WebPros cPanel

8 known vulnerabilities in WebPros cPanel, 6 critical, 1 actively exploited, with patch priority, exploit likelihood and the news covering them.

Recently exploited

  • CVE-2026-41940 CVSS 9.3 critical · actively exploited WebPros cPanel & WHM and WP2 (WordPress Squared) Missing Authentication for Critical Function Vulnerability

Latest vulnerabilities

  • CVE-2026-93698 CVSS 9.9 critical Insufficient validation allows arbitrary commands to be executed via the Multilang adminbin.
  • CVE-2026-93697 CVSS 9.0 critical There is a stored XSS vulnerability allowing arbitrary code execution in the WHM Mass Modify Accounts interface.
  • CVE-2026-93029 CVSS 9.0 critical There is a stored XSS vulnerability allowing arbitrary code execution in the WHM Manage SSL Hosts interface.
  • CVE-2026-87899 CVSS 9.4 critical Execution with unnecessary privileges in cPanel allows remote authenticated users to execute arbitrary code with root privileges.
  • CVE-2026-68490 CVSS 8.2 high Incorrect permission assignment allows local users to obtain sensitive CalDAV/CardDAV information belonging to other accounts.
  • CVE-2026-67401 CVSS 9.9 critical A vulnerability in cPanel allows a mail-enabled account to achieve remote code execution as root through SQLi in EmailTrack component
  • CVE-2026-65643 CVSS 8.7 high Eval injection in cPanel 11.138.0.0 and earlier allows remote authenticated users to execute arbitrary code as root.
  • CVE-2026-41940 CVSS 9.3 critical · actively exploited WebPros cPanel & WHM and WP2 (WordPress Squared) Missing Authentication for Critical Function Vulnerability