logo

CISA Warns of cPanel & WHM Vulnerability Exploited in Attacks

ID: 269bad8a-90b8-5595-8b3e-1c14f8276ade

STIX ID: report--269bad8a-90b8-5595-8b3e-1c14f8276ade

Feed Name: cybersecurityNews.com

Threat Score
85/100

Date Published: 2026-05-04

Date Updated: 2026-05-05

Author: Abinaya

...
...

CISA warns of CVE-2026-41940, a critical CWE-306 authentication bypass in WebPros cPanel & WHM and WP2 that lets unauthenticated attackers directly obtain administrative access to hosting control panels; the vulnerability was added to CISA's KEV catalog with active exploitation reported and an urgent remediation deadline that has passed, so affected organizations are strongly urged to apply vendor patches or discontinue use immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.