CPANEL ZERO-DAY ACTIVELY EXPLOITED, POC RELEASED
AI DESK■ 2 MIN READ
THU, APR 30, 2026■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE
A critical authentication bypass vulnerability in cPanel, WHM, and WP Squared is being actively exploited in the wild since late February. A proof-of-concept is now publicly available.
The Vulnerability
CVE-2026-41940 is a critical authentication bypass flaw affecting cPanel, WHM, and WP Squared. The vulnerability allows attackers to circumvent authentication mechanisms, potentially granting unauthorized access to hosting control panels and administrative functions.
Active Exploitation
Security researchers have confirmed active exploitation attempts dating back to late February. The release of a public proof-of-concept has significantly expanded the attack surface, enabling a broader range of threat actors to leverage the flaw.
Risk Assessment
The combination of a critical severity rating and public exploit code creates an urgent threat landscape. Organizations running affected versions face elevated risk of unauthorized access, data breaches, and potential lateral movement within hosting infrastructure.
Affected Systems
The vulnerability impacts multiple cPanel and WHM versions. WP Squared installations are also vulnerable. Administrators should immediately identify and inventory affected systems across their infrastructure.
Recommended Actions
Organizations should prioritize patching to the latest available versions. Interim mitigations may include restricting access to administrative interfaces, monitoring authentication logs for suspicious activity, and implementing network-level controls on management ports.
Timeline
While initial exploitation attempts occurred in late February, the public release of proof-of-concept code has accelerated the threat timeline. The window for remediation has narrowed considerably.
cPanel and WHM administrators should treat this as a critical priority and coordinate patching across their infrastructure immediately. The availability of public exploit code means this vulnerability will likely see widespread exploitation efforts in the coming days.
■ MORE FROM THE SECURITY DESK
Cybercriminals have transformed DDoS attacks into a polished, commercialized service complete with pricing tiers, customer support, and reseller programs. The DDoS-as-a-Service market has evolved from basic tools into sophisticated attack platforms.
14H AGO— Industry Desk
Microsoft faced backlash after threatening a security researcher with criminal investigation, reigniting debate over software vulnerability disclosure practices and corporate responsibility.
14H AGO— Security Desk
Google is deploying Device Bound Session Credentials (DBSC) to all Chrome users, a security feature designed to prevent account takeovers by protecting session cookies from theft.
14H AGO— Industry Desk
Dutch authorities have dismantled a major botnet comprising 17 million infected devices and seized over 200 servers hosting the operation at a local provider.
14H AGO— Security Desk