logo

Bug of the year (so far): Nasty cPanel vulnerability probably exploited as a 0-day

ID: d4b1a2d6-e15f-5e06-8d69-c3d5d708bdff

STIX ID: report--d4b1a2d6-e15f-5e06-8d69-c3d5d708bdff

Feed Name: The Register (Security)

Threat Score
95/100

Date Published: 2026-04-30

Date Updated: 2026-05-06

...
...

A critical CRLF input-sanitization vulnerability (CVE-2026-41940, CVSS 9.8) in cPanel and WHM allows attackers to create a session cookie from a failed login and send a crafted header to escalate privileges to root, effectively bypassing authentication; it potentially affects all supported, unpatched versions and services relying on cPanel (estimated reach: millions of domains). Emergency patches and vendor/third-party detection scripts are available and administrators are urged to patch immediately and scan for signs of compromise.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.