📰 Full Story
A critical authentication-bypass vulnerability in cPanel and WebHost Manager (WHM), tracked as CVE-2026-41940 and rated 9.8 CVSS, is being actively exploited in the wild, security researchers and hosting firms reported.
The flaw, disclosed by watchTowr and patched by cPanel maker WebPros on April 28, 2026, allows attackers to inject CRLF characters into session files during login processing and promote that malicious data into the session cache to gain administrative — including root — access.
Rapid7 scans indicate roughly 1.5 million cPanel instances are exposed online, though the exact number of vulnerable installs is unknown.
KnownHost, Namecheap and other providers reported evidence of exploitation dating back to late February; CISA added the CVE to its Known Exploited Vulnerabilities list. cPanel has released fixes across supported branches (including WP Squared) plus detection scripts; recommended mitigations include immediate patching, searching for indicators of compromise, firewalling cPanel ports, and restarting cpanel services.








💬 Commentary