Attackers Exploit cPanel Authentication Bypass 0-Day After PoC Release
ID: 61970b90-c3e8-5598-b10a-5656f48aa7f0
STIX ID: report--61970b90-c3e8-5598-b10a-5656f48aa7f0
Feed Name: GBHackers
A critical CVE-2026-41940 zero-day in cPanel/WHM (CVSS 9.8) is actively exploited via a CRLF injection in the session load/save flow, allowing unauthenticated attackers to inject tokens to bypass authentication and achieve root RCE; a PoC has been published and numerous hosting providers are being targeted. The advisory lists affected branches and patched releases, detection indicators (e.g., injected cp_security_token, multi-line passwords, successful_external_auth_with_timestamp), and mitigation steps including immediate patching, session purging, forced password resets, and blocking control-panel ports if necessary.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
