Skip to main content
Mallory
Back to stories
identity-authentication-vulnerabilitywidely-deployed-product-advisoryinternet-facing-service-vulnerabilityend-of-life-software

Critical cPanel & WHM Authentication Flaw Exposes Servers to Unauthorized Access

Updated 5d agoFirst seen Apr 28, 202664 sources

cPanel disclosed a critical login authentication vulnerability in cPanel & WHM that can allow unauthorized access to affected servers, and released fixes for supported versions on April 28, 2026. Public technical details remain limited and no CVE had been assigned at the time of disclosure, but changelog references tied the issue to session loading and saving under CPANEL-52908. The flaw affects multiple supported release tiers, and cPanel urged administrators to upgrade immediately.

Patched builds were issued for versions 110, 118, 126, 132, 134, and 136, while unsupported or end-of-life deployments are also considered likely at risk. The exposure is significant because WHM is used for server administration and cPanel manages individual hosting accounts, meaning successful exploitation could compromise both administrative and tenant access paths. Security teams were advised to rapidly inventory internet-facing cPanel assets, identify impacted versions, and prioritize emergency remediation across hosted environments.

Share:
Critical cPanel & WHM Authentication Flaw Exposes Servers to Unauthorized Access
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

21 events from the earliest known activity through the most recent confirmed update.

21 EVENTS
Feb 23, 20263mo ago

KnownHost observes CVE-2026-41940 exploitation attempts

KnownHost reported seeing successful exploitation of the cPanel & WHM authentication bypass before a fix was available, with execution attempts observed as early as 2026-02-23. This indicates the flaw was being exploited as a zero-day well before cPanel's public disclosure and patch release.

Critical cPanel and WHM bug exploited as a zero-day, PoC now available
Apr 28, 202620d ago

cPanel releases fixes for critical login authentication flaw

cPanel disclosed a critical login authentication vulnerability affecting multiple supported versions of cPanel & WHM and released patched builds for versions 110, 118, 126, 132, 134, and 136. The issue was described as potentially allowing unauthorized access to affected servers, with changelogs tying it to CPANEL-52908.

runZero publishes guidance to identify exposed cPanel & WHM assets

runZero published analysis and asset-discovery guidance following cPanel's disclosure, noting that public technical details were still limited and no CVE had yet been assigned. The post also warned that unsupported or end-of-life versions were likely affected and provided a query to help organizations find impacted systems.

Apr 29, 202619d ago

Namecheap blocks cPanel ports and begins deploying fixes

Following cPanel's disclosure, Namecheap said it temporarily blocked TCP ports 2083 and 2087 to limit access to cPanel and WHM while patches were rolled out. By 2026-04-29 02:42 UTC, it reported fixes had been applied to Reseller and Stellar Business servers, with remaining systems also being addressed.

Critical cPanel Authentication Vulnerability Identified - Update Your Server Immediately

cPanel WHM flaw assigned CVE-2026-41940 amid in-the-wild exploitation

By 2026-04-29, reporting on cPanel's critical WHM authentication bypass identified the issue as CVE-2026-41940 and said it had been exploited in the wild before patches were released. The flaw was described as affecting nearly all known cPanel and WHM versions, including some end-of-life releases, with risk of administrative server compromise.

cPanel released a patch for a WebHost Manager (WHM) authentication bypass bug | Expel

Cyber Centre flags cPanel advisory affecting WP Squared

Canada's Cyber Centre published advisory AV26-404 noting that cPanel's April 28, 2026 security advisory addressed vulnerabilities in both cPanel software and WP Squared. It listed affected versions including WP Squared 11.136.1.7 and urged administrators to review cPanel guidance and apply updates.

cPanel security advisory (AV26-404) - Canadian Centre for Cyber Security

watchTowr publishes CVE-2026-41940 technical analysis and PoC

watchTowr published a technical analysis and proof-of-concept exploit for CVE-2026-41940, the critical cPanel & WHM authentication bypass. The disclosure provided deeper detail on the CRLF injection flaw and raised concern that broader exploitation would follow.

CVE-2026-41940: cPanel & WHM Authentication Bypass

cPanel releases IOC detection script for CVE-2026-41940

cPanel published a detection script to help administrators identify possible exploitation of CVE-2026-41940 by scanning /var/cpanel/sessions for suspicious token patterns and malformed session attributes. The guidance accompanied mitigation advice for organizations unable to patch immediately.

CPanel CVE-2026-41940 Auth Bypass Flaw: Patch Now Fast!
Apr 30, 202618d ago

CISA adds CVE-2026-41940 to KEV catalog

CISA added CVE-2026-41940, affecting WebPros cPanel & WHM and WP2/WordPress Squared, to its Known Exploited Vulnerabilities catalog. The KEV entry set a remediation due date of 2026-05-03 and directed organizations to apply vendor mitigations, follow BOD 22-01 guidance for cloud services, or discontinue use if mitigations are unavailable.

Add Updated KEV Files for 2026-04-30 · cisagov/kev-data@bf15ab0 · GitHub

Cato Networks publishes IPS signatures and IOCs for CVE-2026-41940

On 2026-04-30, Cato Networks said it observed exploitation attempts targeting CVE-2026-41940 and released IPS signatures for virtual patching along with network indicators linked to infrastructure geolocated to Ireland, Japan, and the United States. The disclosure added new defender-focused detection content beyond earlier vendor advisories and cPanel's own IOC script.

Threat Brief: CVE-2026-41940: Critical cPanel & WHM Authentication Bypass Actively Exploited in the Wild | Cato Networks

HostGator takes defensive action against CVE-2026-41940

By 2026-04-30, reporting indicated that hosting provider HostGator had joined other providers in responding to CVE-2026-41940 by restricting cPanel/WHM access and applying patches. This added HostGator as a newly disclosed affected responder to the in-the-wild exploitation of the flaw.

Hackers are actively exploiting a bug in cPanel, used by millions of websites | TechCrunch
May 1, 202617d ago

Censys reports mass compromise wave hitting exposed cPanel/WHM hosts

On 2026-05-01, Censys linked a sharp increase of more than 15,000 newly maliciously classified internet hosts to exploitation targeting cPanel/WHM systems after disclosure of CVE-2026-41940. The company said the activity included at least two post-compromise paths—Mirai-related malware and ransomware appending a ".sorry" extension—indicating large-scale automated exploitation was ongoing.

The cPanel situation is… - Censys
May 2, 202616d ago

cPanelSniper exploit framework for CVE-2026-41940 is publicly released

On 2026-05-02, reporting said security researcher Mitsec published cPanelSniper, a weaponized GitHub exploit framework for CVE-2026-41940 that automates session forgery, bulk scanning, shell access, and post-exploitation actions. The release marked a new escalation beyond earlier technical analysis and PoC disclosures by making a more operational attack tool publicly available.

cPanelSniper - PoC Exploit Disclosed for cPanel Vulnerability, 44,000 Servers Compromised

South-East Asian military entities reported targeted via CVE-2026-41940

Ctrl-Alt-Intel reported that South-East Asian military entities were targeted through exploitation of CVE-2026-41940 in cPanel. This appears to be a newly disclosed victim/campaign development beyond the previously documented mass exploitation and public exploit releases.

South-East Asian Military Entities Targeted via cPanel (CVE-2026-41940) - Ctrl-Alt-Intel

Researchers detail Indonesian defense portal breach tied to CVE-2026-41940

On 2026-05-02, researchers disclosed that a campaign exploiting CVE-2026-41940 also compromised an Indonesian defense-sector training portal using valid credentials, CAPTCHA bypass, SQL injection, and PostgreSQL COPY TO PROGRAM for command execution. The intrusion reportedly enabled internal pivoting and exfiltration of 110 files totaling about 4.37 GB, including sensitive Chinese railway documents and personal data.

Hackers Breach Government and Military Servers by Exploiting cPanel Vulnerability

Unknown actor targets MSP and hosting networks with CVE-2026-41940

Ctrl-Alt-Intel reported on 2026-05-02 that a previously unknown threat actor exploited CVE-2026-41940 to target government and military entities in Southeast Asia, especially in the Philippines and Laos, as well as MSPs and hosting providers in multiple countries. The activity reportedly used public PoC code and post-compromise tooling including AdapdixC2, OpenVPN, Ligolo, and systemd persistence, expanding the known campaign beyond earlier military-focused reporting.

Critical cPanel Vulnerability Weaponized to Target Government and MSP Networks
May 4, 202614d ago

Shadowserver reports 44,000 likely compromised cPanel/WHM IPs

By 2026-05-04, Shadowserver Foundation reported more than 572,000 exposed cPanel/WHM instances worldwide and said over 44,000 IPs were likely already compromised amid exploitation of CVE-2026-41940. The figures provided a new global estimate of exposure and impact beyond earlier reports of scanning and mass exploitation.

Critical vulnerability in cPanel leads to widespread exploitation | Cybersecurity Dive
May 6, 202612d ago

Rapid7 opens Metasploit exploit module PR for CVE-2026-41940

A Rapid7 Metasploit Framework pull request was opened to add an exploit module for the cPanel/WHM authentication bypass RCE tracked as CVE-2026-41940. The public PR indicated work was underway to integrate exploitation into Metasploit, marking a new stage in commoditization of the flaw.

Add exploit for cPanel/WHM auth bypass RCE (CVE-2026-41940) by jburgess-r7 · Pull Request #21417 · rapid7/metasploit-framework · GitHub
May 11, 20267d ago

XLab attributes CVE-2026-41940 backdoor campaign to Mr_Rot13

On 2026-05-11, Qianxin XLab linked ongoing exploitation of CVE-2026-41940 to a threat cluster it calls "Mr_Rot13" and described a Go-based malware family used after compromise. The report said the operators changed root passwords, implanted SSH keys, installed PHP webshells and credential-stealing JavaScript, exfiltrated data to attacker infrastructure and Telegram, and deployed a cross-platform remote-control trojan named "filemanager."

Threat Actor Mr_Rot13 Actively Exploits CVE-2026-41940 for Backdoor Deployment
May 12, 20266d ago

Macnica reports 194 exposed cPanel/WHM servers in Japan hit by Sorry ransomware

Macnica’s Security Research Center said 194 of 1,692 publicly exposed cPanel/WHM servers in Japan had been compromised with Sorry ransomware amid exploitation of CVE-2026-41940. The disclosure provided a new country-specific impact assessment beyond earlier general reporting on ransomware activity tied to the flaw.

Stealthy hackers exploit cPanel flaw in active backdoor campaign (CVE-2026-41940) - Help Net Security
May 13, 20265d ago

Cyber Centre flags new cPanel and WP Squared security advisory

On 2026-05-13, Canada's Cyber Centre published advisory AV26-464 after cPanel issued new security advisories for cPanel & WHM and WP Squared. The notice said affected cPanel & WHM versions were those prior to multiple fixed releases, referenced WP Squared 11.136.1.12, and urged administrators to review cPanel guidance and apply updates.

cPanel security advisory (AV26-464) - Canadian Centre for Cyber Security
SOURCE COVERAGE

Sources

50 references tracked. Mallory keeps watching after this page renders.

50 SOURCESView all
Ca CcsNews
May 13, 2026

cPanel security advisory (AV26-464) - Canadian Centre for Cyber Security

cyber.gc.ca

Open source
ScworldNews
May 12, 2026

Threat actor Mr_Rot13 exploits critical cPanel flaw to deploy Filemanager backdoor | brief | SC Media

scworld.com

Open source
Security AffairsNews
May 12, 2026

Attackers exploit cPanel CVE-2026-41940 to deploy Filemanager Backdoor

securityaffairs.com

Open source
Secpod BlogNews
May 12, 2026

Filemanager Fever: MrRot_13’s cPanel Exploitation Campaign Is Spreading Fast - SecPod Blog

secpod.com

Open source
Belgium Ccb Security AdvisoriesNews
May 12, 2026

Warning: Multiple vulnerabilities in cPanel and WHM, leading to privilege escalation, Patch Immediately! | CCB Belgium

ccb.belgium.be

Open source
Help Net SecurityNews
May 12, 2026

Stealthy hackers exploit cPanel flaw in active backdoor campaign (CVE-2026-41940) - Help Net Security

helpnetsecurity.com

Open source
The Hacker NewsNews
May 11, 2026

cPanel CVE-2026-41940 Under Active Exploitation to Deploy Filemanager Backdoor

thehackernews.com

Open source
Qianxin Xlab BlogNews
May 11, 2026

秘密活动6年的神秘黑客组织Mr_Rot13正在利用cPanel高危漏洞部署后门木马

blog.xlab.qianxin.com

Open source
Qianxin Xlab BlogNews
May 11, 2026

Threat Actor Mr_Rot13 Actively Exploits CVE-2026-41940 for Backdoor Deployment

blog.xlab.qianxin.com

Open source
ScworldNews
May 7, 2026

Getting Rid of Your VPN - Rob Allen - PSW #925 | SC Media

scworld.com

Open source
Metasploit Pull RequestsNews
May 6, 2026

Add exploit for cPanel/WHM auth bypass RCE (CVE-2026-41940) by jburgess-r7 · Pull Request #21417 · rapid7/metasploit-framework · GitHub

github.com

Open source
Security AffairsNews
May 4, 2026

Hackers target governments and MSPs via critical cPanel flaw CVE-2026-41940

securityaffairs.com

Open source
The Hacker NewsNews
May 4, 2026

Critical cPanel Vulnerability Weaponized to Target Government and MSP Networks

thehackernews.com

Open source
Cyber Security NewsNews
May 4, 2026

CISA Warns of cPanel & WHM Vulnerability Exploited in Attacks

cybersecuritynews.com

Open source
Dark ReadingNews
May 4, 2026

Exploit Cyber-Frenzy Threatens Millions via Critical cPanel Vulnerability

darkreading.com

Open source
Techcrunch Com SecurityNews
May 4, 2026

Hackers are mass-exploiting the cPanel bug to gain control of thousands of websites | TechCrunch

techcrunch.com

Open source
Cybersecurity DiveNews
May 4, 2026

Critical vulnerability in cPanel leads to widespread exploitation | Cybersecurity Dive

cybersecuritydive.com

Open source
Security AffairsNews
May 3, 2026

U.S. CISA adds a flaw in WebPros cPanel to its Known Exploited Vulnerabilities catalog

securityaffairs.com

Open source
CatonetworksNews
May 2, 2026

Threat Brief: CVE-2026-41940: Critical cPanel & WHM Authentication Bypass Actively Exploited in the Wild | Cato Networks

catonetworks.com

Open source
Cyber Security NewsNews
May 2, 2026

Hackers Breach Government and Military Servers by Exploiting cPanel Vulnerability

cybersecuritynews.com

Open source
Cyber Security NewsNews
May 2, 2026

cPanelSniper - PoC Exploit Disclosed for cPanel Vulnerability, 44,000 Servers Compromised

cybersecuritynews.com

Open source
DarkwebinformerNews
May 2, 2026

The cPanel Situation Is Spiraling Fast

darkwebinformer.com

Open source
UnclassifiedNews
May 2, 2026

South-East Asian Military Entities Targeted via cPanel (CVE-2026-41940) - Ctrl-Alt-Intel

ctrlaltintel.com

Open source
Censys BlogNews
May 1, 2026

The cPanel situation is… - Censys

censys.com

Open source
Bank Info SecurityNews
May 1, 2026

Attacks Surge Against Vulnerable cPanel and WHM Software

bankinfosecurity.com

Open source
Register SecurityNews
May 1, 2026

Critical cPanel exploited: 'Millions' of sites could be hit • The Register

go.theregister.com

Open source
The Record MediaNews
May 1, 2026

Federal agencies must patch cPanel bug by Sunday, CISA says | The Record from Recorded Future News

therecord.media

Open source
Register SecurityNews
May 1, 2026

Critical cPanel exploited: 'Millions' of sites could be hit

theregister.com

Open source
ScworldNews
Apr 30, 2026

Critical cPanel vulnerability actively exploited in the wild | brief | SC Media

scworld.com

Open source
CyberscoopNews
Apr 30, 2026

cPanel's authentication bypass bug is being exploited in the wild, CISA warns | CyberScoop

cyberscoop.com

Open source
Socprime BlogNews
Apr 30, 2026

CVE-2026-41940: cPanel & WHM Auth Bypass Flaw

socprime.com

Open source
Cyber Security NewsNews
Apr 30, 2026

cPanel 0-Day Authentication Bypass Vulnerability Actively Exploited in the Wild - PoC Released

cybersecuritynews.com

Open source
Thecyberexpress Com VulnerabilitiesNews
Apr 30, 2026

CPanel CVE-2026-41940 Auth Bypass Flaw: Patch Now Fast!

thecyberexpress.com

Open source
Reddit NetsecCommunity
Apr 30, 2026

High Fidelity Check for the cPanel Authentication Bypass (CVE-2026-41940) : r/netsec

reddit.com

Open source
Cisa AdvisoriesAdvisories
Apr 30, 2026

CISA Adds One Known Exploited Vulnerability to Catalog | CISA

cisa.gov

Open source
Help Net SecurityNews
Apr 30, 2026

cPanel zero-day exploited for months before patch release (CVE-2026-41940) - Help Net Security

helpnetsecurity.com

Open source
Belgium Ccb Security AdvisoriesNews
Apr 30, 2026

Warning: Critical authentication bypass in cPanel & WHM, Patch Immediately! | CCB Belgium

ccb.belgium.be

Open source
Cpanel Product AdvisoriesNews
Apr 30, 2026

Security: CVE-2026-41940 - cPanel & WHM / WP2 Security Update 04/28/2026 - cPanel

support.cpanel.net

Open source
Cisa Kev Data CommitsAdvisories
Apr 30, 2026

Add Updated KEV Files for 2026-04-30 · cisagov/kev-data@bf15ab0 · GitHub

github.com

Open source
Techcrunch Com SecurityNews
Apr 30, 2026

Hackers are actively exploiting a bug in cPanel, used by millions of websites | TechCrunch

techcrunch.com

Open source
Bleeping ComputerNews
Apr 30, 2026

Critical cPanel and WHM bug exploited as a zero-day, PoC now available

bleepingcomputer.com

Open source
Cert At Security AdvisoriesAdvisories
Apr 30, 2026

CERT.at Authentication Bypass in cPanel & WHM

cert.at

Open source
Register SecurityNews
Apr 30, 2026

Critical cPanel, WHM flaw probs exploited as 0-day, pros say

theregister.com

Open source
Register SecurityNews
Apr 30, 2026

Critical cPanel, WHM flaw probs exploited as 0-day, pros say • The Register

go.theregister.com

Open source
Ca CcsNews
Apr 29, 2026

AL26-008 - Vulnerability affecting cPanel and WebHost Manager (WHM) - CVE-2026-41940 - Canadian Centre for Cyber Security

cyber.gc.ca

Open source
Expel BlogNews
Apr 29, 2026

cPanel released a patch for a WebHost Manager (WHM) authentication bypass bug | Expel

expel.com

Open source
Ca CcsNews
Apr 29, 2026

cPanel security advisory (AV26-404) - Canadian Centre for Cyber Security

cyber.gc.ca

Open source
AttackerkbNews
Apr 29, 2026

CVE-2026-41940 | AttackerKB

attackerkb.com

Open source
Security AffairsNews
Apr 29, 2026

All supported cPanel versions hit by critical auth bug, now patched

securityaffairs.com

Open source
The Hacker NewsNews
Apr 29, 2026

Critical cPanel Authentication Vulnerability Identified - Update Your Server Immediately

thehackernews.com

Open source
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Critical cPanel & WHM Authentication Flaw Exposes Servers to Unauthorized Access | Mallory