cPanel 0-Day Auth Bypass Exploited in the Wild, PoC Released
ID: 63046871-21ee-53e3-bcd0-aab71114acb3
STIX ID: report--63046871-21ee-53e3-bcd0-aab71114acb3
Feed Name: Cyber Press
Threat Score
A critical authentication-bypass vulnerability (tracked as CVE-2026-41940) in cPanel & WHM's cpsrvd service is being actively exploited, allowing unauthenticated attackers to gain root WHM access; a public proof-of-concept was released, cPanel issued emergency patches for multiple versions, and administrators are urged to apply updates or implement interim mitigations (block standard cPanel/WHM ports or disable services) immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
