logo

Threat Brief: CVE-2026-41940: Critical cPanel & WHM Authentication Bypass Actively Exploited in the Wild

ID: 47e4984a-4971-5d58-bb5e-8f19547232ae

STIX ID: report--47e4984a-4971-5d58-bb5e-8f19547232ae

Feed Name: Cato Networks

Threat Score
88/100

Date Published: 2026-05-02

Date Updated: 2026-07-23

Author: Tim Chen

...
...

CVE-2026-41940 is a critical authentication-bypass in cPanel & WHM (post-11.40) that can allow unauthenticated attackers to gain administrative access; cPanel issued patches and detection guidance while vendors (Cloudflare, Cato) released protections and IPS/WAF signatures. The report outlines the four-stage exploit chain (pre-auth session creation, session manipulation, injected session attributes via Base64/Authorization, and session reload for bypass), documents vendor-documented and Cato-observed indicators (session-file artifacts and a set of source IPs), notes active exploitation in the wild, and emphasizes urgent patching, exposure validation, and layered protections.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.