CVE-2026-41940
WebPros cPanel & WHM and WP2 (WordPress Squared) Missing Authentication for Critical Function Vulnerability - [Actively Exploited]
Description
cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.
INFO
Published Date :
April 29, 2026, 4:16 p.m.
Last Modified :
May 4, 2026, 6:09 p.m.
Remotely Exploit :
Yes !
Source :
[email protected]
CISA KEV (Known Exploited Vulnerabilities)
For the benefit of the cybersecurity community and network defenders—and to help every organization better manage vulnerabilities and keep pace with threat activity—CISA maintains the authoritative source of vulnerabilities that have been exploited in the wild.
WebPros cPanel & WHM (WebHost Manager) and WP2 (WordPress Squared) contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Known Detected May 06, 2026
https://support.cpanel.net/hc/en-us/articles/40073787579671-cPanel-WHM-Security-Update-04-28-2026 ; https://docs.cpanel.net/release-notes/release-notes/ ; https://docs.wpsquared.com/changelogs/versions/changelog/#13617 ; https://nvd.nist.gov/vuln/detail/CVE-2026-41940"
Affected Products
The following products are affected by CVE-2026-41940
vulnerability.
Even if cvefeed.io is aware of the exact versions of the
products
that
are
affected, the information is not represented in the table below.
CVSS Scores
| Score | Version | Severity | Vector | Exploitability Score | Impact Score | Source |
|---|---|---|---|---|---|---|
| CVSS 3.1 | CRITICAL | 83251b91-4cc7-4094-a5c7-464a1b83ea10 | ||||
| CVSS 3.1 | CRITICAL | [email protected] | ||||
| CVSS 3.1 | CRITICAL | MITRE-CVE | ||||
| CVSS 4.0 | CRITICAL | 83251b91-4cc7-4094-a5c7-464a1b83ea10 | ||||
| CVSS 4.0 | CRITICAL | [email protected] |
Solution
- Update cPanel and WHM to a patched version.
- Verify successful update.
Public PoC/Exploit Available at Github
CVE-2026-41940 has a 98 public
PoC/Exploit available at Github.
Go to the Public Exploits tab to see the list.
References to Advisories, Solutions, and Tools
Here, you will find a curated list of external links that provide in-depth
information, practical solutions, and valuable tools related to
CVE-2026-41940.
CWE - Common Weakness Enumeration
While CVE identifies
specific instances of vulnerabilities, CWE categorizes the common flaws or
weaknesses that can lead to vulnerabilities. CVE-2026-41940 is
associated with the following CWEs:
Common Attack Pattern Enumeration and Classification (CAPEC)
Common Attack Pattern Enumeration and Classification
(CAPEC)
stores attack patterns, which are descriptions of the common attributes and
approaches employed by adversaries to exploit the CVE-2026-41940
weaknesses.
We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).
Coleção de skills de segurança ofensiva para Claude Code metodologia PTES completa com AWS/IAM (WorstAssume), pfSense (27+ CVEs), Active Directory, Web Attacks, Palo Alto PAN-OS, AI Agent Audit e LLM Security Testing. Integra AIRecon, Watchtower e hexstrike-local MCP
All-in-one WAF bypass & recon toolkit for bug bounty research. 21 modules: CORS, JWT, GraphQL, SSRF, JS secrets, WordPress, Nuclei fingerprint & more. No API keys required.
Python
None
Shell
Variant of Web Shell by oRb captured in the wild
PHP
None
Python
DonScan — Intelligent Vulnerability Discovery Platform | Built by Cysec Don
Shell Python Dockerfile Makefile JavaScript TypeScript TeX HTML CSS
None
Python
CVE-2026-41940 — cPanel/WHM Auth Bypass By Dr.Anach, CRLF injection in `cpsrvd` Basic auth handler → unauthenticated WHM API access → RCE as root. All cPanel since v11.40 affected.
Python
Форензика после CVE-2026-41940 (cPanel/WHM) — bash-скрипт и чек-лист
Shell
cPanelSniper STABLE - CVE-2026-41940 optimized for 10M+ targets
Python Shell
Defensive exposure assessment tool for identifying externally accessible cPanel, WHM, and Webmail management interfaces related to CVE-2026-41940.
Python
Project Ghost Engine** is an advanced, automated OSINT (Open Source Intelligence) and reconnaissance tool designed for security researchers, bug bounty hunters, and penetration testers. It aggregates data from various passive sources and generates a highly interactive, standalone HTML dashboard tailored to a specific target domain.
Python
A Rust honeypot that simulates a vulnerable cPanel/WHM instance for CVE-2026-41940
Dockerfile Rust
None
Shell
cve-2026-41940 cPanel/WHM Authentication Bypass - Detection Artifact Generator
Python
Results are limited to the first 15 repositories due to potential performance issues.
The following list is the news that have been mention
CVE-2026-41940 vulnerability anywhere in the article.
-
The Hacker News
SEPPMail Secure E-Mail Gateway Vulnerabilities Enable RCE and Mail Traffic Access
Critical security vulnerabilities have been disclosed in SEPPMail Secure E-Mail Gateway, an enterprise-grade email security solution, that could be exploited to achieve remote code execution and enabl ... Read more
-
The Hacker News
MiniPlasma Windows 0-Day Enables SYSTEM Privilege Escalation on Fully Patched Systems
Chaotic Eclipse, the security researcher behind the recently disclosed Windows flaws, YellowKey and GreenPlasma, has released a proof-of-concept (PoC) for a Windows privilege escalation zero-day flaw ... Read more
-
The Hacker News
NGINX CVE-2026-42945 Exploited in the Wild, Causing Worker Crashes and Possible RCE
A newly disclosed security flaw impacting NGINX Plus and NGINX Open has come under active exploitation in the wild, days after its public disclosure, according to VulnCheck. The vulnerability, tracked ... Read more
-
Daily CyberSecurity
CVSS 10 Alert: Quest KACE SMA Auth Bypass Exploited to Hijack Managed Endpoints
Detailed listing of tools and scripts within the exposed C2 directory | Image: Hunt Cybersecurity researchers have just dropped a report on a critical “management plane” threat that has spent the last ... Read more
-
CybersecurityNews
79 Chrome Vulnerabilities Patched, Including 14 Critical One’s – Update Now!
Google has rolled out a massive security update for its Chrome browser, sealing a staggering 79 vulnerabilities before threat actors can exploit them. With 14 of these flaws rated as critical, browsin ... Read more
-
The Cyber Express
Microsoft May 2026 Patch Tuesday Fixes 120 Vulnerabilities, No Zero-Day Exploits Reported
Microsoft has rolled out its May 2026 Patch Tuesday security updates, delivering fixes for approximately 120 vulnerabilities across Windows, Microsoft Office, networking services, and enterprise platf ... Read more
-
CybersecurityNews
PoC Exploit Released for Android Zero-Click Vulnerability that Enables Remote Shell Access
In a chilling blow to mobile security, Google’s May 2026 Android Security Bulletin has unmasked a catastrophic zero-click vulnerability lurking within the core Android System. The CVE-2026-0073 flaw i ... Read more
-
CybersecurityNews
New BitUnlocker Downgrade Attack on Windows 11 Allows Access to Encrypted Disks in 5 Minutes
A new tool, BitUnlocker, reveals a practical downgrade attack against Microsoft’s BitLocker encryption, allowing attackers with physical access to decrypt protected volumes on patched Windows 11 machi ... Read more
-
CybersecurityNews
Hackers Abuse CVE-2026-41940 to Take Over cPanel and WHM Servers
A fatal authentication bypass vulnerability is actively affecting cPanel and WebHost Manager (WHM) servers worldwide. Tracked as CVE-2026-41940 and bearing an apocalyptic maximum severity score of 9.8 ... Read more
-
The Hacker News
cPanel CVE-2026-41940 Under Active Exploitation to Deploy Filemanager Backdoor
A threat actor named Mr_Rot13 has been attributed to the exploitation of a recently disclosed critical cPanel flaw to deploy a backdoor codenamed Filemanager on compromised environments. The attack ex ... Read more
-
security.nl
Nieuw beveiligingslek in cPanel en WHM laat aanvaller Perl-code uitvoeren
Een nieuw beveiligingslek in cPanel en WHM maakt het mogelijk voor een geauthenticeerde aanvaller om willekeurige Perl-code op de onderliggende machine uit te voeren. Er zijn updates beschikbaar gemaa ... Read more
-
CybersecurityNews
New cPanel and WHM Flaws Enable Code Execution, DoS Attacks
cPanel has disclosed three critical security vulnerabilities tracked as CVE-2026-29201, CVE-2026-29202, and CVE-2026-29203 affecting its widely deployed cPanel & WHM web hosting control panel and WP S ... Read more
-
The Hacker News
cPanel, WHM Release Fixes for Three New Vulnerabilities — Patch Now
Ravie LakshmananMay 09, 2026Vulnerability / Web Hosting cPanel has released updates to address three vulnerabilities in cPanel and Web Host Manager (WHM) that could be exploited to achieve privilege ... Read more
-
TheCyberThrone
CISA adds cPanel and Linux Kernel to KEV
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two actively exploited vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog — a critical authentication bypas ... Read more
-
CybersecurityNews
CISA Warns of cPanel & WHM Vulnerability Exploited in Attacks
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent warning regarding a critical security flaw affecting widely used web hosting management platforms. CISA recently a ... Read more
-
security.nl
Criminelen verspreiden Linux-ransomware via beveiligingslek in cPanel
Criminelen maken misbruik van een kritiek beveiligingslek in cPanel en WebHost Manager (WHM) om Linux-ransomware en Mirai-malware te verspreiden, zo meldt securitybedrijf Censys. Bij de aanvallen zoud ... Read more
-
CybersecurityNews
Hackers Breach Government and Military Servers by Exploiting cPanel Vulnerability
A sophisticated adversarial campaign targeting South-East Asian government and military infrastructure, combining rapid exploitation of a critical cPanel authentication bypass with a custom zero-day e ... Read more
-
CybersecurityNews
cPanelSniper – PoC Exploit Disclosed for cPanel Vulnerability, 44,000 Servers Compromised
A weaponized proof-of-concept (PoC) exploit framework dubbed “cPanelSniper” has been publicly released for CVE-2026-41940, a maximum-severity authentication bypass in cPanel & WHM that has already led ... Read more
-
security.nl
'44.000 cPanel-installaties vermoedelijk gehackt via nieuwe kwetsbaarheid'
Meer dan 44.000 installaties van cPanel en WebHost Manager (WHM) zijn zeer vermoedelijk gehackt via een nieuwe kritieke kwetsbaarheid, zo meldt The Shadowserver Foundation. De Amerikaanse en Australis ... Read more
-
The Register
First reports come in of victims of critical cPanel vuln as 'millions' of sites potentially exposed
CISA has added a critical cPanel bug to its known-exploited list, confirming that attackers are already poking holes in one of the internet's most widely used hosting stacks. The vulnerability, tracke ... Read more
The following table lists the changes that have been made to the
CVE-2026-41940 vulnerability over time.
Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability's severity, exploitability, or other characteristics.
-
Modified Analysis by [email protected]
May. 04, 2026
Action Type Old Value New Value Changed CPE Configuration OR *cpe:2.3:a:cpanel:cpanel:*:*:*:*:*:*:*:* versions from (including) 11.40 up to (excluding) 86.0.41 *cpe:2.3:a:cpanel:cpanel:*:*:*:*:*:*:*:* versions from (including) 88.0.0 up to (excluding) 110.0.97 *cpe:2.3:a:cpanel:cpanel:*:*:*:*:*:*:*:* versions from (including) 112.0.0 up to (excluding) 118.0.63 *cpe:2.3:a:cpanel:cpanel:*:*:*:*:*:*:*:* versions from (including) 120.0.0 up to (excluding) 126.0.54 *cpe:2.3:a:cpanel:cpanel:*:*:*:*:*:*:*:* versions from (including) 128.0.0 up to (excluding) 130.0.19 *cpe:2.3:a:cpanel:cpanel:*:*:*:*:*:*:*:* versions from (including) 132.0.0 up to (excluding) 132.0.29 *cpe:2.3:a:cpanel:cpanel:*:*:*:*:*:*:*:* versions from (including) 134.0.0 up to (excluding) 134.0.20 *cpe:2.3:a:cpanel:cpanel:*:*:*:*:*:*:*:* versions from (including) 136.0.0 up to (excluding) 136.0.5 OR *cpe:2.3:a:cpanel:cpanel:*:*:*:*:*:*:*:* versions from (including) 11.40 up to (excluding) 86.0.41 *cpe:2.3:a:cpanel:cpanel:*:*:*:*:*:*:*:* versions from (including) 88.0.0 up to (excluding) 110.0.97 *cpe:2.3:a:cpanel:cpanel:*:*:*:*:*:*:*:* versions from (including) 112.0.0 up to (excluding) 118.0.63 *cpe:2.3:a:cpanel:cpanel:*:*:*:*:*:*:*:* versions from (including) 128.0.0 up to (excluding) 130.0.19 *cpe:2.3:a:cpanel:cpanel:*:*:*:*:*:*:*:* versions from (including) 132.0.0 up to (excluding) 132.0.29 *cpe:2.3:a:cpanel:cpanel:*:*:*:*:*:*:*:* versions from (including) 134.0.0 up to (excluding) 134.0.20 *cpe:2.3:a:cpanel:cpanel:*:*:*:*:*:*:*:* versions from (including) 136.0.0 up to (excluding) 136.0.5 *cpe:2.3:a:cpanel:cpanel:*:*:*:*:*:*:*:* versions from (including) 120.0.0 up to (excluding) 124.0.35 *cpe:2.3:a:cpanel:cpanel:*:*:*:*:*:*:*:* versions from (including) 126.0.1 up to (excluding) 126.0.54 Changed CPE Configuration OR *cpe:2.3:a:cpanel:whm:*:*:*:*:*:*:*:* versions from (including) 11.40 up to (excluding) 86.0.41 *cpe:2.3:a:cpanel:whm:*:*:*:*:*:*:*:* versions from (including) 112.0.0 up to (excluding) 118.0.63 *cpe:2.3:a:cpanel:whm:*:*:*:*:*:*:*:* versions from (including) 120.0.0 up to (excluding) 126.0.54 *cpe:2.3:a:cpanel:whm:*:*:*:*:*:*:*:* versions from (including) 128.0.0 up to (excluding) 130.0.19 *cpe:2.3:a:cpanel:whm:*:*:*:*:*:*:*:* versions from (including) 132.0.0 up to (excluding) 132.0.29 *cpe:2.3:a:cpanel:whm:*:*:*:*:*:*:*:* versions from (including) 134.0.0 up to (excluding) 134.0.20 *cpe:2.3:a:cpanel:whm:*:*:*:*:*:*:*:* versions from (including) 136.0.0 up to (excluding) 136.0.5 *cpe:2.3:a:cpanel:whm:*:*:*:*:*:*:*:* versions from (including) 88.0.0 up to (excluding) 110.0.97 OR *cpe:2.3:a:cpanel:whm:*:*:*:*:*:*:*:* versions from (including) 11.40 up to (excluding) 86.0.41 *cpe:2.3:a:cpanel:whm:*:*:*:*:*:*:*:* versions from (including) 112.0.0 up to (excluding) 118.0.63 *cpe:2.3:a:cpanel:whm:*:*:*:*:*:*:*:* versions from (including) 128.0.0 up to (excluding) 130.0.19 *cpe:2.3:a:cpanel:whm:*:*:*:*:*:*:*:* versions from (including) 132.0.0 up to (excluding) 132.0.29 *cpe:2.3:a:cpanel:whm:*:*:*:*:*:*:*:* versions from (including) 134.0.0 up to (excluding) 134.0.20 *cpe:2.3:a:cpanel:whm:*:*:*:*:*:*:*:* versions from (including) 136.0.0 up to (excluding) 136.0.5 *cpe:2.3:a:cpanel:whm:*:*:*:*:*:*:*:* versions from (including) 88.0.0 up to (excluding) 110.0.97 *cpe:2.3:a:cpanel:whm:*:*:*:*:*:*:*:* versions from (including) 120.0.0 up to (excluding) 124.0.35 *cpe:2.3:a:cpanel:whm:*:*:*:*:*:*:*:* versions from (including) 126.0.1 up to (excluding) 126.0.54 Added Reference Type CVE: https://labs.watchtowr.com/the-internet-is-falling-down-falling-down-falling-down-cpanel-whm-authentication-bypass-cve-2026-41940/ Types: Exploit, Third Party Advisory Added Reference Type CVE: https://www.bleepingcomputer.com/news/security/critrical-cpanel-flaw-mass-exploited-in-sorry-ransomware-attacks/ Types: Press/Media Coverage -
CVE Modified by af854a3a-2127-422b-91ae-364da2661108
May. 04, 2026
Action Type Old Value New Value Added Reference https://labs.watchtowr.com/the-internet-is-falling-down-falling-down-falling-down-cpanel-whm-authentication-bypass-cve-2026-41940/ Added Reference https://www.bleepingcomputer.com/news/security/critrical-cpanel-flaw-mass-exploited-in-sorry-ransomware-attacks/ -
Initial Analysis by [email protected]
Apr. 30, 2026
Action Type Old Value New Value Added CPE Configuration OR *cpe:2.3:a:cpanel:cpanel:*:*:*:*:*:*:*:* versions from (including) 11.40 up to (excluding) 86.0.41 *cpe:2.3:a:cpanel:cpanel:*:*:*:*:*:*:*:* versions from (including) 88.0.0 up to (excluding) 110.0.97 *cpe:2.3:a:cpanel:cpanel:*:*:*:*:*:*:*:* versions from (including) 112.0.0 up to (excluding) 118.0.63 *cpe:2.3:a:cpanel:cpanel:*:*:*:*:*:*:*:* versions from (including) 120.0.0 up to (excluding) 126.0.54 *cpe:2.3:a:cpanel:cpanel:*:*:*:*:*:*:*:* versions from (including) 128.0.0 up to (excluding) 130.0.19 *cpe:2.3:a:cpanel:cpanel:*:*:*:*:*:*:*:* versions from (including) 132.0.0 up to (excluding) 132.0.29 *cpe:2.3:a:cpanel:cpanel:*:*:*:*:*:*:*:* versions from (including) 134.0.0 up to (excluding) 134.0.20 *cpe:2.3:a:cpanel:cpanel:*:*:*:*:*:*:*:* versions from (including) 136.0.0 up to (excluding) 136.0.5 Added CPE Configuration OR *cpe:2.3:a:cpanel:whm:*:*:*:*:*:*:*:* versions from (including) 11.40 up to (excluding) 86.0.41 *cpe:2.3:a:cpanel:whm:*:*:*:*:*:*:*:* versions from (including) 112.0.0 up to (excluding) 118.0.63 *cpe:2.3:a:cpanel:whm:*:*:*:*:*:*:*:* versions from (including) 120.0.0 up to (excluding) 126.0.54 *cpe:2.3:a:cpanel:whm:*:*:*:*:*:*:*:* versions from (including) 128.0.0 up to (excluding) 130.0.19 *cpe:2.3:a:cpanel:whm:*:*:*:*:*:*:*:* versions from (including) 132.0.0 up to (excluding) 132.0.29 *cpe:2.3:a:cpanel:whm:*:*:*:*:*:*:*:* versions from (including) 134.0.0 up to (excluding) 134.0.20 *cpe:2.3:a:cpanel:whm:*:*:*:*:*:*:*:* versions from (including) 136.0.0 up to (excluding) 136.0.5 *cpe:2.3:a:cpanel:whm:*:*:*:*:*:*:*:* versions from (including) 88.0.0 up to (excluding) 110.0.97 Added CPE Configuration OR *cpe:2.3:a:cpanel:wp_squared:*:*:*:*:*:wordpress:*:* versions up to (excluding) 136.1.7 Added Reference Type VulnCheck: https://docs.cpanel.net/release-notes/release-notes Types: Release Notes Added Reference Type VulnCheck: https://docs.wpsquared.com/changelogs/versions/changelog/#13617 Types: Release Notes Added Reference Type CISA-ADP: https://github.com/watchtowrlabs/watchTowr-vs-cPanel-WHM-AuthBypass-to-RCE.py Types: Exploit, Third Party Advisory Added Reference Type VulnCheck: https://support.cpanel.net/hc/en-us/articles/40073787579671-cPanel-WHM-Security-Update-04-28-2026 Types: Vendor Advisory Added Reference Type CISA-ADP: https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-41940 Types: US Government Resource Added Reference Type VulnCheck: https://www.namecheap.com/status-updates/ongoing-critical-security-vulnerability-in-cpanel-april-28-2026 Types: Third Party Advisory Added Reference Type VulnCheck: https://www.vulncheck.com/advisories/cpanel-and-whm-authentication-bypass-via-login-flow Types: Third Party Advisory -
CVE Modified by 134c704f-9b21-4f2e-91b3-4a467353bcc0
Apr. 30, 2026
Action Type Old Value New Value Added Reference https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-41940 -
CVE Modified by [email protected]
Apr. 30, 2026
Action Type Old Value New Value Changed Description cPanel and WHM versions prior to 11.110.0.97, 11.118.0.63, 11.126.0.54, 11.132.0.29, 11.134.0.20, and 11.136.0.5 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel. cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel. -
CVE Modified by 134c704f-9b21-4f2e-91b3-4a467353bcc0
Apr. 29, 2026
Action Type Old Value New Value Added Reference https://github.com/watchtowrlabs/watchTowr-vs-cPanel-WHM-AuthBypass-to-RCE.py -
New CVE Received by [email protected]
Apr. 29, 2026
Action Type Old Value New Value Added Description cPanel and WHM versions prior to 11.110.0.97, 11.118.0.63, 11.126.0.54, 11.132.0.29, 11.134.0.20, and 11.136.0.5 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel. Added CVSS V4.0 AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Added CVSS V3.1 AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Added CWE CWE-306 Added Reference https://docs.cpanel.net/release-notes/release-notes Added Reference https://docs.wpsquared.com/changelogs/versions/changelog/#13617 Added Reference https://support.cpanel.net/hc/en-us/articles/40073787579671-cPanel-WHM-Security-Update-04-28-2026 Added Reference https://www.namecheap.com/status-updates/ongoing-critical-security-vulnerability-in-cpanel-april-28-2026 Added Reference https://www.vulncheck.com/advisories/cpanel-and-whm-authentication-bypass-via-login-flow