CVE-2026-41960. This is gonna burn some folks. cPanel and WHM have an auth bypass which is being currently exploited.
Last Update
2026-05-02T06:03:19Z
Notes
Censys is now seeing wide exploitation attempts, and evidence of Sorry ransomware as a follow-on to successful exploitation.
Shadowserver is reported 44k vulnerable, which they refer to as “likely compromised.”
There’s a weaaponized PoC here:
CVE-2026-41940 — cPanel & WHM Authentication Bypass via Session-File CRLF Injection
Additional Links
Dear Customers, We regret to inform you that a critical security vulnerability has been identified in cPanel software affecting all currently supported versions. This vulnerability relates to an authentication login exploit that could allow...
Est. reading time: 2 minutes
https://support.cpanel.net/hc/en-us/articles/40073787579671-cPanel-WHM-Security-Update-04-28-2026
Hello! Yes, it's all a disaster again!
Let's get this party started:
0:00
/0:12
1×
No comments today, so imagine this:
* We wrote something that we find very funny,
* Nobody else gets it,
* But...
3 Likes
WatchTowr has it. And we have a CVE:
CVE-2026-41940
Hello! Yes, it's all a disaster again!
Let's get this party started:
0:00
/0:12
1×
No comments today, so imagine this:
* We wrote something that we find very funny,
* Nobody else gets it,
* But...
We also have confirmed exploitation, so this moves to Threat Intel
Actions
Patch affected versions.
cPanel & WHM 110.0.x - patched in 11.110.0.97 (was 11.110.0.96)
cPanel & WHM 118.0.x - patched in 11.118.0.63 (was 11.118.0.61)
cPanel & WHM 126.0.x - patched in 11.126.0.54 (was 11.126.0.53)
cPanel & WHM 132.0.x - patched in 11.132.0.29 (was 11.132.0.27)
cPanel & WHM 134.0.x - patched in 11.134.0.20 (was 11.134.0.19)
cPanel & WHM 136.0.x - patched in 11.136.0.5 (was 11.136.0.4)
Thanks for clarifying affected versions - the official blurb is contradictory / ambiguous (“patch for the following versions”) != (“patches to the following versions”)
1 Like
Useful compilation of reports here from The Register.
KnownHost CEO says they have evidence of attempted exploitation as early as 2023-02-26.