๐ฐ Full Story
Security researchers and hosting providers warned on April 28โ30, 2026 that a critical authentication bypass in cPanel and WebHost Manager (CVE-2026-41940) is being actively exploited in the wild.
The flaw, rated 9.8 CVSS, affects all supported cPanel/WHM versions after 11.40 and WP Squared builds, and allows attackers to forge authenticated sessions via a CRLF injection and session-token manipulation to gain root-level access.
Rapid7 scans indicate roughly 1.5 million cPanel instances exposed online, though the number of vulnerable systems is unknown.
Evidence suggests exploitation began as early as February 23, and a public proof-of-concept and technical writeups have been released. cPanel published emergency patches across multiple version branches and supplied detection scripts; several major hosts (including Namecheap and HostGator) temporarily blocked cPanel ports and applied fixes.
CISA added the CVE to its Known Exploited Vulnerabilities list.
Recommended mitigations include immediate patching, restarting cPanel services, blocking ports 2083/2087/2095/2096, and running detection tools to hunt for indicators of compromise.








๐ฌ Commentary