• News/
  • https://www.theregister.com/2026/04/30/cpanel_whn_cves/

Critical cPanel, WHM flaw probs exploited as 0-day, pros say

The Register
·
Connor Jones
·
Published Apr 30, 2026
·
Updated

Emergency patches are available for a critical vulnerability in cPanel and WHM that allows attackers to bypass authentication and gain root access to servers managed using it. Given that cPanel and WebHost Manager (WHM) control panel help manage properties for  70 million domains, by some estimates, and the critical severity of CVE-2026-41940 (9.8), the vulnerability is being considered a disaster by those in the security scene. It also affects every single supported version of the software prior to the patch. For the uninitiated, cPanel and WHM are both Linux-based control panels. The former is used to manage websites, databases, file transfers, email configurations, and domains, while WHM is used for servers. They are both backbones of the internet. Breaking into them would provide an attacker with unfettered access to all the secrets associated with these functions. Or, as watchTowr put it: "Think of it as the keys to the kingdom, and then the keys to every individual apartment inside the kingdom. If the kingdom were the internet and the apartments were websites. For everything." Perhaps the worst part is that early signals from defenders, such as KnownHost CEO Daniel Pearson, suggest it may have been exploited as a zero-day for at least 30 days. Or maybe worse still is the nature of the vulnerability itself – that attackers can gain root access while bypassing all kinds of authentication – a feat worthy of the near-maximum CVSS. The vulnerability also affects WP Squared, ...

Read full article

Affected Software

3 affected components
Cpanel Cpanel
Cpanel WebHost Manager (WHM)
Cpanel WP Squared
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a critical vulnerability in cPanel and WHM that allows attackers to bypass authentication and gain root access.

2

What security implications are discussed in the article?

The article highlights the risk of unauthorized access to servers, which could lead to data breaches and server hijacking.

3

What software is affected by this vulnerability?

The affected software includes cPanel and WebHost Manager (WHM), along with additional products like WP Squared.

4

What measures are recommended in response to the vulnerability?

Emergency patches have been released to address the critical vulnerability and should be applied immediately.

5

How can users protect themselves from this vulnerability?

Users are advised to update their cPanel and WHM installations promptly to mitigate the security risks associated with this flaw.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203