Known Exploited Vulnerability
9.8
CRITICAL CVSS 3.1
CVE-2026-41940
WebPros cPanel & WHM and WP2 (WordPress Squared) Missing Authentication for Critical Function Vulnerability - [Actively Exploited]
Description

cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.

INFO

Published Date :

April 29, 2026, 4:16 p.m.

Last Modified :

May 4, 2026, 6:09 p.m.

Remotely Exploit :

Yes !
CISA Notification
CISA KEV (Known Exploited Vulnerabilities)

For the benefit of the cybersecurity community and network defenders—and to help every organization better manage vulnerabilities and keep pace with threat activity—CISA maintains the authoritative source of vulnerabilities that have been exploited in the wild.

Description :

WebPros cPanel & WHM (WebHost Manager) and WP2 (WordPress Squared) contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.

Required Action :

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Known Ransomware Campaign Use:

Known Detected May 06, 2026

Notes :

https://support.cpanel.net/hc/en-us/articles/40073787579671-cPanel-WHM-Security-Update-04-28-2026 ; https://docs.cpanel.net/release-notes/release-notes/ ; https://docs.wpsquared.com/changelogs/versions/changelog/#13617 ; https://nvd.nist.gov/vuln/detail/CVE-2026-41940"

Affected Products

The following products are affected by CVE-2026-41940 vulnerability. Even if cvefeed.io is aware of the exact versions of the products that are affected, the information is not represented in the table below.

ID Vendor Product Action
1 Cpanel cpanel
2 Cpanel whm
3 Cpanel wp_squared
CVSS Scores
The Common Vulnerability Scoring System is a standardized framework for assessing the severity of vulnerabilities in software and systems. We collect and displays CVSS scores from various sources for each CVE.
Score Version Severity Vector Exploitability Score Impact Score Source
CVSS 3.1 CRITICAL 83251b91-4cc7-4094-a5c7-464a1b83ea10
CVSS 3.1 CRITICAL [email protected]
CVSS 3.1 CRITICAL MITRE-CVE
CVSS 4.0 CRITICAL 83251b91-4cc7-4094-a5c7-464a1b83ea10
CVSS 4.0 CRITICAL [email protected]
Solution
Update cPanel and WHM to a patched version to fix authentication bypass.
  • Update cPanel and WHM to a patched version.
  • Verify successful update.
Public PoC/Exploit Available at Github

CVE-2026-41940 has a 98 public PoC/Exploit available at Github. Go to the Public Exploits tab to see the list.

CWE - Common Weakness Enumeration

While CVE identifies specific instances of vulnerabilities, CWE categorizes the common flaws or weaknesses that can lead to vulnerabilities. CVE-2026-41940 is associated with the following CWEs:

Common Attack Pattern Enumeration and Classification (CAPEC)

We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).

Coleção de skills de segurança ofensiva para Claude Code metodologia PTES completa com AWS/IAM (WorstAssume), pfSense (27+ CVEs), Active Directory, Web Attacks, Palo Alto PAN-OS, AI Agent Audit e LLM Security Testing. Integra AIRecon, Watchtower e hexstrike-local MCP

Updated: 19 hours, 52 minutes ago
1 stars 0 fork 0 watcher
Born at : May 18, 2026, 7:21 p.m. This repo has been linked 4 different CVEs too.

All-in-one WAF bypass & recon toolkit for bug bounty research. 21 modules: CORS, JWT, GraphQL, SSRF, JS secrets, WordPress, Nuclei fingerprint & more. No API keys required.

Python

Updated: 2 days, 11 hours ago
0 stars 0 fork 0 watcher
Born at : May 17, 2026, 4:30 a.m. This repo has been linked 3 different CVEs too.

None

Shell

Updated: 3 days, 7 hours ago
0 stars 0 fork 0 watcher
Born at : May 16, 2026, 12:12 p.m. This repo has been linked 1 different CVEs too.

Variant of Web Shell by oRb captured in the wild

PHP

Updated: 4 days ago
0 stars 0 fork 0 watcher
Born at : May 15, 2026, 4:03 p.m. This repo has been linked 1 different CVEs too.

None

Python

Updated: 3 days, 18 hours ago
0 stars 0 fork 0 watcher
Born at : May 15, 2026, 1:49 p.m. This repo has been linked 1 different CVEs too.

DonScan — Intelligent Vulnerability Discovery Platform | Built by Cysec Don

Shell Python Dockerfile Makefile JavaScript TypeScript TeX HTML CSS

Updated: 6 days, 4 hours ago
0 stars 0 fork 0 watcher
Born at : May 13, 2026, 8:54 a.m. This repo has been linked 3 different CVEs too.

None

Python

Updated: 1 week, 1 day ago
0 stars 0 fork 0 watcher
Born at : May 11, 2026, 3 p.m. This repo has been linked 1 different CVEs too.

CVE-2026-41940 — cPanel/WHM Auth Bypass By Dr.Anach, CRLF injection in `cpsrvd` Basic auth handler → unauthenticated WHM API access → RCE as root. All cPanel since v11.40 affected.

Python

Updated: 1 week, 1 day ago
0 stars 0 fork 0 watcher
Born at : May 11, 2026, 7:01 a.m. This repo has been linked 1 different CVEs too.

Форензика после CVE-2026-41940 (cPanel/WHM) — bash-скрипт и чек-лист

Shell

Updated: 1 week, 2 days ago
0 stars 0 fork 0 watcher
Born at : May 10, 2026, 4:31 p.m. This repo has been linked 1 different CVEs too.

cPanelSniper STABLE - CVE-2026-41940 optimized for 10M+ targets

Python Shell

Updated: 1 week, 2 days ago
0 stars 0 fork 0 watcher
Born at : May 10, 2026, 12:35 p.m. This repo has been linked 1 different CVEs too.

Defensive exposure assessment tool for identifying externally accessible cPanel, WHM, and Webmail management interfaces related to CVE-2026-41940.

Python

Updated: 1 week, 3 days ago
0 stars 0 fork 0 watcher
Born at : May 9, 2026, 3:21 p.m. This repo has been linked 1 different CVEs too.

Project Ghost Engine** is an advanced, automated OSINT (Open Source Intelligence) and reconnaissance tool designed for security researchers, bug bounty hunters, and penetration testers. It aggregates data from various passive sources and generates a highly interactive, standalone HTML dashboard tailored to a specific target domain.

Python

Updated: 2 days, 5 hours ago
1 stars 0 fork 0 watcher
Born at : May 9, 2026, 3:22 a.m. This repo has been linked 1 different CVEs too.

A Rust honeypot that simulates a vulnerable cPanel/WHM instance for CVE-2026-41940

Dockerfile Rust

Updated: 1 week, 3 days ago
0 stars 0 fork 0 watcher
Born at : May 8, 2026, 7:37 p.m. This repo has been linked 1 different CVEs too.

None

Shell

Updated: 1 week, 4 days ago
0 stars 0 fork 0 watcher
Born at : May 8, 2026, 2:05 p.m. This repo has been linked 1 different CVEs too.

cve-2026-41940 cPanel/WHM Authentication Bypass - Detection Artifact Generator

Python

Updated: 1 week, 5 days ago
0 stars 0 fork 0 watcher
Born at : May 7, 2026, 4:17 p.m. This repo has been linked 1 different CVEs too.

Results are limited to the first 15 repositories due to potential performance issues.

The following list is the news that have been mention CVE-2026-41940 vulnerability anywhere in the article.

  • The Hacker News
SEPPMail Secure E-Mail Gateway Vulnerabilities Enable RCE and Mail Traffic Access

Critical security vulnerabilities have been disclosed in SEPPMail Secure E-Mail Gateway, an enterprise-grade email security solution, that could be exploited to achieve remote code execution and enabl ... Read more

Published Date: May 19, 2026 (10 hours, 35 minutes ago)
  • The Hacker News
MiniPlasma Windows 0-Day Enables SYSTEM Privilege Escalation on Fully Patched Systems

Chaotic Eclipse, the security researcher behind the recently disclosed Windows flaws, YellowKey and GreenPlasma, has released a proof-of-concept (PoC) for a Windows privilege escalation zero-day flaw ... Read more

Published Date: May 18, 2026 (1 day, 14 hours ago)
  • The Hacker News
NGINX CVE-2026-42945 Exploited in the Wild, Causing Worker Crashes and Possible RCE

A newly disclosed security flaw impacting NGINX Plus and NGINX Open has come under active exploitation in the wild, days after its public disclosure, according to VulnCheck. The vulnerability, tracked ... Read more

Published Date: May 17, 2026 (2 days, 8 hours ago)
  • Daily CyberSecurity
CVSS 10 Alert: Quest KACE SMA Auth Bypass Exploited to Hijack Managed Endpoints

Detailed listing of tools and scripts within the exposed C2 directory | Image: Hunt Cybersecurity researchers have just dropped a report on a critical “management plane” threat that has spent the last ... Read more

Published Date: May 16, 2026 (3 days, 18 hours ago)
  • CybersecurityNews
79 Chrome Vulnerabilities Patched, Including 14 Critical One’s – Update Now!

Google has rolled out a massive security update for its Chrome browser, sealing a staggering 79 vulnerabilities before threat actors can exploit them. With 14 of these flaws rated as critical, browsin ... Read more

Published Date: May 15, 2026 (4 days, 12 hours ago)
  • The Cyber Express
Microsoft May 2026 Patch Tuesday Fixes 120 Vulnerabilities, No Zero-Day Exploits Reported

Microsoft has rolled out its May 2026 Patch Tuesday security updates, delivering fixes for approximately 120 vulnerabilities across Windows, Microsoft Office, networking services, and enterprise platf ... Read more

Published Date: May 13, 2026 (6 days, 13 hours ago)
  • CybersecurityNews
PoC Exploit Released for Android Zero-Click Vulnerability that Enables Remote Shell Access

In a chilling blow to mobile security, Google’s May 2026 Android Security Bulletin has unmasked a catastrophic zero-click vulnerability lurking within the core Android System. The CVE-2026-0073 flaw i ... Read more

Published Date: May 12, 2026 (1 week ago)
  • CybersecurityNews
New BitUnlocker Downgrade Attack on Windows 11 Allows Access to Encrypted Disks in 5 Minutes

A new tool, BitUnlocker, reveals a practical downgrade attack against Microsoft’s BitLocker encryption, allowing attackers with physical access to decrypt protected volumes on patched Windows 11 machi ... Read more

Published Date: May 12, 2026 (1 week ago)
  • CybersecurityNews
Hackers Abuse CVE-2026-41940 to Take Over cPanel and WHM Servers

A fatal authentication bypass vulnerability is actively affecting cPanel and WebHost Manager (WHM) servers worldwide. Tracked as CVE-2026-41940 and bearing an apocalyptic maximum severity score of 9.8 ... Read more

Published Date: May 12, 2026 (1 week ago)
  • The Hacker News
cPanel CVE-2026-41940 Under Active Exploitation to Deploy Filemanager Backdoor

A threat actor named Mr_Rot13 has been attributed to the exploitation of a recently disclosed critical cPanel flaw to deploy a backdoor codenamed Filemanager on compromised environments. The attack ex ... Read more

Published Date: May 11, 2026 (1 week, 1 day ago)
  • security.nl
Nieuw beveiligingslek in cPanel en WHM laat aanvaller Perl-code uitvoeren

Een nieuw beveiligingslek in cPanel en WHM maakt het mogelijk voor een geauthenticeerde aanvaller om willekeurige Perl-code op de onderliggende machine uit te voeren. Er zijn updates beschikbaar gemaa ... Read more

Published Date: May 10, 2026 (1 week, 2 days ago)
  • CybersecurityNews
New cPanel and WHM Flaws Enable Code Execution, DoS Attacks

cPanel has disclosed three critical security vulnerabilities tracked as CVE-2026-29201, CVE-2026-29202, and CVE-2026-29203 affecting its widely deployed cPanel & WHM web hosting control panel and WP S ... Read more

Published Date: May 10, 2026 (1 week, 2 days ago)
  • The Hacker News
cPanel, WHM Release Fixes for Three New Vulnerabilities — Patch Now

Ravie LakshmananMay 09, 2026Vulnerability / Web Hosting cPanel has released updates to address three vulnerabilities in cPanel and Web Host Manager (WHM) that could be exploited to achieve privilege ... Read more

Published Date: May 09, 2026 (1 week, 3 days ago)
  • TheCyberThrone
CISA adds cPanel and Linux Kernel to KEV

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two actively exploited vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog — a critical authentication bypas ... Read more

Published Date: May 04, 2026 (2 weeks, 1 day ago)
  • CybersecurityNews
CISA Warns of cPanel & WHM Vulnerability Exploited in Attacks

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent warning regarding a critical security flaw affecting widely used web hosting management platforms. CISA recently a ... Read more

Published Date: May 04, 2026 (2 weeks, 1 day ago)
  • security.nl
Criminelen verspreiden Linux-ransomware via beveiligingslek in cPanel

Criminelen maken misbruik van een kritiek beveiligingslek in cPanel en WebHost Manager (WHM) om Linux-ransomware en Mirai-malware te verspreiden, zo meldt securitybedrijf Censys. Bij de aanvallen zoud ... Read more

Published Date: May 04, 2026 (2 weeks, 1 day ago)
  • CybersecurityNews
Hackers Breach Government and Military Servers by Exploiting cPanel Vulnerability

A sophisticated adversarial campaign targeting South-East Asian government and military infrastructure, combining rapid exploitation of a critical cPanel authentication bypass with a custom zero-day e ... Read more

Published Date: May 02, 2026 (2 weeks, 3 days ago)
  • CybersecurityNews
cPanelSniper – PoC Exploit Disclosed for cPanel Vulnerability, 44,000 Servers Compromised

A weaponized proof-of-concept (PoC) exploit framework dubbed “cPanelSniper” has been publicly released for CVE-2026-41940, a maximum-severity authentication bypass in cPanel & WHM that has already led ... Read more

Published Date: May 02, 2026 (2 weeks, 3 days ago)
  • security.nl
'44.000 cPanel-installaties vermoedelijk gehackt via nieuwe kwetsbaarheid'

Meer dan 44.000 installaties van cPanel en WebHost Manager (WHM) zijn zeer vermoedelijk gehackt via een nieuwe kritieke kwetsbaarheid, zo meldt The Shadowserver Foundation. De Amerikaanse en Australis ... Read more

Published Date: May 01, 2026 (2 weeks, 4 days ago)
  • The Register
First reports come in of victims of critical cPanel vuln as 'millions' of sites potentially exposed

CISA has added a critical cPanel bug to its known-exploited list, confirming that attackers are already poking holes in one of the internet's most widely used hosting stacks. The vulnerability, tracke ... Read more

Published Date: May 01, 2026 (2 weeks, 4 days ago)

The following table lists the changes that have been made to the CVE-2026-41940 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability's severity, exploitability, or other characteristics.

  • Modified Analysis by [email protected]

    May. 04, 2026

    Action Type Old Value New Value
    Changed CPE Configuration OR *cpe:2.3:a:cpanel:cpanel:*:*:*:*:*:*:*:* versions from (including) 11.40 up to (excluding) 86.0.41 *cpe:2.3:a:cpanel:cpanel:*:*:*:*:*:*:*:* versions from (including) 88.0.0 up to (excluding) 110.0.97 *cpe:2.3:a:cpanel:cpanel:*:*:*:*:*:*:*:* versions from (including) 112.0.0 up to (excluding) 118.0.63 *cpe:2.3:a:cpanel:cpanel:*:*:*:*:*:*:*:* versions from (including) 120.0.0 up to (excluding) 126.0.54 *cpe:2.3:a:cpanel:cpanel:*:*:*:*:*:*:*:* versions from (including) 128.0.0 up to (excluding) 130.0.19 *cpe:2.3:a:cpanel:cpanel:*:*:*:*:*:*:*:* versions from (including) 132.0.0 up to (excluding) 132.0.29 *cpe:2.3:a:cpanel:cpanel:*:*:*:*:*:*:*:* versions from (including) 134.0.0 up to (excluding) 134.0.20 *cpe:2.3:a:cpanel:cpanel:*:*:*:*:*:*:*:* versions from (including) 136.0.0 up to (excluding) 136.0.5 OR *cpe:2.3:a:cpanel:cpanel:*:*:*:*:*:*:*:* versions from (including) 11.40 up to (excluding) 86.0.41 *cpe:2.3:a:cpanel:cpanel:*:*:*:*:*:*:*:* versions from (including) 88.0.0 up to (excluding) 110.0.97 *cpe:2.3:a:cpanel:cpanel:*:*:*:*:*:*:*:* versions from (including) 112.0.0 up to (excluding) 118.0.63 *cpe:2.3:a:cpanel:cpanel:*:*:*:*:*:*:*:* versions from (including) 128.0.0 up to (excluding) 130.0.19 *cpe:2.3:a:cpanel:cpanel:*:*:*:*:*:*:*:* versions from (including) 132.0.0 up to (excluding) 132.0.29 *cpe:2.3:a:cpanel:cpanel:*:*:*:*:*:*:*:* versions from (including) 134.0.0 up to (excluding) 134.0.20 *cpe:2.3:a:cpanel:cpanel:*:*:*:*:*:*:*:* versions from (including) 136.0.0 up to (excluding) 136.0.5 *cpe:2.3:a:cpanel:cpanel:*:*:*:*:*:*:*:* versions from (including) 120.0.0 up to (excluding) 124.0.35 *cpe:2.3:a:cpanel:cpanel:*:*:*:*:*:*:*:* versions from (including) 126.0.1 up to (excluding) 126.0.54
    Changed CPE Configuration OR *cpe:2.3:a:cpanel:whm:*:*:*:*:*:*:*:* versions from (including) 11.40 up to (excluding) 86.0.41 *cpe:2.3:a:cpanel:whm:*:*:*:*:*:*:*:* versions from (including) 112.0.0 up to (excluding) 118.0.63 *cpe:2.3:a:cpanel:whm:*:*:*:*:*:*:*:* versions from (including) 120.0.0 up to (excluding) 126.0.54 *cpe:2.3:a:cpanel:whm:*:*:*:*:*:*:*:* versions from (including) 128.0.0 up to (excluding) 130.0.19 *cpe:2.3:a:cpanel:whm:*:*:*:*:*:*:*:* versions from (including) 132.0.0 up to (excluding) 132.0.29 *cpe:2.3:a:cpanel:whm:*:*:*:*:*:*:*:* versions from (including) 134.0.0 up to (excluding) 134.0.20 *cpe:2.3:a:cpanel:whm:*:*:*:*:*:*:*:* versions from (including) 136.0.0 up to (excluding) 136.0.5 *cpe:2.3:a:cpanel:whm:*:*:*:*:*:*:*:* versions from (including) 88.0.0 up to (excluding) 110.0.97 OR *cpe:2.3:a:cpanel:whm:*:*:*:*:*:*:*:* versions from (including) 11.40 up to (excluding) 86.0.41 *cpe:2.3:a:cpanel:whm:*:*:*:*:*:*:*:* versions from (including) 112.0.0 up to (excluding) 118.0.63 *cpe:2.3:a:cpanel:whm:*:*:*:*:*:*:*:* versions from (including) 128.0.0 up to (excluding) 130.0.19 *cpe:2.3:a:cpanel:whm:*:*:*:*:*:*:*:* versions from (including) 132.0.0 up to (excluding) 132.0.29 *cpe:2.3:a:cpanel:whm:*:*:*:*:*:*:*:* versions from (including) 134.0.0 up to (excluding) 134.0.20 *cpe:2.3:a:cpanel:whm:*:*:*:*:*:*:*:* versions from (including) 136.0.0 up to (excluding) 136.0.5 *cpe:2.3:a:cpanel:whm:*:*:*:*:*:*:*:* versions from (including) 88.0.0 up to (excluding) 110.0.97 *cpe:2.3:a:cpanel:whm:*:*:*:*:*:*:*:* versions from (including) 120.0.0 up to (excluding) 124.0.35 *cpe:2.3:a:cpanel:whm:*:*:*:*:*:*:*:* versions from (including) 126.0.1 up to (excluding) 126.0.54
    Added Reference Type CVE: https://labs.watchtowr.com/the-internet-is-falling-down-falling-down-falling-down-cpanel-whm-authentication-bypass-cve-2026-41940/ Types: Exploit, Third Party Advisory
    Added Reference Type CVE: https://www.bleepingcomputer.com/news/security/critrical-cpanel-flaw-mass-exploited-in-sorry-ransomware-attacks/ Types: Press/Media Coverage
  • CVE Modified by af854a3a-2127-422b-91ae-364da2661108

    May. 04, 2026

    Action Type Old Value New Value
    Added Reference https://labs.watchtowr.com/the-internet-is-falling-down-falling-down-falling-down-cpanel-whm-authentication-bypass-cve-2026-41940/
    Added Reference https://www.bleepingcomputer.com/news/security/critrical-cpanel-flaw-mass-exploited-in-sorry-ransomware-attacks/
  • Initial Analysis by [email protected]

    Apr. 30, 2026

    Action Type Old Value New Value
    Added CPE Configuration OR *cpe:2.3:a:cpanel:cpanel:*:*:*:*:*:*:*:* versions from (including) 11.40 up to (excluding) 86.0.41 *cpe:2.3:a:cpanel:cpanel:*:*:*:*:*:*:*:* versions from (including) 88.0.0 up to (excluding) 110.0.97 *cpe:2.3:a:cpanel:cpanel:*:*:*:*:*:*:*:* versions from (including) 112.0.0 up to (excluding) 118.0.63 *cpe:2.3:a:cpanel:cpanel:*:*:*:*:*:*:*:* versions from (including) 120.0.0 up to (excluding) 126.0.54 *cpe:2.3:a:cpanel:cpanel:*:*:*:*:*:*:*:* versions from (including) 128.0.0 up to (excluding) 130.0.19 *cpe:2.3:a:cpanel:cpanel:*:*:*:*:*:*:*:* versions from (including) 132.0.0 up to (excluding) 132.0.29 *cpe:2.3:a:cpanel:cpanel:*:*:*:*:*:*:*:* versions from (including) 134.0.0 up to (excluding) 134.0.20 *cpe:2.3:a:cpanel:cpanel:*:*:*:*:*:*:*:* versions from (including) 136.0.0 up to (excluding) 136.0.5
    Added CPE Configuration OR *cpe:2.3:a:cpanel:whm:*:*:*:*:*:*:*:* versions from (including) 11.40 up to (excluding) 86.0.41 *cpe:2.3:a:cpanel:whm:*:*:*:*:*:*:*:* versions from (including) 112.0.0 up to (excluding) 118.0.63 *cpe:2.3:a:cpanel:whm:*:*:*:*:*:*:*:* versions from (including) 120.0.0 up to (excluding) 126.0.54 *cpe:2.3:a:cpanel:whm:*:*:*:*:*:*:*:* versions from (including) 128.0.0 up to (excluding) 130.0.19 *cpe:2.3:a:cpanel:whm:*:*:*:*:*:*:*:* versions from (including) 132.0.0 up to (excluding) 132.0.29 *cpe:2.3:a:cpanel:whm:*:*:*:*:*:*:*:* versions from (including) 134.0.0 up to (excluding) 134.0.20 *cpe:2.3:a:cpanel:whm:*:*:*:*:*:*:*:* versions from (including) 136.0.0 up to (excluding) 136.0.5 *cpe:2.3:a:cpanel:whm:*:*:*:*:*:*:*:* versions from (including) 88.0.0 up to (excluding) 110.0.97
    Added CPE Configuration OR *cpe:2.3:a:cpanel:wp_squared:*:*:*:*:*:wordpress:*:* versions up to (excluding) 136.1.7
    Added Reference Type VulnCheck: https://docs.cpanel.net/release-notes/release-notes Types: Release Notes
    Added Reference Type VulnCheck: https://docs.wpsquared.com/changelogs/versions/changelog/#13617 Types: Release Notes
    Added Reference Type CISA-ADP: https://github.com/watchtowrlabs/watchTowr-vs-cPanel-WHM-AuthBypass-to-RCE.py Types: Exploit, Third Party Advisory
    Added Reference Type VulnCheck: https://support.cpanel.net/hc/en-us/articles/40073787579671-cPanel-WHM-Security-Update-04-28-2026 Types: Vendor Advisory
    Added Reference Type CISA-ADP: https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-41940 Types: US Government Resource
    Added Reference Type VulnCheck: https://www.namecheap.com/status-updates/ongoing-critical-security-vulnerability-in-cpanel-april-28-2026 Types: Third Party Advisory
    Added Reference Type VulnCheck: https://www.vulncheck.com/advisories/cpanel-and-whm-authentication-bypass-via-login-flow Types: Third Party Advisory
  • CVE Modified by 134c704f-9b21-4f2e-91b3-4a467353bcc0

    Apr. 30, 2026

    Action Type Old Value New Value
    Added Reference https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-41940
  • CVE Modified by [email protected]

    Apr. 30, 2026

    Action Type Old Value New Value
    Changed Description cPanel and WHM versions prior to 11.110.0.97, 11.118.0.63, 11.126.0.54, 11.132.0.29, 11.134.0.20, and 11.136.0.5 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel. cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.
  • CVE Modified by 134c704f-9b21-4f2e-91b3-4a467353bcc0

    Apr. 29, 2026

    Action Type Old Value New Value
    Added Reference https://github.com/watchtowrlabs/watchTowr-vs-cPanel-WHM-AuthBypass-to-RCE.py
  • New CVE Received by [email protected]

    Apr. 29, 2026

    Action Type Old Value New Value
    Added Description cPanel and WHM versions prior to 11.110.0.97, 11.118.0.63, 11.126.0.54, 11.132.0.29, 11.134.0.20, and 11.136.0.5 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.
    Added CVSS V4.0 AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
    Added CVSS V3.1 AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
    Added CWE CWE-306
    Added Reference https://docs.cpanel.net/release-notes/release-notes
    Added Reference https://docs.wpsquared.com/changelogs/versions/changelog/#13617
    Added Reference https://support.cpanel.net/hc/en-us/articles/40073787579671-cPanel-WHM-Security-Update-04-28-2026
    Added Reference https://www.namecheap.com/status-updates/ongoing-critical-security-vulnerability-in-cpanel-april-28-2026
    Added Reference https://www.vulncheck.com/advisories/cpanel-and-whm-authentication-bypass-via-login-flow
EPSS is a daily estimate of the probability of exploitation activity being observed over the next 30 days. Following chart shows the EPSS score history of the vulnerability.