Critical severity9.8CISA KEVNVD Advisory· Published Apr 29, 2026· Updated May 4, 2026
CVE-2026-41940
CVE-2026-41940
Description
cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.
Affected products
3Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
8- labs.watchtowr.com/the-internet-is-falling-down-falling-down-falling-down-cpanel-whm-authentication-bypass-cve-2026-41940/nvdExploitThird Party Advisory
- support.cpanel.net/hc/en-us/articles/40073787579671-cPanel-WHM-Security-Update-04-28-2026nvdVendor Advisory
- www.namecheap.com/status-updates/ongoing-critical-security-vulnerability-in-cpanel-april-28-2026nvdThird Party Advisory
- www.vulncheck.com/advisories/cpanel-and-whm-authentication-bypass-via-login-flownvdThird Party Advisory
- docs.cpanel.net/release-notes/release-notesnvdRelease Notes
- docs.wpsquared.com/changelogs/versions/changelog/nvdRelease Notes
- www.bleepingcomputer.com/news/security/critrical-cpanel-flaw-mass-exploited-in-sorry-ransomware-attacks/nvdPress/Media Coverage
- www.cisa.gov/known-exploited-vulnerabilities-catalognvdUS Government Resource
News mentions
23- Stealthy hackers exploit cPanel flaw in active backdoor campaign (CVE-2026-41940)Help Net Security · May 12, 2026
- cPanel CVE-2026-41940 Under Active Exploitation to Deploy Filemanager BackdoorThe Hacker News · May 11, 2026
- Week in review: cPanel vulnerability actively exploited, DigiCert breach, LinkedIn job scamsHelp Net Security · May 10, 2026
- cPanel, WHM Release Fixes for Three New Vulnerabilities — Patch NowThe Hacker News · May 9, 2026
- Risky Business #836 -- You can't patch the bugpocalypseRisky Business · May 6, 2026
- Exploit Cyber-Frenzy Threatens Millions via Critical cPanel VulnerabilityDark Reading · May 4, 2026
- 4th May – Threat Intelligence ReportCheck Point Research · May 4, 2026
- Multiple threat actors actively exploit cPanel vulnerability (CVE-2026-41940)Help Net Security · May 4, 2026
- Critical cPanel Vulnerability Weaponized to Target Government and MSP NetworksThe Hacker News · May 4, 2026
- Over 40,000 Servers Compromised in Ongoing cPanel ExploitationSecurityWeek · May 4, 2026
- A week in security (April 27 – May 3)Malwarebytes Labs · May 4, 2026
- Week in review: High-severity LPE vulnerability in the Linux kernel, cPanel 0-day exploited for monthsHelp Net Security · May 3, 2026
- Critrical cPanel flaw mass-exploited in "Sorry" ransomware attacksBleepingComputer · May 2, 2026
- Federal agencies must patch cPanel bug by Sunday, CISA saysThe Record · May 1, 2026
- First reports come in of victims of critical cPanel vuln as 'millions' of sites potentially exposedThe Register Security · May 1, 2026
- First reports come in of victims of critical cPanel vuln as 'millions' of sites potentially exposedThe Register Security · May 1, 2026
- Actively exploited cPanel bug exposes millions of websites to takeoverMalwarebytes Labs · May 1, 2026
- cPanel zero-day exploited for months before patch release (CVE-2026-41940)Help Net Security · Apr 30, 2026
- Bug of the year (so far): Nasty cPanel vulnerability probably exploited as a 0-dayThe Register Security · Apr 30, 2026
- Bug of the year (so far): Nasty cPanel vulnerability probably exploited as a 0-dayThe Register Security · Apr 30, 2026
- CVE-2026-41940: cPanel & WHM Authentication BypassRapid7 Blog · Apr 29, 2026
- Critical cPanel Authentication Vulnerability Identified — Update Your Server ImmediatelyThe Hacker News · Apr 29, 2026
- CISA Adds One Known Exploited Vulnerability to CatalogCISA Alerts