logo

Critical cPanel and WHM bug exploited as a zero-day, PoC now available

ID: 08ad8158-840e-5513-a754-3bd304611f6b

STIX ID: report--08ad8158-840e-5513-a754-3bd304611f6b

Feed Name: Bleeping Computer

Threat Score
85/100

Date Published: 2026-04-30

Date Updated: 2026-04-30

Author: Bill Toulas

...
...

**CVE-2026-41940 (cPanel/WHM/WP Squared)** — A CRLF injection in cPanel & WHM's login and session loading processes enables an authentication bypass that can grant full control of affected hosts; evidence shows exploitation attempts in the wild (observed as early as 2026-02-23). cPanel released fixes on 2026-04-28 with specific patched builds listed; vendors recommend restarting cpsrvd, blocking management ports (2083/2087/2095/2096) if patching is delayed, auditing for compromise, and using published detection scripts to verify vulnerability or infection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.