Multiple cPanel Bugs Allow Access to Critical System Resources
ID: faa84d18-95cb-5fc6-9d43-369080d06545
STIX ID: report--faa84d18-95cb-5fc6-9d43-369080d06545
Feed Name: Cyber Press
A critical set of vulnerabilities in cPanel & WHM was disclosed in April–May 2026, led by CVE-2026-41940 (CVSS 9.8), which allows crafted cookie-based requests to bypass authentication and multi-factor authentication and gives attackers full administrative control; researchers observed active exploitation before patches were released. Multiple subsequent May patches addressed additional server-side flaws that could be chained for privilege escalation, lateral movement, and persistence on shared hosting, and operators are urged to apply updates, rotate credentials, review logs, and audit customer accounts.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
