CRITICAL
CVE-2026-41940
CVSS
9.8
KEV
Description
cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.
Summary dbcve.org
cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized administrative access to the control panel. The flaw appears to be in the authentication mechanism itself, enabling attackers to circumvent login verification entirely.
Mitigation
Update cPanel/WHM to the latest version containing the security patch. As an interim measure, restrict network access to the cPanel/WHM interfaces using firewall rules or IP allow-listing until the patch can be applied.
Weakness (CWE)
CWE-306
Missing Authentication
EPSS Score
98.53%
Probability of exploitation in next 30 days
99.9th percentile
References
https://docs.cpanel.net/release-notes/release-notes
Release Notes
https://docs.wpsquared.com/changelogs/versions/changelog/#13617
Release Notes
https://support.cpanel.net/hc/en-us/articles/40073787579671-cPanel-WHM-Security-Update-04-28-2026
Vendor Advisory
https://www.namecheap.com/status-updates/ongoing-critical-security-vulnerability-in-cpanel-april-28-2026
Third Party Advisory
https://www.vulncheck.com/advisories/cpanel-and-whm-authentication-bypass-via-login-flow
Third Party Advisory
https://labs.watchtowr.com/the-internet-is-falling-down-falling-down-falling-down-cpanel-whm-authentication-bypass-cve-2026-41940/
Exploit, Third Party Advisory
https://www.bleepingcomputer.com/news/security/critrical-cpanel-flaw-mass-exploited-in-sorry-ransomware-attacks/
Press/Media Coverage
https://github.com/watchtowrlabs/watchTowr-vs-cPanel-WHM-AuthBypass-to-RCE.py
Exploit, Third Party Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-41940
US Government Resource
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.