CVE-2026-41960: cPanel auth bypass EITW

CVE-2026-41960. This is gonna burn some folks. cPanel and WHM have an auth bypass which is being currently exploited.

Last Update

2026-05-02T06:03:19Z

Notes

Censys is now seeing wide exploitation attempts, and evidence of Sorry ransomware as a follow-on to successful exploitation.

Shadowserver is reported 44k vulnerable, which they refer to as “likely compromised.”

There’s a weaaponized PoC here:

Additional Links

https://support.cpanel.net/hc/en-us/articles/40073787579671-cPanel-WHM-Security-Update-04-28-2026

3 Likes

WatchTowr has it. And we have a CVE:

CVE-2026-41940

We also have confirmed exploitation, so this moves to Threat Intel

Actions

Patch affected versions.

  • cPanel & WHM 110.0.x - patched in 11.110.0.97 (was 11.110.0.96)
  • cPanel & WHM 118.0.x - patched in 11.118.0.63 (was 11.118.0.61)
  • cPanel & WHM 126.0.x - patched in 11.126.0.54 (was 11.126.0.53)
  • cPanel & WHM 132.0.x - patched in 11.132.0.29 (was 11.132.0.27)
  • cPanel & WHM 134.0.x - patched in 11.134.0.20 (was 11.134.0.19)
  • cPanel & WHM 136.0.x - patched in 11.136.0.5 (was 11.136.0.4)

Thanks for clarifying affected versions - the official blurb is contradictory / ambiguous (“patch for the following versions”) != (“patches to the following versions”)

1 Like

Useful compilation of reports here from The Register.

KnownHost CEO says they have evidence of attempted exploitation as early as 2023-02-26.

Updated with Censys info