CVE-2026-41940Active Exploitation(cpanel / cpanel)

CRITICALCVSS 9.3 · CRITICALCISA KEV

Exploitation observed; activity peaked at 121 mentions and remains active

Immediate actions

  • Patch cpanel cpanel systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.

9.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2026-05-03. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-306

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • cpanel
  • whm
  • wp_squared

Threat summary

  • Active exploitation appears in 565 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 940 mentions across 82 observed days

What's happening

  • Active exploitation reported across 565 signals
  • Exploit tool or code specified in 88 signals
  • PoC mentioned or linked in 148 signals
  • Patch or workaround mentioned in 303 signals
  • Technical details provided in 493 signals
  • General: 115 classified signals
  • Disclosure: 108 classified signals
  • Peaked 79d ago at 121 mentions (2026-05-01); latest day: 1
  • 940 total mentions across 82 days

Affected systems

Vendors
Products
cpanelwhmwp_squared

Deep dive

Activity timeline940 mentions / 82d
0306191121Mentions · 2026-04-29: 25Mentions · 2026-04-30: 119Mentions · 2026-05-01: 121Mentions · 2026-05-02: 48Mentions · 2026-05-03: 66Mentions · 2026-05-04: 92Mentions · 2026-05-05: 40Mentions · 2026-05-06: 44Mentions · 2026-05-07: 24Mentions · 2026-05-08: 12Mentions · 2026-05-09: 9Mentions · 2026-05-10: 16Mentions · 2026-05-11: 41Mentions · 2026-05-12: 51Mentions · 2026-05-13: 11Mentions · 2026-05-14: 5Mentions · 2026-05-15: 8Mentions · 2026-05-16: 6Mentions · 2026-05-17: 10Mentions · 2026-05-18: 4Mentions · 2026-05-19: 3Mentions · 2026-05-20: 5Mentions · 2026-05-21: 2Mentions · 2026-05-22: 6Mentions · 2026-05-23: 4Mentions · 2026-05-24: 2Mentions · 2026-05-25: 1Mentions · 2026-05-26: 2Mentions · 2026-05-27: 5Mentions · 2026-05-28: 1Mentions · 2026-05-29: 3Mentions · 2026-05-30: 2Mentions · 2026-05-31: 6Mentions · 2026-06-01: 12Mentions · 2026-06-02: 1Mentions · 2026-06-03: 2Mentions · 2026-06-04: 10Mentions · 2026-06-05: 10Mentions · 2026-06-06: 2Mentions · 2026-06-07: 1Mentions · 2026-06-08: 3Mentions · 2026-06-09: 2Mentions · 2026-06-13: 2Mentions · 2026-06-14: 1Mentions · 2026-06-15: 7Mentions · 2026-06-16: 15Mentions · 2026-06-17: 3Mentions · 2026-06-18: 1Mentions · 2026-06-19: 3Mentions · 2026-06-22: 8Mentions · 2026-06-26: 5Mentions · 2026-07-06: 1Mentions · 2026-07-07: 13Mentions · 2026-07-10: 1Mentions · 2026-07-15: 1Mentions · 2026-07-17: 1Mentions · 2026-07-21: 1Mentions · 2026-07-22: 2Mentions · 2026-07-23: 6Mentions · 2026-07-24: 1Mentions · 2026-07-25: 1Mentions · 2026-07-27: 1Mentions · 2026-07-29: 1Mentions · 2026-07-31: 1Mentions · 2026-08-05: 1Mentions · 2026-08-06: 3Mentions · 2026-08-10: 1Mentions · 2026-08-11: 1Mentions · 2026-08-12: 1Mentions · 2026-08-13: 1Mentions · 2026-08-14: 2Mentions · 2026-08-16: 3Mentions · 2026-08-21: 1Mentions · 2026-08-22: 2Mentions · 2026-08-23: 1Mentions · 2026-08-31: 1Mentions · 2026-09-05: 1Mentions · 2026-09-17: 1Mentions · 2026-09-18: 3Mentions · 2026-09-21: 2Mentions · 2026-09-29: 1Mentions · 2026-09-30: 1PoC Mentioned / Linked · 2026-04-29: 4PoC Mentioned / Linked · 2026-04-30: 25PoC Mentioned / Linked · 2026-05-01: 23PoC Mentioned / Linked · 2026-05-02: 11PoC Mentioned / Linked · 2026-05-03: 12PoC Mentioned / Linked · 2026-05-04: 14PoC Mentioned / Linked · 2026-05-05: 5PoC Mentioned / Linked · 2026-05-06: 6PoC Mentioned / Linked · 2026-05-07: 2PoC Mentioned / Linked · 2026-05-08: 4PoC Mentioned / Linked · 2026-05-09: 1PoC Mentioned / Linked · 2026-05-11: 7PoC Mentioned / Linked · 2026-05-12: 2PoC Mentioned / Linked · 2026-05-14: 1PoC Mentioned / Linked · 2026-05-15: 2PoC Mentioned / Linked · 2026-05-16: 1PoC Mentioned / Linked · 2026-05-18: 1PoC Mentioned / Linked · 2026-05-20: 1PoC Mentioned / Linked · 2026-05-21: 1PoC Mentioned / Linked · 2026-05-22: 2PoC Mentioned / Linked · 2026-05-24: 1PoC Mentioned / Linked · 2026-05-26: 1PoC Mentioned / Linked · 2026-05-27: 1PoC Mentioned / Linked · 2026-06-04: 1PoC Mentioned / Linked · 2026-06-15: 1PoC Mentioned / Linked · 2026-06-16: 2PoC Mentioned / Linked · 2026-07-10: 1PoC Mentioned / Linked · 2026-07-15: 1PoC Mentioned / Linked · 2026-07-22: 1PoC Mentioned / Linked · 2026-07-24: 1PoC Mentioned / Linked · 2026-08-06: 1PoC Mentioned / Linked · 2026-08-11: 1PoC Mentioned / Linked · 2026-08-13: 1PoC Mentioned / Linked · 2026-08-14: 1PoC Mentioned / Linked · 2026-08-16: 3PoC Mentioned / Linked · 2026-08-22: 2PoC Mentioned / Linked · 2026-09-17: 1PoC Mentioned / Linked · 2026-09-18: 2Exploit Tool / Code · 2026-04-29: 3Exploit Tool / Code · 2026-04-30: 12Exploit Tool / Code · 2026-05-01: 15Exploit Tool / Code · 2026-05-02: 8Exploit Tool / Code · 2026-05-03: 7Exploit Tool / Code · 2026-05-04: 10Exploit Tool / Code · 2026-05-05: 4Exploit Tool / Code · 2026-05-06: 5Exploit Tool / Code · 2026-05-07: 1Exploit Tool / Code · 2026-05-08: 2Exploit Tool / Code · 2026-05-11: 4Exploit Tool / Code · 2026-05-12: 2Exploit Tool / Code · 2026-05-15: 1Exploit Tool / Code · 2026-05-22: 2Exploit Tool / Code · 2026-05-24: 1Exploit Tool / Code · 2026-06-03: 1Exploit Tool / Code · 2026-07-24: 1Exploit Tool / Code · 2026-08-06: 1Exploit Tool / Code · 2026-08-13: 1Exploit Tool / Code · 2026-08-14: 1Exploit Tool / Code · 2026-08-16: 2Exploit Tool / Code · 2026-08-22: 2Exploit Tool / Code · 2026-09-17: 1Exploit Tool / Code · 2026-09-18: 1Active Exploitation · 2026-04-29: 4Active Exploitation · 2026-04-30: 52Active Exploitation · 2026-05-01: 71Active Exploitation · 2026-05-02: 36Active Exploitation · 2026-05-03: 46Active Exploitation · 2026-05-04: 66Active Exploitation · 2026-05-05: 30Active Exploitation · 2026-05-06: 21Active Exploitation · 2026-05-07: 12Active Exploitation · 2026-05-08: 7Active Exploitation · 2026-05-09: 3Active Exploitation · 2026-05-10: 5Active Exploitation · 2026-05-11: 31Active Exploitation · 2026-05-12: 44Active Exploitation · 2026-05-13: 10Active Exploitation · 2026-05-14: 3Active Exploitation · 2026-05-15: 5Active Exploitation · 2026-05-16: 4Active Exploitation · 2026-05-17: 9Active Exploitation · 2026-05-18: 3Active Exploitation · 2026-05-19: 1Active Exploitation · 2026-05-20: 2Active Exploitation · 2026-05-21: 1Active Exploitation · 2026-05-22: 3Active Exploitation · 2026-05-23: 1Active Exploitation · 2026-05-25: 1Active Exploitation · 2026-05-27: 2Active Exploitation · 2026-05-28: 1Active Exploitation · 2026-05-29: 2Active Exploitation · 2026-05-30: 2Active Exploitation · 2026-05-31: 4Active Exploitation · 2026-06-01: 7Active Exploitation · 2026-06-03: 2Active Exploitation · 2026-06-04: 6Active Exploitation · 2026-06-05: 7Active Exploitation · 2026-06-07: 1Active Exploitation · 2026-06-08: 2Active Exploitation · 2026-06-13: 1Active Exploitation · 2026-06-15: 4Active Exploitation · 2026-06-16: 6Active Exploitation · 2026-06-17: 2Active Exploitation · 2026-06-18: 1Active Exploitation · 2026-06-19: 1Active Exploitation · 2026-06-22: 6Active Exploitation · 2026-06-26: 4Active Exploitation · 2026-07-07: 12Active Exploitation · 2026-07-15: 1Active Exploitation · 2026-07-22: 2Active Exploitation · 2026-07-23: 6Active Exploitation · 2026-07-25: 1Active Exploitation · 2026-07-27: 1Active Exploitation · 2026-07-31: 1Active Exploitation · 2026-08-05: 1Active Exploitation · 2026-08-10: 1Active Exploitation · 2026-08-12: 1Active Exploitation · 2026-08-14: 1Active Exploitation · 2026-08-16: 1Active Exploitation · 2026-08-31: 1Active Exploitation · 2026-09-18: 1Active Exploitation · 2026-09-21: 2Patch / Workaround · 2026-04-29: 11Patch / Workaround · 2026-04-30: 57Patch / Workaround · 2026-05-01: 46Patch / Workaround · 2026-05-02: 19Patch / Workaround · 2026-05-03: 21Patch / Workaround · 2026-05-04: 24Patch / Workaround · 2026-05-05: 14Patch / Workaround · 2026-05-06: 10Patch / Workaround · 2026-05-07: 9Patch / Workaround · 2026-05-08: 4Patch / Workaround · 2026-05-09: 3Patch / Workaround · 2026-05-10: 12Patch / Workaround · 2026-05-11: 7Patch / Workaround · 2026-05-12: 7Patch / Workaround · 2026-05-13: 5Patch / Workaround · 2026-05-14: 1Patch / Workaround · 2026-05-15: 1Patch / Workaround · 2026-05-16: 2Patch / Workaround · 2026-05-17: 4Patch / Workaround · 2026-05-20: 2Patch / Workaround · 2026-05-21: 1Patch / Workaround · 2026-05-23: 2Patch / Workaround · 2026-05-26: 1Patch / Workaround · 2026-05-29: 1Patch / Workaround · 2026-06-03: 1Patch / Workaround · 2026-06-04: 3Patch / Workaround · 2026-06-05: 5Patch / Workaround · 2026-06-08: 2Patch / Workaround · 2026-06-14: 1Patch / Workaround · 2026-06-15: 1Patch / Workaround · 2026-06-16: 3Patch / Workaround · 2026-06-17: 2Patch / Workaround · 2026-06-18: 1Patch / Workaround · 2026-06-26: 1Patch / Workaround · 2026-07-07: 11Patch / Workaround · 2026-07-23: 1Patch / Workaround · 2026-07-25: 1Patch / Workaround · 2026-07-27: 1Patch / Workaround · 2026-08-05: 1Patch / Workaround · 2026-08-16: 1Patch / Workaround · 2026-08-31: 1Patch / Workaround · 2026-09-05: 1Patch / Workaround · 2026-09-18: 1Technical Details · 2026-04-29: 18Technical Details · 2026-04-30: 73Technical Details · 2026-05-01: 69Technical Details · 2026-05-02: 30Technical Details · 2026-05-03: 31Technical Details · 2026-05-04: 48Technical Details · 2026-05-05: 21Technical Details · 2026-05-06: 17Technical Details · 2026-05-07: 9Technical Details · 2026-05-08: 7Technical Details · 2026-05-09: 4Technical Details · 2026-05-10: 10Technical Details · 2026-05-11: 14Technical Details · 2026-05-12: 13Technical Details · 2026-05-13: 7Technical Details · 2026-05-14: 1Technical Details · 2026-05-15: 3Technical Details · 2026-05-16: 3Technical Details · 2026-05-17: 6Technical Details · 2026-05-18: 3Technical Details · 2026-05-20: 2Technical Details · 2026-05-21: 2Technical Details · 2026-05-22: 6Technical Details · 2026-05-23: 1Technical Details · 2026-05-24: 2Technical Details · 2026-05-25: 1Technical Details · 2026-05-27: 3Technical Details · 2026-05-28: 1Technical Details · 2026-05-29: 3Technical Details · 2026-05-30: 2Technical Details · 2026-05-31: 4Technical Details · 2026-06-01: 8Technical Details · 2026-06-03: 2Technical Details · 2026-06-04: 4Technical Details · 2026-06-05: 5Technical Details · 2026-06-06: 1Technical Details · 2026-06-07: 1Technical Details · 2026-06-08: 2Technical Details · 2026-06-09: 2Technical Details · 2026-06-13: 2Technical Details · 2026-06-15: 4Technical Details · 2026-06-16: 12Technical Details · 2026-06-17: 3Technical Details · 2026-06-18: 1Technical Details · 2026-06-19: 3Technical Details · 2026-06-22: 7Technical Details · 2026-06-26: 4Technical Details · 2026-07-10: 1Technical Details · 2026-07-17: 1Technical Details · 2026-07-21: 1Technical Details · 2026-07-22: 1Technical Details · 2026-07-23: 1Technical Details · 2026-08-06: 2Technical Details · 2026-08-14: 2Technical Details · 2026-08-16: 2Technical Details · 2026-08-22: 1Technical Details · 2026-08-23: 1Technical Details · 2026-08-31: 1Technical Details · 2026-09-17: 1Technical Details · 2026-09-18: 2Technical Details · 2026-09-21: 104-2905-0705-1505-2305-3106-0806-1907-2108-0508-2109-2909-30
Signal classification7 categories
Active Exploitation
53456.9%
General
11512.3%
Disclosure
10811.5%
Patch
10711.4%
PoC
464.9%
Exploit
272.9%
Referenced assets436 URLs
By indicator
Classification over time
DateTotalLabels
2026-04-2925
Active Exploitation4Disclosure5Exploit1General7Patch7PoC1
2026-04-30119
Active Exploitation48Disclosure18Exploit5General18Patch27PoC3
2026-05-01121
Active Exploitation64Disclosure14Exploit4False Positive1General15Patch19PoC4
2026-05-0248
Active Exploitation30Disclosure1Exploit2General4Patch4PoC7
2026-05-0366
Active Exploitation44Disclosure3Exploit1General7Patch6PoC5
2026-05-0492
Active Exploitation63Disclosure6Exploit2General11Patch5PoC5
2026-05-0540
Active Exploitation30Disclosure4General3Patch1PoC2
2026-05-0644
Active Exploitation17Disclosure9Exploit3General7Patch5PoC3
2026-05-0724
Active Exploitation11Disclosure3General2Patch7PoC1
2026-05-0812
Active Exploitation7Disclosure1Exploit1General1Patch2
2026-05-099
Active Exploitation2Disclosure2Exploit1General2Patch2
2026-05-1016
Active Exploitation5Disclosure3General3Patch5
2026-05-1141
Active Exploitation31Disclosure1Exploit1General4Patch3PoC1
2026-05-1251
Active Exploitation44Disclosure3General2Patch2
2026-05-1311
Active Exploitation10Patch1
2026-05-145
Active Exploitation3General1Patch1
2026-05-158
Active Exploitation5Disclosure1General2
2026-05-166
Active Exploitation4General1PoC1
2026-05-1710
Active Exploitation9Patch1
2026-05-184
Active Exploitation3General1
2026-05-193
Active Exploitation1Disclosure1General1
2026-05-205
Active Exploitation2Disclosure2Patch1
2026-05-212
Active Exploitation1Disclosure1
2026-05-226
Active Exploitation3Disclosure2PoC1
2026-05-234
Active Exploitation1General2Patch1
2026-05-242
Disclosure1PoC1
2026-05-251
Active Exploitation1
2026-05-262
Disclosure1Patch1
2026-05-275
Active Exploitation2Disclosure2PoC1
2026-05-281
Active Exploitation1
2026-05-293
Active Exploitation2Disclosure1
2026-05-302
Active Exploitation2
2026-05-316
Active Exploitation4Disclosure1General1
2026-06-0112
Active Exploitation7Disclosure3General2
2026-06-021
General1
2026-06-032
Active Exploitation2
2026-06-0410
Active Exploitation6Disclosure1General3
2026-06-0510
Active Exploitation7Disclosure1General2
2026-06-062
General2
2026-06-071
Active Exploitation1
2026-06-083
Active Exploitation2Patch1
2026-06-092
General2
2026-06-132
Active Exploitation1Disclosure1
2026-06-141
Patch1
2026-06-157
Active Exploitation4Disclosure2Patch1
2026-06-1615
Active Exploitation5Disclosure7Exploit1General2
2026-06-173
Active Exploitation2Patch1
2026-06-181
Active Exploitation1
2026-06-193
Active Exploitation1Disclosure2
2026-06-228
Active Exploitation6Disclosure1Exploit1
2026-06-265
Active Exploitation4General1
2026-07-061
Disclosure1
2026-07-0713
Active Exploitation12General1
2026-07-101
PoC1
2026-07-151
Active Exploitation1
2026-07-171
General1
2026-07-211
Disclosure1
2026-07-222
Active Exploitation2
2026-07-236
Active Exploitation6
2026-07-241
PoC1
2026-07-251
Active Exploitation1
2026-07-271
Active Exploitation1
2026-07-291
General1
2026-07-311
Active Exploitation1
2026-08-051
Patch1
2026-08-063
Disclosure1General1PoC1
2026-08-101
Active Exploitation1
2026-08-111
PoC1
2026-08-121
Active Exploitation1
2026-08-131
PoC1
2026-08-142
Active Exploitation1PoC1
2026-08-163
Exploit2PoC1
2026-08-211
General1
2026-08-222
Exploit1PoC1
2026-08-231
Disclosure1
2026-08-311
Active Exploitation1
2026-09-051
Patch1
2026-09-171
PoC1
2026-09-183
Active Exploitation1Exploit1PoC1
2026-09-212
Active Exploitation2
Full discourse20 posts
  • International Cyber Digest@IntCyberDigest
    Active Exploitation

    🚨 BREAKING: cPanel and WHM, the control panels behind an estimated 70+ million websites, have a critical security flaw that lets anyone become root admin without a password. CVE-2026-41940 affects every supported version. It’s already being exploited in the wild. watchTowr Labs published the full attack today, after the hosting company KnownHost confirmed the bug was already being used to break into a significant chunk of the internet. If you've never heard of cPanel: it's the dashboard that hosting providers and millions of website owners use to manage their servers, domains, email accounts, databases, and SSL certificates. WHM is the admin version that controls the entire server. If someone gets root access to WHM, they get the keys to the kingdom and to every apartment inside it. How the attack works, in plain English: 🔴 Step 1: The attacker sends a deliberately wrong login. cPanel still creates a temporary "you tried to log in" record on disk and gives the attacker a cookie tied to it. 🔴 Step 2: The attacker tweaks the cookie to disable cPanel's password encryption. Normally cPanel encrypts the password field on disk. With one small change to the cookie, cPanel just stores it as plain text instead. 🔴 Step 3: The attacker sends a fake login attempt where the password field secretly contains hidden line breaks. cPanel does not strip these line breaks out, so they get written straight to the session file. Each line break creates a brand new fake record. The attacker uses this to inject lines that say "this user is root" and "this user already authenticated successfully." 🔴 Step 4: The attacker visits one more random page on the site to nudge cPanel into re-reading the file. cPanel then promotes the injected fake lines into its main session memory. 🔴 Step 5: On the next request, cPanel sees a flag that says "this user already passed the password check." cPanel trusts that flag, skips checking the actual password, and lets the attacker in as root. From start to finish, the attack takes a handful of HTTP requests. If you run cPanel or WHM, the patched versions are: 🔴 cPanel/WHM 110.0.x → 11.110.0.97 🔴 cPanel/WHM 118.0.x → 11.118.0.63 🔴 cPanel/WHM 126.0.x → 11.126.0.54 🔴 cPanel/WHM 132.0.x → 11.132.0.29 🔴 cPanel/WHM 134.0.x → 11.134.0.20 🔴 cPanel/WHM 136.0.x → 11.136.0.5 If your version is older than these, assume someone has already broken in and act accordingly. Patch right now, then rotate every password and key the server touched: root passwords, API tokens, SSL private keys, SSH keys, mail passwords, and database passwords.

    Post summary

    CVE-2026-41940 is a critical flaw in cPanel/WHM that enables unauthenticated privilege escalation to root, is already being exploited in the wild, and patches are available.

    1037711663.9K2.2K560.2K
    184.6K followersView on X
  • Anonymous Hispano@anonopshispano
    Active Exploitation

    🚨 ALERTA: HACKEAN EL CORAZÓN DE INTERNET; FALLO EN CPANEL AFECTA A MILLONES 🛡️💻🔓 Se ha detectado una vulnerabilidad zero-day crítica (CVE-2026-41940) en cPanel y WHM, las herramientas que administran más de 70 millones de sitios web. Este fallo es una "llave maestra" que permite a cualquier atacante convertirse en administrador total (root) sin conocer la contraseña. 🖋️ ¿CÓMO FUNCIONA EL ATAQUE? (EN TÉRMINOS SENCILLOS) En términos sencillos, el hacker engaña al sistema mediante "recados falsos": 📋 El Engaño: Envía un inicio de sesión falso y manipula una "cookie" para que el servidor deje de cifrar datos. 📋 Inyección: Introduce líneas de texto ocultas que dicen "este usuario ya puso su clave y es el jefe". 📋 El Salto: El sistema lee estas líneas, confía en ellas y le da acceso total al atacante, saltándose toda seguridad. 🧐 ¿QUÉ DEBES HACER? ✨🧤🕊️ Si administras un servidor, la situación es crítica realidad en la que el ataque ya se está usando "en la calle". Actualiza de inmediato: Debes instalar las versiones parchadas (ej. 11.136.0.5 o superiores según tu rama). Limpia la casa: Si tenías una versión vulnerable, asume que ya entraron. Cambia contraseñas de root, bases de datos, correos y regenera llaves SSH y certificados SSL. ¿Está tu sitio web a salvo o le has dejado la puerta abierta al mundo? 🕒 En este entorno digital en el que un par de clics bastan para perderlo todo, la velocidad de tu reacción es tu única defensa, realidad en la que el parcheo no es opcional, es vital. 💸🚫💻 LA INFORMACIÓN TÉCNICA 👇 https://support.cpanel.net/hc/en-us/articles/40073787579671-Security-CVE-2026-41940-cPanel-WHM-WP2-Security-Update-04-28-2026 #cPanel #CyberSecurity #Hackers #ZeroDay #Hosting #SeguridadDigital 📋 📢🚨🛡️

    Post summary

    The post announces a zero‑day in cPanel/WHM with evident real‑world exploitation, urges immediate patching, and outlines key vulnerability details.

    16369231.3K702103.2K
    476.8K followersView on X
  • Yunus Emre Öztaş@ynsmroztas
    Exploit

    🚨 cPanelSniper — CVE-2026-41940 cPanel & WHM'de CVSS 10.0 kritik auth bypass. CRLF injection → session file poisoning → root WHM access. Zero creds. ~70M domain affected. 4-stage chain: → preauth session mint → CRLF inject via Authorization header → do_token_denied gadget (raw→cache flush) → /json-api/version → PWNED ✅ Interactive WHM shell ✅ Account enum · cmd exec · backdoor admin ✅ Bulk scan · pipeline ready · stdlib only 🔗 http://github.com/ynsmroztas/cPanelSniper #BugBounty #InfoSec #WHM #RedTeam #AppSec #bugbountytip #bugbountytips #infosec #recon

    Post summary

    The post announces a CVE-2026-41940 vulnerability with a publicly available 4‑stage exploit chain and GitHub repository, but has no evidence of active exploitation or patches.

    1319621.1K94061.5K
    7.7K followersView on X
  • DarkShadow@darkshadow2bd
    PoC

    WHAT THE HACK HAPPENS IN THIS YEAR! cPanel & WHM - Auth bypass (CVE-2026-41940) here is the exploit POC: https://github.com/watchtowrlabs/watchTowr-vs-cPanel-WHM-AuthBypass-to-RCE.py Join my bugbounty telegram chennal: http://t.me/ShellSec #bugbounty #cpanel #cve https://t.co/VoozmHKZc6

    Post summary

    The post shares a proof‑of‑concept exploit for CVE‑2026‑41940, providing a GitHub link to the code, but gives no indication of active exploitation, patch information, or detailed technical specifics.

    11124577962858.0K
    7.4K followersView on X
  • BleepingComputer@BleepinComputer
    Active Exploitation

    🚨 BREAKING: Hackers are now exploiting the cPanel authentication bypass flaw (CVE-2026-41940) to deploy "Sorry" ransomware on compromised websites. Numerous sources say attacks began Thursday, with threat actors breaching servers and deploying a Go-based Linux encryptor that appends the .sorry extension to files. What the ransomware does: 🔴 Encrypts files and appends the ".sorry" extension. 🔴 Protects the encryption key with an embedded RSA-2048 public key 🔴 Drops a README.md ransom note in every folder 🔴 Uses a fixed Tox ID for ransom negotiations Victims are being instructed to contact the attacker via Tox to pay for decryption. This is not related to the older 2018 HiddenTear ".sorry" ransomware. This is a new, Linux-targeting encryptor tied directly to active cPanel exploitation. If you're running cPanel or WHM, patch immediately.

    Post summary

    The post reports that CVE‑2026‑41940 is being actively exploited to deliver ransomware, urges immediate patching, and provides no PoC or exploit code.

    2023019838390109.2K
    255.0K followersView on X
  • Dark Web Informer@DarkWebInformer
    PoC

    ‼️ CVE-2026-41940: A high-performance, multi-threaded security auditing tool designed to detect CVE-2026-41940, a critical Authentication Bypass vulnerability in cPanel & WHM. https://github.com/XsanFlip/poc-cpanel-cve-2026-41940 https://t.co/6k0syQvMjK

    Post summary

    The post promotes a GitHub repository containing a proof‑of‑concept tool for the cPanel/WHM authentication bypass (CVE‑2026‑41940), confirming the vulnerability and providing exploitation code.

    5135267342243.4K
    222.6K followersView on X
  • watchTowr@watchtowrcyber
    General

    The Internet is falling down, falling down, falling down Welcome back to another disaster - this time, an Auth Bypass in cPanel/WHM, tracked as CVE-2026-41940 Enjoy with us.. https://labs.watchtowr.com/the-internet-is-falling-down-falling-down-falling-down-cpanel-whm-authentication-bypass-cve-2026-41940?123

    Post summary

    The post announces a newly discovered authentication bypass in cPanel/WHM for CVE-2026-41940, pointing to an external blog for more details but providing no evidence of exploitation or remediation.

    1117819624362152.9K
    12.2K followersView on X
  • The Hacker News@TheHackersNews
    Active Exploitation

    ⚠️ UPDATE: #cPanel flaw now tracked as CVE-2026-41940 (CVSS 9.8)—an auth bypass granting unauthenticated admin access. Reportedly exploited as a 0-day, with activity observed for at least 30 days before disclosure. Root cause: CRLF injection enabling session forgery. 🔗 Exploit mechanics and real-world impact → https://thehackernews.com/2026/04/critical-cpanel-authentication.html

    Post summary

    The text alerts that CVE-2026-41940, a high‑severity CRLF injection flaw in cPanel, has been actively exploited for roughly 30 days, granting unauthenticated admin access, with no patch announced and no exploit code detailed in the post.

    8169864823864.1K
    1.8M followersView on X
  • Dark Web Informer@DarkWebInformer
    PoC

    ‼️ cPanelSniper: CVE-2026-41940 - cPanel & WHM Authentication Bypass via Session-File CRLF Injection GitHub: https://github.com/ynsmroztas/cPanelSniper CVE-2026-41940 - cPanel & WHM Authentication Bypass via Session-File CRLF Injection 4-stage exploit chain · Interactive WHM Shell · Bulk scanner · Pipeline ready · stdlib only

    Post summary

    The post announces a GitHub release for CVE‑2026‑41940, offering a 4‑stage exploit chain and interactive shell that demonstrates authentication bypass via CRLF injection in cPanel/WHM. No evidence of active exploitation or patches is provided.

    593154037633.2K
    222.6K followersView on X
  • I'M H4CK3R 42@luckyhacker43
    Exploit

    The Internet Is Falling Down, Falling Down, Falling Down (cPanel & WHM Authentication Bypass CVE-2026-41940) 🤯🔥 🔗 Join team 👉 https://t.me/luckyhacker42 🔗 https://nvd.nist.gov/vuln/detail/CVE-2026-41940 🔗 https://github.com/watchtowrlabs/watchTowr-vs-cPanel-WHM-AuthBypass-to-RCE.py 🔗 https://labs.watchtowr.com/the-internet-is-falling-down-falling-down-falling-down-cpanel-whm-authentication-bypass-cve-2026-41940/ https://t.co/TBmHn4bTEz

    Post summary

    A new cPanel & WHM authentication bypass vulnerability (CVE‑2026‑41940) is announced, with a publicly available exploit script on GitHub, but no evidence of active exploitation or available patches.

    569142845630.3K
    5.0K followersView on X
  • Dark Web Informer@DarkWebInformer
    Active Exploitation

    🚨 The cPanel Situation Is Spiraling Fast On April 29, CVE-2026-41940 was disclosed: a critical pre-authentication bypass in cPanel/WHM that lets remote attackers skip the login flow entirely and gain elevated access. Within 24 hours, it was already being weaponized. Censys watched the fallout in real time. The 6-day timeline (cPanel hosts flagged malicious): Apr 26: 117 Apr 27: 47 Apr 28: 106 Apr 29: 70 Apr 30: 146 May 1: 15,448 On May 1 alone, total malicious hosts jumped by +19,131, and 15,302 of those (roughly 80%) were cPanel/WHM systems. Compare that to the prior days where cPanel made up well under 1.2% of daily changes. This was not background noise. It was a coordinated spike. Top affected providers: DigitalOcean: 1,043 Contabo: 716 OVH: 501 Vultr: 391 Oracle: 321 Unified Layer: 280 Hetzner: 277 Akamai/Linode: 275 GoDaddy: 209 Microsoft: 169 With 1,052,657 cPanel/WHM hosts exposed on the public internet and only 9,595 currently flagged as malicious, the attack surface is enormous and growing. At least two campaigns are running in parallel: a Mirai botnet variant (nuclear.x86) deployed post-compromise, and a ransomware campaign tied to the Sorry/Hidden-Tear family. Ransomware footprint: ~7,000 cPanel servers with ".sorry" encrypted files 6,465 hosts: index.html.sorry 1,637 hosts: index.php.sorry 795 hosts: wp-config.php.sorry Victims directed to attackers via qTox If you run cPanel/WHM, patch immediately. Source: https://censys.com/blog/the-cpanel-situation-is/

    Post summary

    The post details a newly disclosed CVE-2026-41940 that has already been actively exploited in the wild, evidenced by rapidly growing malicious host counts, and urges immediate patching of affected cPanel/WHM systems.

    13120250321964.9K
    222.6K followersView on X
  • Pirat_Nation 🔴@Pirat_Nation
    Active Exploitation

    Hackers are actively exploiting a critical vulnerability in cPanel and WHM known as CVE-2026-41940. This authentication bypass allows attackers to gain full admin access to web servers without needing any login information, the issue affects all currently supported versions of cPanel and WHM. The flaw has been under active attack since February 2026 and presents a major threat to shared hosting providers and the millions of websites they host. Attackers could steal data, install malware, or take over entire servers. cPanel released security patches on April 28 and recommends updating immediately. Many large hosting companies such as HostGator and Namecheap have already deployed the fix. If your server runs cPanel, apply the update now or contact your host to make sure you are protected.

    Post summary

    The notice highlights that CVE‑2026‑41940, a cPanel authentication bypass, is actively being exploited, underscores the urgent impact on shared hosting, and reports that vendor patches are available.

    963453215455.5K
    336.1K followersView on X
  • shubs@infosec_au
    General

    We've just released a high fidelity scanner for CVE-2026-41940 (cPanel/WHM authentication bypass). All public PoCs so far lead to false negatives, and are not reliable. @SLCyberSec's research team's notes on this here: https://slcyber.io/research-center/high-fidelity-check-for-the-cpanel-authentication-bypass-cve-2026-41940/ & tool here: https://github.com/assetnote/cpanel2shell-scanner

    Post summary

    SLCyberSec releases a high‑fidelity scanner for CVE‑2026‑41940 to address unreliable public PoCs; no exploit code or patch is disclosed.

    377034020024.2K
    58.6K followersView on X
  • International Cyber Digest@IntCyberDigest
    Active Exploitation

    🚨 UPDATE on the cPanel/WHM authentication bypass (CVE-2026-41940): Shadowserver now reports at least 44,000 unique IPs compromised and actively scanning their honeypot network on April 30, 2026. What this means in practice. Within roughly 24 hours of public disclosure, attackers have already taken over enough vulnerable cPanel/WHM servers to use them as a global scanning swarm, hunting for the next batch of victims. Each of those 44,000 IPs is itself a compromised host, mostly shared-hosting servers running customer websites, email, and databases. Shadowserver also reports approximately 650,000 cPanel/WHM instances exposed to the internet in total. Anything not patched today is sitting in the targeting pool.

    Post summary

    Shadowserver reports that at least 44,000 cPanel/WHM servers are compromised and actively scanning, signifying that CVE‑2026‑41940 is being actively exploited in the wild.

    569837813051.6K
    184.6K followersView on X
  • 🕳@sekurlsa_pw
    General

    Nuclei template for detection cPanel & WHM - Authentication Bypass via Session-File CRLF Injection nuclei -t http/cves/2026/CVE-2026-41940.yaml Use -u <target> -l <target.list> https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-41940.yaml

    Post summary

    The article provides a Nuclei detection template for CVE-2026-41940, noting an authentication bypass via CRLF injection, but it does not discuss exploits, active use, patches, or verification status.

    050024518515.5K
    2.6K followersView on X
  • The Hacker News@TheHackersNews
    Active Exploitation

    CVE-2026-41940 (cPanel) exploited within 24h • 44,000 IPs linked to scanning/brute-force activity • Targets: Southeast Asia gov/military + MSPs • Enables auth bypass → full system control • Mirai variants and Sorry ransomware observed Read: https://thehackernews.com/2026/05/critical-cpanel-vulnerability.html

    Post summary

    CVE-2026-41940 in cPanel has been actively exploited within 24 hours, with widespread scanning and authentication bypass leading to full system control, and the presence of Mirai variants and ransomware confirms malicious use.

    36972144521.5K
    1.8M followersView on X
  • DeepTechTR 🇹🇷@DeepTechTR
    Active Exploitation

    Hackerlar, cPanel ve WHM'de CVE-2026-41940 olarak bilinen kritik bir güvenlik açığını aktif olarak istismar ediyor. Bu kimlik doğrulama atlatma yöntemi, saldırganların herhangi bir giriş bilgisine ihtiyaç duymadan web sunucularına tam yönetici erişimi elde etmelerini sağlıyor ve sorun, cPanel ve WHM'nin şu anda desteklenen tüm sürümlerini etkiliyor. Bu güvenlik açığı, Şubat 2026'dan beri aktif saldırı altında ve paylaşımlı hosting sağlayıcıları ve barındırdıkları milyonlarca web sitesi için büyük bir tehdit oluşturuyor. Saldırganlar veri çalabilir, kötü amaçlı yazılım yükleyebilir veya tüm sunucuları ele geçirebilir. cPanel, 28 Nisan'da güvenlik yamaları yayınladı ve hemen güncelleme yapılmasını öneriyor. HostGator ve Namecheap gibi birçok büyük hosting şirketi düzeltmeyi zaten uyguladı. Sunucunuzda cPanel çalışıyorsa, güncellemeyi şimdi uygulayın veya korunduğunuzdan emin olmak için hosting sağlayıcınızla iletişime geçin.

    Post summary

    CVE‑2026‑41940 is being actively exploited, granting attackers full admin rights on cPanel/WHM, but official patches have been released and should be applied immediately.

    533019610422.9K
    24.3K followersView on X
  • Ryx@PadhiyarRushi
    PoC

    cPanel bypass tool is already on GitHub and being forked. CVE-2026-41940: unauthenticated authentication bypass for cPanel/WHM. Public PoC automates the whole path. Hosting control planes with this still open are getting scanned right now. https://github.com/lanicer/cve-2026-41940-PoC #Cybersecurity #AI #AISecurity #MCP #Claude #GPT #Infosec #Trending #AppSec #RCE

    Post summary

    The tweet announces CVE-2026-41940, an unauthenticated authentication bypass in cPanel/WHM, and shares a public PoC on GitHub while noting that vulnerable hosting control planes are currently being scanned.

    139015912413.8K
    953 followersView on X
  • The Hacker News@TheHackersNews
    Active Exploitation

    🚨 More than 2,000 attacker IPs worldwide are exploiting cPanel CVE-2026-41940 to deploy the Filemanager backdoor. The campaign, linked to Mr_Rot13, enables credential theft, ransomware, cryptomining, botnet activity, and persistent SSH access, with infrastructure tied to low-detection activity dating back to 2020. Read: https://thehackernews.com/2026/05/cpanel-cve-2026-41940-under-active.html

    Post summary

    The post reports that CVE-2026-41940 is being actively exploited by thousands of attacker IPs, facilitating credential theft, ransomware, and other malicious activities.

    55941826143.6K
    1.9M followersView on X
  • Gray Hats@the_yellow_fall
    Patch

    Critical 9.8 CVSS zero-day CVE-2026-41940 is hitting cPanel servers. Technical details and PoC exploit code are now public. Patch immediately to prevent takeover #cPanel #CVE202641940 #ZeroDay #AuthenticationBypass #PoC #Exploit #WebHosting #CyberSecurity https://securityonline.info/cpanel-authentication-security-update-2026/ https://t.co/O8hGOvLbDm

    Post summary

    CVE‑2026‑41940 is a critical zero‑day authentication bypass affecting cPanel servers, with public PoC exploit code; immediate patching is urged to prevent server takeover.

    03501799016.5K
    12.5K followersView on X
CPE platform detail3 entries

3 of 3 entries

PartVendorProductVersionTarget SWTarget HW
Appcpanelcpanel---
Appcpanelwhm---
Appcpanelwp_squared-wordpress-

Explore more