Critical cPanel CVE-2026-41940 Vulnerability Under Active Exploitation
A critical vulnerability (CVSS 9.8) in cPanel and WebHost Manager (WHM) is under active exploitation, allowing unauthenticated remote attackers to bypass authentication and gain full server control.
Key Details
- CVE ID: CVE-2026-41940
- CVSS Score: 9.8 (Critical)
- Affected Products: cPanel and WebHost Manager (WHM)
- Status: Under active exploitation before patches landed
- Impact: Millions of websites potentially exposed
- Mitigation: Emergency patches released for those managing the millions of domains
CISA has added this vulnerability to its Known Exploited Vulnerabilities catalog. This is being called the “Bug of the year (so far)” with exploitation underway before patches landed, with at least one victim reporting a ransomware demand.