cPanel & WHM Missing Authentication for Critical Function (CVE-2026-41940) — CISA KEV — Threadlinqs Intelligence
As of 2026-05-30, cPanel & WHM Missing Authentication for Critical Function (CVE-2026-41940) — CISA KEV is a critical-severity vulnerability threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 18 indicators of compromise.
Threat ID: TL-2026-0440 · Severity: CRITICAL · CVSS: 9.8 · Status: ACTIVE · Category: VULNERABILITY
WebPros cPanel & WHM and WP2 (WordPress Squared) contain a pre-authentication bypass in the login flow (CWE-306, CVE-2026-41940) that lets unauthenticated remote attackers reach administrative
CVE-2026-41940 is a missing-authentication-for-critical-function flaw in the cPanel & WHM control panel login flow that affects every supported release line beyond 11.40 and the WP2 (WordPress Squared) product that shares the cpsrvd code path. Because the cPanel & WHM administrative interface is reachable over the public internet on TCP/2083 (cPanel TLS), TCP/2087 (WHM TLS), TCP/2095 (Webmail TLS) and TCP/2096 (Webmail TLS) by default, an unauthenticated network attacker can interact with privileged endpoints normally gated by the login state machine.
The vulnerability scored CVSS 3.1 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) and CVSS 4.0 9.3, both Critical. CWE classification is CWE-306 — Missing Authentication for Critical Function. Successful abuse is functionally equivalent to gaining a privileged WHM session: an attacker can manage users, mailboxes, DNS, FTP, MySQL grants, and underlying server configuration, so any compromised host is best treated as fully compromised at the server-administrator layer.
CISA added CVE-2026-41940 to the Known Exploited Vulnerabilities (KEV) catalog on 2026-04-30, citing evidence of active exploitation. The KEV listing triggers BOD 22-01 obligations for U.S. Federal Civilian Executive Branch agencies and is a strong industry signal for accelerated remediation in the broader hosting and SMB-IT ecosystem. WebPros published security update notice 40073787579671 on 2026-04-28, releasing emergency builds across all maintained release tiers (LTS 11.110, 11.118, 11.126, current 11.132/11.134/11.136). Namecheap, one of the largest cPanel-based shared-hosting operators, took the unusual step of network-blocking TCP/2083 and TCP/2087 across its fleet pending patch deployment.
This Threadlinqs record is intentionally a defensive-only knowledge base entry: it focuses on patch-state inventory, exposure reduction, and log/network telemetry blue teams can use to validate that their estate is patched and has not been touched. No exploit chain is reproduced here.
Remediation priorities are layered. First, identify every cPanel/WHM and WP2 host (managed and shadow IT) and confirm version is at or above the fixed build for its release line. Second, restrict the cPanel/WHM service ports to administrative IP allow-lists or VPN-only access until patching is verified — Namecheap-style perimeter blocks are an acceptable temporary mitigation for fleets that cannot patch within a 24-hour window. Third, perform a compromise assessment on any host that was both unpatched and internet-exposed since 2026-04-28: review /usr/local/cpanel/logs/access_log, /usr/local/cpanel/logs/error_log, /usr/local/cpanel/logs/login_log, and /var/cpanel/accounting.log for unexpected administrative logins, account creation, reseller privilege grants, package modifications, and SSH key additions. Finally, rotate WHM root, reseller, and cPanel user credentials, and reissue API tokens on any host that cannot be cleanly proven uncompromised.
Target sectors: hosting, small-business, education, government, media, ecommerce, nonprofit, healthcare, professional-services
Target regions: Global, North America, Europe, Asia-Pacific, Latin America
Detections & IOCs
As of 2026-07-26, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 18 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
VULNERABILITY, CRITICAL, threat intelligence, cybersecurity, CVE-2026-41940, T1595, T1595.002, T1592.002, T1583, T1190, T1133, T1078, T1059, T1136.001, T1098.004