logo

CISA Alerts on cPanel & WHM Flaw Actively Exploited in Attacks

ID: 88078165-c15b-59ef-aa4b-8a25a9129c04

STIX ID: report--88078165-c15b-59ef-aa4b-8a25a9129c04

Feed Name: Cyber Press

Threat Score
85/100

Date Published: 2026-05-04

Date Updated: 2026-05-05

Author: AnuPriya

...
...

CVE-2026-41940 is a missing-authentication (CWE-306) vulnerability in WebPros cPanel & WHM and WP2 that enables remote attackers to bypass the login flow and obtain administrative access. CISA added the flaw to its Known Exploited Vulnerabilities catalog on April 30, 2026, citing active exploitation; organizations are urged to apply vendor patches, follow secure configurations, monitor admin activity, or discontinue affected products if fixes are unavailable.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.