logo

Multiple cPanel Bugs Allow Access to Critical System Resources

ID: faa84d18-95cb-5fc6-9d43-369080d06545

STIX ID: report--faa84d18-95cb-5fc6-9d43-369080d06545

Feed Name: Cyber Press

Threat Score
90/100

Date Published: 2026-05-15

Date Updated: 2026-05-22

Author: AnuPriya

...
...

A critical set of vulnerabilities in cPanel & WHM was disclosed in April–May 2026, led by CVE-2026-41940 (CVSS 9.8), which allows crafted cookie-based requests to bypass authentication and multi-factor authentication and gives attackers full administrative control; researchers observed active exploitation before patches were released. Multiple subsequent May patches addressed additional server-side flaws that could be chained for privilege escalation, lateral movement, and persistence on shared hosting, and operators are urged to apply updates, rotate credentials, review logs, and audit customer accounts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.