• News/
  • https://www.bleepingcomputer.com/news/security/critical-cpanel-and-whm-bug-exploited-as-a-zero-day-poc-now-available/

Critical cPanel and WHM bug exploited as a zero-day, PoC now available

BleepingComputer
·
Bill Toulas
·
Published Apr 30, 2026
·
Updated

The critical CVE-2026-41940 authentication bypass vulnerability in cPanel, WHM, and WP Squared is being actively exploited in the wild and has been leveraged in attempts since late February. It is unclear when exploitation started, but KnownHost, a hosting provider that uses cPanel, said the day the vulnerability was disclosed that "successful exploits have been seen in the wild" before a fix became available. However, KnownHost CEO Daniel Pearson stated that the company has "seen execution attempts as early as 2/23/2026." Newly published technical details, which can be used to develop an exploit, reveal that the issue is a "Carriage Return Line Feed (CRLF) injection in the login and session loading processes of cPanel & WHM." cPanel released a fix on April 28, following pressure from hosting providers. To protect customers, Namecheap temporarily blocked connections to cPanel and WHM ports 2083 and 2087 until patches became available. A report from offensive security company watchTowr explains that the flaw is caused by improper session handling in cPanel & WHM, where user-controlled input from the Authorization header is written into server-side session files before authentication and without proper sanitization. watchTowr researchers also published a detailed analysis on how the bug can be triggered to log into the system without validating the provided password, which can be used to develop a working exploit. According to Rapid7, Shodan internet scans show that there are ...

Read full article

Affected Software

2 affected components
Cpanel Cpanel
Cpanel WHM
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a critical authentication bypass vulnerability in cPanel and WHM, identified as CVE-2026-41940, that is actively being exploited.

2

What security implications are discussed in the article?

The article highlights the risks associated with the exploitation of the vulnerability, which allows unauthorized access to affected systems.

3

What products or software are affected by this vulnerability?

The affected products include cPanel, WHM, and WP Squared.

4

Who is targeted by this zero-day vulnerability?

The zero-day vulnerability is targeting users of cPanel and WHM services.

5

What has been made available that relates to the exploitation of this bug?

A proof of concept (PoC) for the exploitation of the vulnerability has been made available.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203