cPanel zero-day exploited for months before patch release (CVE-2026-41940)
ID: ee4f9445-dd25-59a4-a4ae-6bf504adb2d0
STIX ID: report--ee4f9445-dd25-59a4-a4ae-6bf504adb2d0
Feed Name: Help Net Security
A critical authentication bypass (CVE-2026-41940) in cPanel/WHM allows unauthenticated attackers to manipulate the whostmgrsession cookie and inject properties into session files (e.g., user=root), granting administrator-level access; exploitation has been observed in the wild since February 23. cPanel released patches on April 28 and recommends updating to patched builds, restarting cpsrvd, blocking WHM/cPanel ports, stopping cpsrvd/cpdavd, and using provided scripts to search for known indicators of compromise.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
