cPanel is a very popular hosting framework which is often very difficult to avoid exposing to the internet. The exploit for this weakness gives the attacker root access to cPanel (and from there easy RCE on the system), and the exploit is reliable, well documented, and affects all versions of cPanel except the latest patch. There are well over a million hosts exposed, and though cPanel does have some automated self-upgrade functionality, it can be turned off, and the window before an upgrade (usually up to 24h) is long enough for attacker to have already exploited this weakness. cPanel have provided a script you can use to detect if compromise has already occurred, which can be found here.
AI description
CVE-2026-41940 is an authentication bypass vulnerability impacting cPanel & WHM and WP Squared products. This flaw allows unauthenticated remote attackers to bypass the login process and gain unauthorized administrative access to affected systems. The vulnerability stems from a Carriage Return Line Feed (CRLF) injection within the login and session loading mechanisms of cPanel & WHM, where an attacker can manipulate the `whostmgrsession` cookie to circumvent encryption. Successful exploitation of CVE-2026-41940 grants an attacker control over the cPanel host system, including its configurations, databases, and the websites it manages. Security firm watchTowr Labs has published a technical analysis and proof-of-concept exploit for this vulnerability, detailed in their blog post titled "The Internet Is Falling Down, Falling Down, Falling Down (cPanel & WHM Authentication Bypass CVE-2026-41940)". The vulnerability affects cPanel and WHM versions after 11.40, with patches available in later versions.
- Description
- cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.
- Source
- disclosure@vulncheck.com
- NVD status
- Analyzed
- Products
- cpanel, whm, wp_squared
CVSS 4.0
- Type
- Secondary
- Base score
- 9.3
- Impact score
- -
- Exploitability score
- -
- Vector string
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Severity
- CRITICAL
CVSS 3.1
- Type
- Secondary
- Base score
- 9.8
- Impact score
- 5.9
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity
- CRITICAL
Data from CISA
- Vulnerability name
- WebPros cPanel & WHM and WP2 (WordPress Squared) Missing Authentication for Critical Function Vulnerability
- Exploit added on
- Apr 30, 2026
- Exploit action due
- May 3, 2026
- Required action
- Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- disclosure@vulncheck.com
- CWE-306
- Hype score
- Not currently trending
🚨 THREAT INTEL | May 4, 2026 🔴 cPanel auth bypass (CVE-2026-41940) ACTIVELY EXPLOITED 🔴 ScreenConnect RCE (CVE-2024-1708) — 30+ live C2s 🔴 Cisco SD-WAN Emergency Directive 500+ live malware URLs | Mirai, Vidar, LummaStealer active #ThreatIntel #Cybersecurity #SOC ht
@404LABSx
4 May 2026
145 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Top 5 Trending CVEs: 1 - CVE-2026-31431 2 - CVE-2026-41940 3 - CVE-2026-3910 4 - CVE-2024-20359 5 - CVE-2024-20353 #cve #cvetrends #cveshield #cybersecurity https://t.co/4Fua3CAN6W
@CVEShield
3 May 2026
120 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2025-55182といいCVE-2026-41940といい、なんで俺はCriticalの脆弱性に見舞われるんだ?
@hrktvl
1 May 2026
207 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
1 Quote
🚨 THREAT INTEL | May 1, 2026 PATCH: CVE-2026-41940 cPanel (due May 3) + CVE-2024-1708 ConnectWise RCE ACTIVE: QakBot C2, Vidar, LummaStealer, 500+ malicious URLs NEW: Needle Stealer + PhantomRPC Windows LPE #CyberSecurity #Infosec https://t.co/kJ4xBBgQTp
@404LABSx
1 May 2026
96 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:cpanel:cpanel:*:*:*:*:*:*:*:*",
"matchCriteriaId": "D018D47F-B020-41B1-8755-9197EB8673D3",
"versionEndExcluding": "86.0.41",
"versionStartIncluding": "11.40",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:cpanel:cpanel:*:*:*:*:*:*:*:*",
"matchCriteriaId": "9BF3DBAC-D629-44A9-B102-2D8F82709CA2",
"versionEndExcluding": "110.0.97",
"versionStartIncluding": "88.0.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:cpanel:cpanel:*:*:*:*:*:*:*:*",
"matchCriteriaId": "3EEFF12C-11E8-4A5C-9C72-BA1A422A9E72",
"versionEndExcluding": "118.0.63",
"versionStartIncluding": "112.0.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:cpanel:cpanel:*:*:*:*:*:*:*:*",
"matchCriteriaId": "5533AA73-5007-4820-A5C6-0460C486882D",
"versionEndExcluding": "124.0.35",
"versionStartIncluding": "120.0.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:cpanel:cpanel:*:*:*:*:*:*:*:*",
"matchCriteriaId": "15C0513D-8C56-4C5F-B818-E2CE90223AD4",
"versionEndExcluding": "126.0.54",
"versionStartIncluding": "126.0.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:cpanel:cpanel:*:*:*:*:*:*:*:*",
"matchCriteriaId": "B5FE32EC-AEFB-4B27-AE65-A95432CAA812",
"versionEndExcluding": "130.0.19",
"versionStartIncluding": "128.0.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:cpanel:cpanel:*:*:*:*:*:*:*:*",
"matchCriteriaId": "24982921-6C0D-478E-BBF1-7C9DC7023760",
"versionEndExcluding": "132.0.29",
"versionStartIncluding": "132.0.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:cpanel:cpanel:*:*:*:*:*:*:*:*",
"matchCriteriaId": "B0213A2B-4A5A-4098-87FF-517E33F96807",
"versionEndExcluding": "134.0.20",
"versionStartIncluding": "134.0.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:cpanel:cpanel:*:*:*:*:*:*:*:*",
"matchCriteriaId": "09F99F08-1FB9-4BC6-8C7D-52062BA28479",
"versionEndExcluding": "136.0.5",
"versionStartIncluding": "136.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:cpanel:whm:*:*:*:*:*:*:*:*",
"matchCriteriaId": "63BE6DEF-A6EA-4545-9A3D-E1BA84A50EC7",
"versionEndExcluding": "86.0.41",
"versionStartIncluding": "11.40",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:cpanel:whm:*:*:*:*:*:*:*:*",
"matchCriteriaId": "74E9C069-EA63-4B95-9229-45AD97563532",
"versionEndExcluding": "110.0.97",
"versionStartIncluding": "88.0.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:cpanel:whm:*:*:*:*:*:*:*:*",
"matchCriteriaId": "2FCD52CF-3F10-4FFA-8FC7-AA5F370AF9B8",
"versionEndExcluding": "118.0.63",
"versionStartIncluding": "112.0.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:cpanel:whm:*:*:*:*:*:*:*:*",
"matchCriteriaId": "2ED81103-D03E-4351-9C19-1B3F120268D6",
"versionEndExcluding": "124.0.35",
"versionStartIncluding": "120.0.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:cpanel:whm:*:*:*:*:*:*:*:*",
"matchCriteriaId": "6DC3D6F0-8D07-4719-977E-DB978AEB7A67",
"versionEndExcluding": "126.0.54",
"versionStartIncluding": "126.0.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:cpanel:whm:*:*:*:*:*:*:*:*",
"matchCriteriaId": "C6C216F5-330D-4DAA-B042-1A4707FF658E",
"versionEndExcluding": "130.0.19",
"versionStartIncluding": "128.0.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:cpanel:whm:*:*:*:*:*:*:*:*",
"matchCriteriaId": "8793EED8-BDBD-4CC8-9698-FCEE769CFB5B",
"versionEndExcluding": "132.0.29",
"versionStartIncluding": "132.0.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:cpanel:whm:*:*:*:*:*:*:*:*",
"matchCriteriaId": "53AC31A0-AD91-4897-89E7-1C05AF03BF5A",
"versionEndExcluding": "134.0.20",
"versionStartIncluding": "134.0.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:cpanel:whm:*:*:*:*:*:*:*:*",
"matchCriteriaId": "23D646D3-2BDC-44C8-8C5F-9E21B0613A48",
"versionEndExcluding": "136.0.5",
"versionStartIncluding": "136.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:cpanel:wp_squared:*:*:*:*:*:wordpress:*:*",
"matchCriteriaId": "80392939-B45D-4C12-ADBB-334E783BDE67",
"versionEndExcluding": "136.1.7",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]