logo

cPanel zero-day exploited for months before patch release (CVE-2026-41940)

ID: ee4f9445-dd25-59a4-a4ae-6bf504adb2d0

STIX ID: report--ee4f9445-dd25-59a4-a4ae-6bf504adb2d0

Feed Name: Help Net Security

Threat Score
85/100

Date Published: 2026-04-30

Date Updated: 2026-04-30

Author: Zeljka Zorz

...
...

A critical authentication bypass (CVE-2026-41940) in cPanel/WHM allows unauthenticated attackers to manipulate the whostmgrsession cookie and inject properties into session files (e.g., user=root), granting administrator-level access; exploitation has been observed in the wild since February 23. cPanel released patches on April 28 and recommends updating to patched builds, restarting cpsrvd, blocking WHM/cPanel ports, stopping cpsrvd/cpdavd, and using provided scripts to search for known indicators of compromise.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.