cPanel disclosed and patched a critical authentication bypass in cPanel & WHM, tracked as CVE-2026-41940, after reports of active in-the-wild exploitation against hosting infrastructure. The flaw affects authentication paths in supported versions and can let unauthenticated attackers reach administrative interfaces, forge authenticated sessions, and potentially gain control of hosted websites, databases, email accounts, and server configuration. Government and industry alerts warned that shared hosting environments face outsized risk because a single compromised server can expose many downstream customer sites, and some providers temporarily restricted cPanel and WHM login ports while applying fixes.
Public technical analysis and a GitHub proof-of-concept described an exploit chain involving manipulated HTTP headers and session cookie handling to create forged privileged sessions, including possible root-level WHM access. Separately, cPanel also patched three additional vulnerabilities in cPanel & WHM and WP Squared—CVE-2026-29201, CVE-2026-29202, and CVE-2026-29203—that enable arbitrary file read through path traversal, Perl code injection leading to remote code execution, and denial-of-service via unsafe symlink handling. The most severe of the newly disclosed flaws, CVE-2026-29202, affects the create_user API and can allow arbitrary Perl code execution on the server, reinforcing calls for immediate upgrades, restricted access to management interfaces, and log review for suspicious authorization and cookie activity.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
9 events from the most recent confirmed update back to the earliest known activity.
After patching the May vulnerabilities, cPanel advised administrators to upgrade immediately to fixed releases across supported branches, including WP Squared 11.136.1.10 or later. The company highlighted the risk of lateral movement, privilege escalation, and full server compromise in shared hosting environments.
On May 8, 2026, cPanel patched three additional vulnerabilities: CVE-2026-29201, CVE-2026-29202, and CVE-2026-29203. The issues enabled arbitrary file read via path traversal, Perl code injection leading to remote code execution, and denial of service through unsafe symlink handling.
A GitHub repository named cPanelSniper was published describing and automating exploitation of CVE-2026-41940. The project outlined a session-file CRLF injection technique to obtain forged WHM access and included post-exploitation capabilities.
Public analysis from watchTowr described an authentication bypass chain involving insufficient sanitization of HTTP headers and insufficient validation of session cookies. The write-up explained how forged authenticated sessions could be created against vulnerable cPanel & WHM instances.
Following disclosure of CVE-2026-41940, major hosting providers including Namecheap and KnownHost temporarily blocked cPanel and WHM login ports until patches could be applied. This was a defensive response to ongoing exploitation risk.
Security reporting stated that CVE-2026-41940 was being actively exploited as a 0-day against hosting infrastructure in April 2026. Because cPanel is widely used in shared hosting, successful exploitation could expose many downstream customer sites on a single server.
On April 29, 2026, the Canadian Centre for Cyber Security issued Alert AL26-008 warning that exploitation of CVE-2026-41940 was highly probable. The alert urged immediate patching, restricting access to management interfaces, and reviewing logs for suspicious activity.
cPanel disclosed the critical authentication bypass vulnerability CVE-2026-41940 affecting supported cPanel & WHM versions and released patched versions at disclosure. The flaw could allow unauthenticated attackers to access administrative interfaces and compromise hosted websites, databases, email accounts, and server settings.
A separate advisory about remote code execution in CentOS Web Panel (CVE-2025-70951) was published by Fenrisk. It is unrelated to the cPanel/WHM vulnerabilities and does not materially advance this story.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
6 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcegithub.com
Open sourcelinkedin.com
Open sourcecyber.gc.ca
Open sourcelabs.beazley.security
Open sourcefenrisk.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.