logo

Warning: Critical authentication bypass in cPanel & WHM, Patch Immediately!

ID: 506b777c-6284-5273-aafe-32b73b66749b

STIX ID: report--506b777c-6284-5273-aafe-32b73b66749b

Feed Name: CCB Advisories Feed

Threat Score
95/100

Date Published: 2026-04-30

Date Updated: 2026-07-24

...
...

CVE-2026-41940 is a critical authentication bypass in cPanel & WHM (CVSS 9.8) that allows unauthenticated remote attackers to gain administrative access; public proof-of-concept code and indications of active exploitation have been reported. The advisory urges immediate patching, enhanced monitoring/detection, and incident reporting, noting that patching does not remediate potential historical compromise.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.