logo

cPanel 0-Day Auth Bypass Exploited in the Wild, PoC Released

ID: 63046871-21ee-53e3-bcd0-aab71114acb3

STIX ID: report--63046871-21ee-53e3-bcd0-aab71114acb3

Feed Name: Cyber Press

Threat Score
90/100

Date Published: 2026-04-30

Date Updated: 2026-04-30

Author: Lucas Martin

...
...

A critical authentication-bypass vulnerability (tracked as CVE-2026-41940) in cPanel & WHM's cpsrvd service is being actively exploited, allowing unauthenticated attackers to gain root WHM access; a public proof-of-concept was released, cPanel issued emergency patches for multiple versions, and administrators are urged to apply updates or implement interim mitigations (block standard cPanel/WHM ports or disable services) immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.