logo

Bug of the year (so far): Nasty cPanel vulnerability probably exploited as a 0-day

ID: 69b9f7f5-c6ae-57fb-8eec-31bc035d8774

STIX ID: report--69b9f7f5-c6ae-57fb-8eec-31bc035d8774

Feed Name: The Register (Security)

Threat Score
92/100

Date Published: 2026-04-30

Date Updated: 2026-04-30

Author: Connor Jones

...
...

Critical CRLF vulnerability CVE-2026-41940 in cPanel and WHM (CVSS 9.8) allows attackers to bypass authentication and obtain root access on unpatched servers—potentially affecting millions of domains; evidence suggests possible zero-day exploitation for ~30 days and vendors/researchers have released patches and detection artefacts, so immediate patching and investigation are recommended.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.