CVE-2026-41940
CISA KEVAs of 2026-04-30, CVE-2026-41940 is a CVSS 9.8 (CRITICAL-severity) vulnerability. CISA KEV-listed (known exploited). EPSS exploitation probability 28.4%. Threadlinqs Intelligence tracks 3 threats exploiting it.
Last updated: 2026-04-30
cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.
CVSS v3 vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses (CWE)
CWE-306
Exploitation status
CISA KEV-listed (known exploited)
Threats tracking this CVE
- KryBit Ransomware-as-a-Service Strikes Back — Breaches 0APT Infrastructure Amid Faux-Ransomware Feud (May 2026) — HIGH
- Sorry Ransomware Mass Exploitation of cPanel/WHM Authentication Bypass CVE-2026-41940 (44,000+ Servers Compromised) — CRITICAL
- cPanel & WHM Missing Authentication for Critical Function (CVE-2026-41940) — CISA KEV — CRITICAL
References
- https://docs.cpanel.net/release-notes/release-notes
- https://docs.wpsquared.com/changelogs/versions/changelog/#13617
- https://support.cpanel.net/hc/en-us/articles/40073787579671-cPanel-WHM-Security-Update-04-28-2026
- https://www.namecheap.com/status-updates/ongoing-critical-security-vulnerability-in-cpanel-april-28-2026
- https://www.vulncheck.com/advisories/cpanel-and-whm-authentication-bypass-via-login-flow
- https://github.com/watchtowrlabs/watchTowr-vs-cPanel-WHM-AuthBypass-to-RCE.py
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-41940
← all vulnerabilities · Markdown version · Threadlinqs Intelligence
Enriched from CVE.org, NVD (this product uses the NVD API but is not endorsed or certified by the NVD), FIRST EPSS, CISA KEV, and GitHub Security Advisories.