Bug of the year (so far): Nasty cPanel vulnerability probably exploited as a 0-day
ID: 69b9f7f5-c6ae-57fb-8eec-31bc035d8774
STIX ID: report--69b9f7f5-c6ae-57fb-8eec-31bc035d8774
Feed Name: The Register (Security)
Threat Score
Critical CRLF vulnerability CVE-2026-41940 in cPanel and WHM (CVSS 9.8) allows attackers to bypass authentication and obtain root access on unpatched servers—potentially affecting millions of domains; evidence suggests possible zero-day exploitation for ~30 days and vendors/researchers have released patches and detection artefacts, so immediate patching and investigation are recommended.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
