Skip to main content
institutional access

You are connecting from
Lake Geneva Public Library,
please login or register to take advantage of your institution's Ground News Plan.

Published loading...Updated

Critical cPanel and WHM Bug Exploited as a Zero-Day, PoC Now Available

Researchers say the flaw lets attackers log in without a password, and Rapid7 estimates about 1.5 million cPanel instances are exposed online.

  • A critical authentication bypass vulnerability, tracked as CVE-2026-41940, allows remote attackers to gain full root administrator access to cPanel and Web Host Manager servers with a severity score of 9.8.
  • According to watchTowr Labs, the flaw involves "Carriage Return Line Feed injection in the login and session loading processes"; KnownHost CEO Daniel Pearson stated the company has "seen execution attempts as early as 2/23/2026."
  • Approximately 1.5 million cPanel instances are exposed online, according to Rapid7 scans; Namecheap blocked connections to ports 2083 and 2087 to prevent unauthorized access.
  • Canada's national cybersecurity agency warned that "exploitation is highly probable," while cPanel released patches for versions including 136.0 and added a "Sanitization" function to prevent injection attacks.
  • While KnownHost observed unauthorized attempts on around 30 servers, security researchers recommend that administrators audit logs and reset credentials if indicators of compromise appear.
Insights by Ground AI
Podcasts & Opinions

12 Articles

The discovery of a vulnerability in the cPanel identified as CVE-2026-41940 ignited an urgent alert in the hosting and security community. The failure, classified as zero-day, is being actively explored since February and allows authentication bypasses, opening the way for unauthorized access to servers. Considering the wide adoption of cPanel and WHM in shared hosting environments and VPS, the potential impact is significant. System administrat…

Think freely.Subscribe and get full access to Ground NewsSubscriptions start at $9.99/yearSubscribe

Bias Distribution

  • 100% of the sources are Center
100% Center

Factuality Info Icon

To view factuality data please Upgrade to Premium

Ownership

Info Icon

To view ownership data please Upgrade to Vantage

Malware Analysis, News and Indicators broke the news on Wednesday, April 29, 2026.
Too Big Arrow Icon
Sources are mostly out of (0)

Similar News Topics

News
Feed Dots Icon
For You
Search Icon
Search
Blindspot LogoBlindspotLocal