CVE-2026-41940
cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.
- Published Apr 29, 2026
- CVSS 9.3 critical
- 98.5% chance of exploitation in the next 30 days (EPSS)
- In CISA's Known Exploited Vulnerabilities catalog
- A Metasploit module exploits it
Affected software
In the news
- Death By 20,000 PoCs VulnCheck Blog ·
- Quantifying 2026 Routinely Targeted Vulnerabilities (So Far) VulnCheck Blog ·