peter bassill · operator
$ cve CVE-2026-41940 JSON

CVE-2026-41940 KEV EXPLOIT

9.8
CRITICAL · CVSS 3.1 · EPSS 98.5% (pctl 100)

Patch first

On CISA KEV — known exploited in the wild, due 2026-05-03.

Description

cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS98.53% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-306
On CISA KEVyes — remediate by 2026-05-03
Public exploityes
Published2026-04-29
Last modified2026-06-17

CISA KEV

NameWebPros cPanel & WHM and WP2 (WordPress Squared) Missing Authentication for Critical Function Vulnerability
Added2026-04-30
Due2026-05-03
Vendor / productWebPros / cPanel & WHM and WP2 (WordPress Squared)
Ransomware useknown

Affected (3)

VendorProduct
cpanelcpanel
cpanelwhm
cpanelwp squared

Public exploits

SourceTitleDate
exploit-dbcPanel - CRLF Injection2026-05-26

References

→ the Explorer  ·  watch your stack  ·  NVD