CVE-2026-41940
CRITICALcPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.
Published: 4/29/2026Modified: 5/4/2026
References (9)
https://docs.cpanel.net/release-notes/release-notesRelease Noteshttps://docs.wpsquared.com/changelogs/versions/changelog/#13617Release Noteshttps://support.cpanel.net/hc/en-us/articles/40073787579671-cPanel-WHM-Security-Update-04-28-2026Vendor Advisoryhttps://www.namecheap.com/status-updates/ongoing-critical-security-vulnerability-in-cpanel-april-28-2026Third Party Advisoryhttps://www.vulncheck.com/advisories/cpanel-and-whm-authentication-bypass-via-login-flowThird Party Advisoryhttps://labs.watchtowr.com/the-internet-is-falling-down-falling-down-falling-down-cpanel-whm-authentication-bypass-cve-2026-41940/ExploitThird Party Advisoryhttps://www.bleepingcomputer.com/news/security/critrical-cpanel-flaw-mass-exploited-in-sorry-ransomware-attacks/Press/Media Coveragehttps://github.com/watchtowrlabs/watchTowr-vs-cPanel-WHM-AuthBypass-to-RCE.pyExploitThird Party Advisoryhttps://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-41940US Government Resource