logo

CISA Alert Highlights Active Exploitation of cPanel & WHM Security Bug

ID: 60a159a0-a796-577d-bbc2-277ba7aae857

STIX ID: report--60a159a0-a796-577d-bbc2-277ba7aae857

Feed Name: GBHackers

Threat Score
85/100

Date Published: 2026-05-04

Date Updated: 2026-06-18

Author: Divya

...
...

CISA has added CVE-2026-41940 — a critical missing-authentication/authentication bypass flaw in WebPros cPanel & WHM and WP2 — to its KEV catalog, confirming active exploitation in the wild. The vulnerability allows remote attackers to bypass the login flow and obtain full administrative access to hosting control panels, posing a high risk of server compromise, data theft, and widespread abuse; CISA required federal agencies to remediate under BOD 22-01 and strongly urges immediate patching or discontinuation of affected products.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.