cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.
https://www.vulncheck.com/advisories/cpanel-and-whm-authentication-bypass-via-login-flow
https://support.cpanel.net/hc/en-us/articles/40073787579671-cPanel-WHM-Security-Update-04-28-2026
https://thehackernews.com/2026/08/critical-cpanel-flaw-could-let-one.html
https://securelist.com/vulnerabilities-and-exploits-in-q2-2026/121091/
https://thehackernews.com/2026/08/cisa-flags-langflow-rce-tomcat-and-n.html
https://thehackernews.com/2026/07/attackers-weaponize-github-actions.html
https://socket.dev/blog/github-actions-abuse-powers-cpanel-and-whm-exploitation
https://thehackernews.com/2026/05/litespeed-cpanel-plugin-cve-2026-48172.html
https://thehackernews.com/2026/05/cpanel-cve-2026-41940-under-active.html
https://thehackernews.com/2026/05/cpanel-whm-patch-3-new-vulnerabilities.html
https://www.securityweek.com/over-40000-servers-compromised-in-ongoing-cpanel-exploitation/
https://www.darkreading.com/threat-intelligence/exploit-cyber-frenzy-critical-cpanel-vulnerability
https://www.theregister.com/2026/05/01/critical_cpanel_vuln_hits_cisa/
https://www.databreachtoday.com/attacks-surge-against-vulnerable-cpanel-whm-software-a-31571
https://therecord.media/cisa-orders-federal-agencies-to-patch-cpanel-bug
https://www.theregister.com/2026/04/30/cpanel_whn_cves/
https://www.securityweek.com/critical-cpanel-whm-vulnerability-exploited-as-zero-day-for-months/
https://www.helpnetsecurity.com/2026/04/30/cpanel-zero-day-vulnerability-cve-2026-41940-exploited/
https://cyberscoop.com/cpanel-authentication-bypass-vulnerability-cve-2026-41940-exploited/
https://arcticwolf.com/resources/blog/cve-2026-41940/
https://thehackernews.com/2026/04/critical-cpanel-authentication.html
https://github.com/0xgh057r3c0n/CVE-2026-41940
https://github.com/lanicer/cve-2026-41940-PoC
https://github.com/pemarine/cve-2026-41940-PoC
https://github.com/yanchenyu360/CVE-2026-41940-Security-Patch
https://github.com/keithbennedict/CVE-2026-41940-Linux
https://github.com/CerberusMrXi/cPanel-WHM-CVE-2026-41940-auth-bypass-exploit
https://github.com/tc4dy/CVE-2026-54121-PoC-Exploit
https://github.com/tc4dy/CVE-2026-60206-PoC-Exploit
https://github.com/AnotherSec/CVE-2026-41940
https://github.com/tc4dy/CVE-2026-6875-PoC-Exploit
https://github.com/the-artist111/NeuralReaper
https://github.com/oguz-kagan-akar/CVE-2026-41940-analysis
https://github.com/Byungju/cve-research-lab
https://github.com/tc4dy/CVE-2026-41091-PoC-Exploit
https://github.com/limo57640-crypto/limo57640-crypto
https://github.com/asdasddqwdq29-a11y/CVE-2026-41940
https://github.com/tc4dy/CVE-2026-24061-PoC-Exploit
https://github.com/yurahshell/CVE-2026-41940
https://github.com/rain-fly/linux-privesc-cves
https://github.com/willygailo/CVE-2026-41940-Linux
https://github.com/gilangnuradha-debug/CVE---EXPLOIT
https://github.com/sardine-web/Automated-scanner-CVE-2026-41940
https://github.com/BlackRainSentinel/cPanel-patch-radar
https://github.com/samarthop2011/cve2026
https://github.com/bob-reis/claude-pentest-skills
https://github.com/limo57640-crypto/cpanel-cve-41940-detector
https://github.com/tc4dy/CVE-2026-0073-PoC-Exploit
https://github.com/tc4dy/CVE-2026-41940-PoC-Exploit
https://github.com/zycoder0day/CVE-2026-41940
https://github.com/anach-ai/CVE-2026-41940
https://github.com/ngksiva/cpanel-forensics
https://github.com/44pie/cpsniper
https://github.com/SreejaPuthan/cpanel-control-plane-exposure-check
https://github.com/acuciureanu/cpanel2shell-honeypot
https://github.com/thekawix/CVE-2026-41940
https://github.com/OhmGun/whmxploit---CVE-2026-41940
https://github.com/bughunt4me/cpanelCVE-2026-41940
https://github.com/bughunt4me/cpanelCVE
https://github.com/Richflexpix/cpanel-pwn
https://github.com/Unfold-Security/CVE-2026-41940-Detection
https://github.com/ZildanZ/CVE-2026-41940
https://github.com/itsismarcos/CVE-2026-41940
https://github.com/iSee857/cPanel-WHM-CVE-2026-41940-AuthBypass
https://github.com/nickpaulsec/2026-41940-poc
https://github.com/sercanokur/CVE-2026-41940-cPanel-WHM-Verification-Tool
https://github.com/Jovicaa/CVE-2026041940-IoC-forensics-instructions
https://github.com/Underh0st/CPanel-Audit-Remediation-Tool
https://github.com/tahaXafous/CVE_2026_41940_scan_exploit
https://github.com/imbas007/POC_CVE-2026-41940
https://github.com/linko-iheb/cve-2026-41940-scanner
https://github.com/3tternp/CVE-2026-41940---cPanel-WHM-check
https://github.com/dennisec/CVE-2026-41940
https://github.com/MrAriaNet/cPanel-Fix
https://github.com/AmirrezaMarzban/portscan-CVE-2026-41940
https://github.com/vineet7800/cpanel-malware-cleaner-cve-2026
https://github.com/devtint/CVE-2026-41940
https://github.com/0xBlackash/CVE-2026-41940
https://github.com/Jenderal92/CVE-2026-41940
https://github.com/kmaruthisrikar/CVE-2026-41940-cPanel-Auth-Bypass-Exploit
https://github.com/0dev1337/cpanelscanner
https://github.com/sebinxavi/cve-checker-2026
https://github.com/ynsmroztas/cPanelSniper
https://github.com/Lutfifakee-Project/CVE-2026-41940
https://github.com/cyber-green/CVE_REPORT_2026
https://github.com/Erdemcey/CVE_Analizleri
https://github.com/mahfuzreham/cpanel-cve-2026-41940
https://github.com/senyx122/CVE-2026-41940
https://github.com/george1-adel/CVE-2026-41940_exploit
https://github.com/shahidmallaofficial/cpanel-cve-2026-41940-fix
https://github.com/0xabdoulaye/CPANEL-CVE-2026-41940
https://github.com/rfxn/cpanel-sessionscribe
https://github.com/sedatyildiznet/cve-audit
https://github.com/sedatabase/cve-audit
https://github.com/ilmndwntr/CVE-2026-41940-MASS-EXPLOIT
https://github.com/assetnote/cpanel2shell-scanner
https://github.com/Wesuiliye/CVE-2026-41940
https://github.com/Sachinart/CVE-2026-41940-cpanel-0day
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-41940
https://docs.wpsquared.com/changelogs/versions/changelog/#13617
Published: 2026-04-29
Updated: 2026-05-04
Known Exploited Vulnerability (KEV)
Base Score: 10
Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C
Severity: Critical
Base Score: 9.8
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity: Critical
Base Score: 9.3
Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Severity: Critical
EPSS: 0.98527
Tenable Research has classified this CVE under the following Vulnerability Watch classification, which includes active and historical (inactive) classifications. You can learn more about these classifications on our blog.
Vulnerability of Interest