Critical cPanel and WHM bug exploited as a zero-day, PoC now available
ID: 08ad8158-840e-5513-a754-3bd304611f6b
STIX ID: report--08ad8158-840e-5513-a754-3bd304611f6b
Feed Name: Bleeping Computer
**CVE-2026-41940 (cPanel/WHM/WP Squared)** — A CRLF injection in cPanel & WHM's login and session loading processes enables an authentication bypass that can grant full control of affected hosts; evidence shows exploitation attempts in the wild (observed as early as 2026-02-23). cPanel released fixes on 2026-04-28 with specific patched builds listed; vendors recommend restarting cpsrvd, blocking management ports (2083/2087/2095/2096) if patching is delayed, auditing for compromise, and using published detection scripts to verify vulnerability or infection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
