CVE-2026-41940

Critical9.8Published on April 29, 2026

cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.

Actively exploited

  • In the CISA exploited-vulnerabilities catalogue since Apr 30, 2026
  • US federal agencies must remediate it by May 3, 2026 (BOD 22-01)
  • Attacked 2 days before the vulnerability was made public
  • Confirmed by sensors, not only by reports
  • Used in ransomware campaigns

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Source: CISA KEV · Sep 21, 2026 Sep 20, 2026 Sep 19, 2026 Sep 18, 2026 Sep 18, 2026 Sep 17, 2026

CVSS score9.8 / 10CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness type (CWE)CWE-306
Vendorscpanel

Affected products

VendorsProductVersions
cpanelcpanel< 86.0.41
cpanelwhm< 86.0.41
cpanelwp squared< 136.1.7

Related articles

This product uses the NVD API but is not endorsed or certified by the NVD.

CVE database