CVE-2026-41940
cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.
Actively exploited
- In the CISA exploited-vulnerabilities catalogue since Apr 30, 2026
- US federal agencies must remediate it by May 3, 2026 (BOD 22-01)
- Attacked 2 days before the vulnerability was made public
- Confirmed by sensors, not only by reports
- Used in ransomware campaigns
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Source: CISA KEV · Sep 21, 2026 Sep 20, 2026 Sep 19, 2026 Sep 18, 2026 Sep 18, 2026 Sep 17, 2026
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HAffected products
| Vendors | Product | Versions |
|---|---|---|
| cpanel | cpanel | < 86.0.41 |
| cpanel | whm | < 86.0.41 |
| cpanel | wp squared | < 136.1.7 |
Related articles
VulnerabilitiesCISA Adds Three Vulnerabilities to KEV Catalog: Langflow, Tomcat and N-central Affected
CISA adds three actively exploited vulnerabilities to the KEV catalog, impacting Langflow, Apache Tomcat, and N-central. Patch immediately by August 7, 2026.
VulnerabilitiesFrom a parked domain to server root: the critical flaw in cPanel/WHM
CVE-2026-65643 is a critical flaw in cPanel/WHM allowing privilege escalation to root. Immediate updates are required to prevent server compromise.
This product uses the NVD API but is not endorsed or certified by the NVD.