Critical cPanel Vulnerability Lets Attackers Bypass Login, Gain Root Access
ID: bcb87904-4ded-5b3b-b95b-34479fc3c8ca
STIX ID: report--bcb87904-4ded-5b3b-b95b-34479fc3c8ca
Feed Name: HackRead
Threat Score
Researchers at watchTowr Labs disclosed CVE-2026-41940, a critical (CVSS 9.8) authentication-bypass vulnerability in cPanel & WHM's cpsrvd session handling that allows attackers to inject CRLF into session files and escalate to root without credentials; exploitation was observed in the wild as a 0-day since February 2026, patches were released on 28 April 2026, and detection artifacts were published to help administrators identify compromises.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
