Threat Brief: CVE-2026-41940: Critical cPanel & WHM Authentication Bypass Actively Exploited in the Wild
ID: 47e4984a-4971-5d58-bb5e-8f19547232ae
STIX ID: report--47e4984a-4971-5d58-bb5e-8f19547232ae
Feed Name: Cato Networks
CVE-2026-41940 is a critical authentication-bypass in cPanel & WHM (post-11.40) that can allow unauthenticated attackers to gain administrative access; cPanel issued patches and detection guidance while vendors (Cloudflare, Cato) released protections and IPS/WAF signatures. The report outlines the four-stage exploit chain (pre-auth session creation, session manipulation, injected session attributes via Base64/Authorization, and session reload for bypass), documents vendor-documented and Cato-observed indicators (session-file artifacts and a set of source IPs), notes active exploitation in the wild, and emphasizes urgent patching, exposure validation, and layered protections.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
