streams — targeted attack visibility covering hundreds of millions of messages daily, and a glob ... Read more

Published Date: May 27, 2026 (2 months, 1 week ago)
  • The Hacker News
Claude Mythos AI Finds 10,000 High-Severity Flaws in Widely Used Software

Anthropic on Friday disclosed that Project Glasswing has helped uncover more than 10,000 high- or critical-severity vulnerabilities across some of the most "systemically" important software across the ... Read more

Published Date: May 23, 2026 (2 months, 2 weeks ago)
  • The Hacker News
LiteSpeed cPanel Plugin CVE-2026-48172 Exploited to Run Scripts as Root

A maximum-severity security vulnerability impacting LiteSpeed User-End cPanel Plugin has come under active exploitation in the wild. The flaw, tracked as CVE-2026-48172 (CVSS score: 10.0), relates to ... Read more

Published Date: May 23, 2026 (2 months, 2 weeks ago)
  • The Hacker News
Drupal Core SQL Injection Bug Actively Exploited, Added to CISA KEV

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a recently patched critical security flaw impacting Drupal Core to its Known Exploited Vulnerabilities (KEV) catalog, based o ... Read more

Published Date: May 23, 2026 (2 months, 2 weeks ago)
  • The Hacker News
CISA Adds Exploited Langflow and Trend Micro Apex One Vulnerabilities to KEV

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added two security flaws impacting Langflow and Trend Micro Apex One to its Known Exploited Vulnerabilities (KEV) catalog, ... Read more

Published Date: May 22, 2026 (2 months, 2 weeks ago)
  • The Hacker News
Cisco Patches CVSS 10.0 Secure Workload REST API Flaw Enabling Data Access

Cisco has rolled out updates for a maximum-severity security flaw impacting Secure Workload that could allow an unauthenticated, remote attacker to access sensitive data. Tracked as CVE-2026-20223 (CV ... Read more

Published Date: May 22, 2026 (2 months, 2 weeks ago)
  • The Hacker News
Microsoft Warns of Two Actively Exploited Defender Vulnerabilities

Microsoft has disclosed that a privilege escalation and a denial-of-service flaw in Defender has come under active exploitation in the wild. The former, tracked as CVE-2026-41091, is rated 7.8 on the ... Read more

Published Date: May 21, 2026 (2 months, 2 weeks ago)
  • The Hacker News
9-Year-Old Linux Kernel Flaw Enables Root Command Execution on Major Distros

Cybersecurity researchers have disclosed details of a vulnerability in the Linux kernel that remained undetected for nine years. The vulnerability, tracked as CVE-2026-46333 (CVSS score: 5.5), is a ca ... Read more

Published Date: May 21, 2026 (2 months, 2 weeks ago)
  • The Hacker News
Highly Critical Drupal Core Flaw Exposes PostgreSQL Sites to RCE Attacks

Drupal has released security updates for a "highly critical" security vulnerability in Drupal Core that could be exploited by attackers to achieve remote code execution, privilege escalation, or infor ... Read more

Published Date: May 21, 2026 (2 months, 2 weeks ago)
  • The Hacker News
Microsoft Releases Mitigation for YellowKey BitLocker Bypass CVE-2026-45585 Exploit

Microsoft on Tuesday released a mitigation for a BitLocker bypass vulnerability named YellowKey following its public disclosure last week. The zero-day flaw, now tracked as CVE-2026-45585, carries a C ... Read more

Published Date: May 20, 2026 (2 months, 2 weeks ago)
  • The Hacker News
SEPPMail Secure E-Mail Gateway Vulnerabilities Enable RCE and Mail Traffic Access

Critical security vulnerabilities have been disclosed in SEPPMail Secure E-Mail Gateway, an enterprise-grade email security solution, that could be exploited to achieve remote code execution and enabl ... Read more

Published Date: May 19, 2026 (2 months, 2 weeks ago)
  • The Hacker News
MiniPlasma Windows 0-Day Enables SYSTEM Privilege Escalation on Fully Patched Systems

Chaotic Eclipse, the security researcher behind the recently disclosed Windows flaws, YellowKey and GreenPlasma, has released a proof-of-concept (PoC) for a Windows privilege escalation zero-day flaw ... Read more

Published Date: May 18, 2026 (2 months, 3 weeks ago)
  • The Hacker News
NGINX CVE-2026-42945 Exploited in the Wild, Causing Worker Crashes and Possible RCE

A newly disclosed security flaw impacting NGINX Plus and NGINX Open has come under active exploitation in the wild, days after its public disclosure, according to VulnCheck. The vulnerability, tracked ... Read more

Published Date: May 17, 2026 (2 months, 3 weeks ago)
  • Daily CyberSecurity
CVSS 10 Alert: Quest KACE SMA Auth Bypass Exploited to Hijack Managed Endpoints

Detailed listing of tools and scripts within the exposed C2 directory | Image: Hunt Cybersecurity researchers have just dropped a report on a critical “management plane” threat that has spent the last ... Read more

Published Date: May 16, 2026 (2 months, 3 weeks ago)
  • CybersecurityNews
79 Chrome Vulnerabilities Patched, Including 14 Critical One’s – Update Now!

Google has rolled out a massive security update for its Chrome browser, sealing a staggering 79 vulnerabilities before threat actors can exploit them. With 14 of these flaws rated as critical, browsin ... Read more

Published Date: May 15, 2026 (2 months, 3 weeks ago)
  • The Cyber Express
Microsoft May 2026 Patch Tuesday Fixes 120 Vulnerabilities, No Zero-Day Exploits Reported

Microsoft has rolled out its May 2026 Patch Tuesday security updates, delivering fixes for approximately 120 vulnerabilities across Windows, Microsoft Office, networking services, and enterprise platf ... Read more

Published Date: May 13, 2026 (2 months, 3 weeks ago)
  • CybersecurityNews
PoC Exploit Released for Android Zero-Click Vulnerability that Enables Remote Shell Access

In a chilling blow to mobile security, Google’s May 2026 Android Security Bulletin has unmasked a catastrophic zero-click vulnerability lurking within the core Android System. The CVE-2026-0073 flaw i ... Read more

Published Date: May 12, 2026 (2 months, 3 weeks ago)

The following table lists the changes that have been made to the CVE-2026-41940 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability's severity, exploitability, or other characteristics.

  • CVE Modified by 134c704f-9b21-4f2e-91b3-4a467353bcc0

    Jun. 17, 2026

    Action Type Old Value New Value
    Added SSVC {'id': 'CVE-2026-41940', 'role': 'CISA Coordinator', 'options': [{'exploitation': 'active'}, {'automatable': 'yes'}, {'technicalImpact': 'total'}], 'version': '2.0.3', 'timestamp': '2026-04-29T00:00:00+00:00'}
  • CVE Modified by [email protected]

    Jun. 17, 2026

    Action Type Old Value New Value
    Added Affected [{'vendor': 'WebPros', 'product': 'cPanel', 'versions': [{'status': 'affected', 'version': '11.40.0.0', 'lessThan': '11.86.0.41', 'versionType': 'custom'}, {'status': 'affected', 'version': '11.88.0.0', 'lessThan': '11.94.0.28', 'versionType': 'custom'}, {'status': 'affected', 'version': '11.96.0.0', 'lessThan': '11.102.0.39', 'versionType': 'custom'}, {'status': 'affected', 'version': '11.104.0.0', 'lessThan': '11.110.0.97', 'versionType': 'custom'}, {'status': 'affected', 'version': '11.112.0.0', 'lessThan': '11.118.0.63', 'versionType': 'custom'}, {'status': 'affected', 'version': '11.120.0.0', 'lessThan': '11.124.0.35', 'versionType': 'custom'}, {'status': 'affected', 'version': '11.126.0.0', 'lessThan': '11.126.0.54', 'versionType': 'custom'}, {'status': 'affected', 'version': '11.128.0.0', 'lessThan': '11.130.0.19', 'versionType': 'custom'}, {'status': 'affected', 'version': '11.132.0.0', 'lessThan': '11.132.0.29', 'versionType': 'custom'}, {'status': 'affected', 'version': '11.134.0.0', 'lessThan': '11.134.0.20', 'versionType': 'custom'}, {'status': 'affected', 'version': '11.136.0.0', 'lessThan': '11.136.0.5', 'versionType': 'custom'}], 'defaultStatus': 'affected'}, {'vendor': 'WebPros', 'product': 'WP Squared', 'versions': [{'status': 'unaffected', 'version': '11.136.1.7', 'versionType': 'custom'}], 'defaultStatus': 'affected'}, {'vendor': 'WebPros', 'product': 'WHM', 'versions': [{'status': 'affected', 'version': '11.40.0.0', 'lessThan': '11.86.0.41', 'versionType': 'custom'}, {'status': 'affected', 'version': '11.88.0.0', 'lessThan': '11.94.0.28', 'versionType': 'custom'}, {'status': 'affected', 'version': '11.96.0.0', 'lessThan': '11.102.0.39', 'versionType': 'custom'}, {'status': 'affected', 'version': '11.104.0.0', 'lessThan': '11.110.0.97', 'versionType': 'custom'}, {'status': 'affected', 'version': '11.112.0.0', 'lessThan': '11.118.0.63', 'versionType': 'custom'}, {'status': 'affected', 'version': '11.120.0.0', 'lessThan': '11.124.0.35', 'versionType': 'custom'}, {'status': 'affected', 'version': '11.126.0.0', 'lessThan': '11.126.0.54', 'versionType': 'custom'}, {'status': 'affected', 'version': '11.128.0.0', 'lessThan': '11.130.0.19', 'versionType': 'custom'}, {'status': 'affected', 'version': '11.132.0.0', 'lessThan': '11.132.0.29', 'versionType': 'custom'}, {'status': 'affected', 'version': '11.134.0.0', 'lessThan': '11.134.0.20', 'versionType': 'custom'}, {'status': 'affected', 'version': '11.136.0.0', 'lessThan': '11.136.0.5', 'versionType': 'custom'}], 'defaultStatus': 'affected'}]
  • Modified Analysis by [email protected]

    May. 04, 2026

    Action Type Old Value New Value
    Changed CPE Configuration OR *cpe:2.3:a:cpanel:cpanel:*:*:*:*:*:*:*:* versions from (including) 11.40 up to (excluding) 86.0.41 *cpe:2.3:a:cpanel:cpanel:*:*:*:*:*:*:*:* versions from (including) 88.0.0 up to (excluding) 110.0.97 *cpe:2.3:a:cpanel:cpanel:*:*:*:*:*:*:*:* versions from (including) 112.0.0 up to (excluding) 118.0.63 *cpe:2.3:a:cpanel:cpanel:*:*:*:*:*:*:*:* versions from (including) 120.0.0 up to (excluding) 126.0.54 *cpe:2.3:a:cpanel:cpanel:*:*:*:*:*:*:*:* versions from (including) 128.0.0 up to (excluding) 130.0.19 *cpe:2.3:a:cpanel:cpanel:*:*:*:*:*:*:*:* versions from (including) 132.0.0 up to (excluding) 132.0.29 *cpe:2.3:a:cpanel:cpanel:*:*:*:*:*:*:*:* versions from (including) 134.0.0 up to (excluding) 134.0.20 *cpe:2.3:a:cpanel:cpanel:*:*:*:*:*:*:*:* versions from (including) 136.0.0 up to (excluding) 136.0.5 OR *cpe:2.3:a:cpanel:cpanel:*:*:*:*:*:*:*:* versions from (including) 11.40 up to (excluding) 86.0.41 *cpe:2.3:a:cpanel:cpanel:*:*:*:*:*:*:*:* versions from (including) 88.0.0 up to (excluding) 110.0.97 *cpe:2.3:a:cpanel:cpanel:*:*:*:*:*:*:*:* versions from (including) 112.0.0 up to (excluding) 118.0.63 *cpe:2.3:a:cpanel:cpanel:*:*:*:*:*:*:*:* versions from (including) 128.0.0 up to (excluding) 130.0.19 *cpe:2.3:a:cpanel:cpanel:*:*:*:*:*:*:*:* versions from (including) 132.0.0 up to (excluding) 132.0.29 *cpe:2.3:a:cpanel:cpanel:*:*:*:*:*:*:*:* versions from (including) 134.0.0 up to (excluding) 134.0.20 *cpe:2.3:a:cpanel:cpanel:*:*:*:*:*:*:*:* versions from (including) 136.0.0 up to (excluding) 136.0.5 *cpe:2.3:a:cpanel:cpanel:*:*:*:*:*:*:*:* versions from (including) 120.0.0 up to (excluding) 124.0.35 *cpe:2.3:a:cpanel:cpanel:*:*:*:*:*:*:*:* versions from (including) 126.0.1 up to (excluding) 126.0.54
    Changed CPE Configuration OR *cpe:2.3:a:cpanel:whm:*:*:*:*:*:*:*:* versions from (including) 11.40 up to (excluding) 86.0.41 *cpe:2.3:a:cpanel:whm:*:*:*:*:*:*:*:* versions from (including) 112.0.0 up to (excluding) 118.0.63 *cpe:2.3:a:cpanel:whm:*:*:*:*:*:*:*:* versions from (including) 120.0.0 up to (excluding) 126.0.54 *cpe:2.3:a:cpanel:whm:*:*:*:*:*:*:*:* versions from (including) 128.0.0 up to (excluding) 130.0.19 *cpe:2.3:a:cpanel:whm:*:*:*:*:*:*:*:* versions from (including) 132.0.0 up to (excluding) 132.0.29 *cpe:2.3:a:cpanel:whm:*:*:*:*:*:*:*:* versions from (including) 134.0.0 up to (excluding) 134.0.20 *cpe:2.3:a:cpanel:whm:*:*:*:*:*:*:*:* versions from (including) 136.0.0 up to (excluding) 136.0.5 *cpe:2.3:a:cpanel:whm:*:*:*:*:*:*:*:* versions from (including) 88.0.0 up to (excluding) 110.0.97 OR *cpe:2.3:a:cpanel:whm:*:*:*:*:*:*:*:* versions from (including) 11.40 up to (excluding) 86.0.41 *cpe:2.3:a:cpanel:whm:*:*:*:*:*:*:*:* versions from (including) 112.0.0 up to (excluding) 118.0.63 *cpe:2.3:a:cpanel:whm:*:*:*:*:*:*:*:* versions from (including) 128.0.0 up to (excluding) 130.0.19 *cpe:2.3:a:cpanel:whm:*:*:*:*:*:*:*:* versions from (including) 132.0.0 up to (excluding) 132.0.29 *cpe:2.3:a:cpanel:whm:*:*:*:*:*:*:*:* versions from (including) 134.0.0 up to (excluding) 134.0.20 *cpe:2.3:a:cpanel:whm:*:*:*:*:*:*:*:* versions from (including) 136.0.0 up to (excluding) 136.0.5 *cpe:2.3:a:cpanel:whm:*:*:*:*:*:*:*:* versions from (including) 88.0.0 up to (excluding) 110.0.97 *cpe:2.3:a:cpanel:whm:*:*:*:*:*:*:*:* versions from (including) 120.0.0 up to (excluding) 124.0.35 *cpe:2.3:a:cpanel:whm:*:*:*:*:*:*:*:* versions from (including) 126.0.1 up to (excluding) 126.0.54
    Added Reference Type CVE: https://labs.watchtowr.com/the-internet-is-falling-down-falling-down-falling-down-cpanel-whm-authentication-bypass-cve-2026-41940/ Types: Exploit, Third Party Advisory
    Added Reference Type CVE: https://www.bleepingcomputer.com/news/security/critrical-cpanel-flaw-mass-exploited-in-sorry-ransomware-attacks/ Types: Press/Media Coverage
  • CVE Modified by af854a3a-2127-422b-91ae-364da2661108

    May. 04, 2026

    Action Type Old Value New Value
    Added Reference https://labs.watchtowr.com/the-internet-is-falling-down-falling-down-falling-down-cpanel-whm-authentication-bypass-cve-2026-41940/
    Added Reference https://www.bleepingcomputer.com/news/security/critrical-cpanel-flaw-mass-exploited-in-sorry-ransomware-attacks/
  • Initial Analysis by [email protected]

    Apr. 30, 2026

    Action Type Old Value New Value
    Added CPE Configuration OR *cpe:2.3:a:cpanel:cpanel:*:*:*:*:*:*:*:* versions from (including) 11.40 up to (excluding) 86.0.41 *cpe:2.3:a:cpanel:cpanel:*:*:*:*:*:*:*:* versions from (including) 88.0.0 up to (excluding) 110.0.97 *cpe:2.3:a:cpanel:cpanel:*:*:*:*:*:*:*:* versions from (including) 112.0.0 up to (excluding) 118.0.63 *cpe:2.3:a:cpanel:cpanel:*:*:*:*:*:*:*:* versions from (including) 120.0.0 up to (excluding) 126.0.54 *cpe:2.3:a:cpanel:cpanel:*:*:*:*:*:*:*:* versions from (including) 128.0.0 up to (excluding) 130.0.19 *cpe:2.3:a:cpanel:cpanel:*:*:*:*:*:*:*:* versions from (including) 132.0.0 up to (excluding) 132.0.29 *cpe:2.3:a:cpanel:cpanel:*:*:*:*:*:*:*:* versions from (including) 134.0.0 up to (excluding) 134.0.20 *cpe:2.3:a:cpanel:cpanel:*:*:*:*:*:*:*:* versions from (including) 136.0.0 up to (excluding) 136.0.5
    Added CPE Configuration OR *cpe:2.3:a:cpanel:whm:*:*:*:*:*:*:*:* versions from (including) 11.40 up to (excluding) 86.0.41 *cpe:2.3:a:cpanel:whm:*:*:*:*:*:*:*:* versions from (including) 112.0.0 up to (excluding) 118.0.63 *cpe:2.3:a:cpanel:whm:*:*:*:*:*:*:*:* versions from (including) 120.0.0 up to (excluding) 126.0.54 *cpe:2.3:a:cpanel:whm:*:*:*:*:*:*:*:* versions from (including) 128.0.0 up to (excluding) 130.0.19 *cpe:2.3:a:cpanel:whm:*:*:*:*:*:*:*:* versions from (including) 132.0.0 up to (excluding) 132.0.29 *cpe:2.3:a:cpanel:whm:*:*:*:*:*:*:*:* versions from (including) 134.0.0 up to (excluding) 134.0.20 *cpe:2.3:a:cpanel:whm:*:*:*:*:*:*:*:* versions from (including) 136.0.0 up to (excluding) 136.0.5 *cpe:2.3:a:cpanel:whm:*:*:*:*:*:*:*:* versions from (including) 88.0.0 up to (excluding) 110.0.97
    Added CPE Configuration OR *cpe:2.3:a:cpanel:wp_squared:*:*:*:*:*:wordpress:*:* versions up to (excluding) 136.1.7
    Added Reference Type VulnCheck: https://docs.cpanel.net/release-notes/release-notes Types: Release Notes
    Added Reference Type VulnCheck: https://docs.wpsquared.com/changelogs/versions/changelog/#13617 Types: Release Notes
    Added Reference Type CISA-ADP: https://github.com/watchtowrlabs/watchTowr-vs-cPanel-WHM-AuthBypass-to-RCE.py Types: Exploit, Third Party Advisory
    Added Reference Type VulnCheck: https://support.cpanel.net/hc/en-us/articles/40073787579671-cPanel-WHM-Security-Update-04-28-2026 Types: Vendor Advisory
    Added Reference Type CISA-ADP: https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-41940 Types: US Government Resource
    Added Reference Type VulnCheck: https://www.namecheap.com/status-updates/ongoing-critical-security-vulnerability-in-cpanel-april-28-2026 Types: Third Party Advisory
    Added Reference Type VulnCheck: https://www.vulncheck.com/advisories/cpanel-and-whm-authentication-bypass-via-login-flow Types: Third Party Advisory
  • CVE Modified by 134c704f-9b21-4f2e-91b3-4a467353bcc0

    Apr. 30, 2026

    Action Type Old Value New Value
    Added Reference https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-41940
  • CVE Modified by [email protected]

    Apr. 30, 2026

    Action Type Old Value New Value
    Changed Description cPanel and WHM versions prior to 11.110.0.97, 11.118.0.63, 11.126.0.54, 11.132.0.29, 11.134.0.20, and 11.136.0.5 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel. cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.
  • CVE Modified by 134c704f-9b21-4f2e-91b3-4a467353bcc0

    Apr. 29, 2026

    Action Type Old Value New Value
    Added Reference https://github.com/watchtowrlabs/watchTowr-vs-cPanel-WHM-AuthBypass-to-RCE.py
  • New CVE Received by [email protected]

    Apr. 29, 2026

    Action Type Old Value New Value
    Added Description cPanel and WHM versions prior to 11.110.0.97, 11.118.0.63, 11.126.0.54, 11.132.0.29, 11.134.0.20, and 11.136.0.5 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.
    Added CVSS V4.0 AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
    Added CVSS V3.1 AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
    Added CWE CWE-306
    Added Reference https://docs.cpanel.net/release-notes/release-notes
    Added Reference https://docs.wpsquared.com/changelogs/versions/changelog/#13617
    Added Reference https://support.cpanel.net/hc/en-us/articles/40073787579671-cPanel-WHM-Security-Update-04-28-2026
    Added Reference https://www.namecheap.com/status-updates/ongoing-critical-security-vulnerability-in-cpanel-april-28-2026
    Added Reference https://www.vulncheck.com/advisories/cpanel-and-whm-authentication-bypass-via-login-flow
EPSS is a daily estimate of the probability of exploitation activity being observed over the next 30 days. Following chart shows the EPSS score history of the vulnerability.