CVE-2026-41940
Confirmed PUBLISHEDWebPros cPanel and WHM Authentication Bypass via Login Flow
1 day faster than CISA KEV
Recommended Action
Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
At a Glance
cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.
- CVE Published
- Apr 29, 2026
- Exploitation Reported
- Jun 01, 2026
- CVSS
- 9.3 Critical
- EPSS
- 98.1%
Affected Versions
| Vendor | Product | Version | Status |
|---|---|---|---|
| WebPros |
cPanel
|
11.40.0.0 to < 11.86.0.41 |
Affected |
| WebPros |
cPanel
|
11.88.0.0 to < 11.94.0.28 |
Affected |
| WebPros |
cPanel
|
11.96.0.0 to < 11.102.0.39 |
Affected |
| WebPros |
cPanel
|
11.104.0.0 to < 11.110.0.97 |
Affected |
| WebPros |
cPanel
|
11.112.0.0 to < 11.118.0.63 |
Affected |
| WebPros |
cPanel
|
11.120.0.0 to < 11.124.0.35 |
Affected |
| WebPros |
cPanel
|
11.126.0.0 to < 11.126.0.54 |
Affected |
| WebPros |
cPanel
|
11.128.0.0 to < 11.130.0.19 |
Affected |
| WebPros |
cPanel
|
11.132.0.0 to < 11.132.0.29 |
Affected |
| WebPros |
cPanel
|
11.134.0.0 to < 11.134.0.20 |
Affected |
| WebPros |
cPanel
|
11.136.0.0 to < 11.136.0.5 |
Affected |
| WebPros |
WP Squared
|
11.136.1.7 |
Unaffected |
| WebPros |
WHM
|
11.40.0.0 to < 11.86.0.41 |
Affected |
| WebPros |
WHM
|
11.88.0.0 to < 11.94.0.28 |
Affected |
| WebPros |
WHM
|
11.96.0.0 to < 11.102.0.39 |
Affected |
| WebPros |
WHM
|
11.104.0.0 to < 11.110.0.97 |
Affected |
| WebPros |
WHM
|
11.112.0.0 to < 11.118.0.63 |
Affected |
| WebPros |
WHM
|
11.120.0.0 to < 11.124.0.35 |
Affected |
| WebPros |
WHM
|
11.126.0.0 to < 11.126.0.54 |
Affected |
| WebPros |
WHM
|
11.128.0.0 to < 11.130.0.19 |
Affected |
| WebPros |
WHM
|
11.132.0.0 to < 11.132.0.29 |
Affected |
| WebPros |
WHM
|
11.134.0.0 to < 11.134.0.20 |
Affected |
| WebPros |
WHM
|
11.136.0.0 to < 11.136.0.5 |
Affected |
CVE References
- Vendor Advisory — support.cpanel.net support.cpanel.net · Vendor Advisory https://support.cpanel.net/hc/en-us/articles/40073787579671-cPanel-WH...
- Third-Party Advisory — namecheap.com namecheap.com · Third-Party Advisory https://www.namecheap.com/status-updates/ongoing-critical-security-vu...
- Third-Party Advisory — vulncheck.com vulncheck.com · Third-Party Advisory https://www.vulncheck.com/advisories/cpanel-and-whm-authentication-by...
- Release Notes — docs.cpanel.net docs.cpanel.net · Release Notes https://docs.cpanel.net/release-notes/release-notes
- Release Notes — docs.wpsquared.com docs.wpsquared.com · Release Notes https://docs.wpsquared.com/changelogs/versions/changelog/#13617
Recommended Actions
- Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
- Check enrichment artifacts for scanner coverage and available PoCs before rolling remediation validation.
- Use the Pro API to automate enrichment, telemetry, and workflow delivery for VM, SOC, and CTI pipelines.
Known Exploited Vulnerability Sources
Catalogues that list this CVE as a known exploited vulnerability.
Per-source evidence links for KEV attestations are available through the KEVIntel Pro API.
Learn about Pro API access| Source | Added |
|---|---|
| The Shadowserver First | 2026-06-01 00:00 UTC |
| CVE | 2026-06-01 13:26 UTC |
| CISA | 2026-06-02 14:01 UTC |
| Daily CyberSecurity | 2026-06-08 13:20 UTC |
| Tenable Blog | 2026-07-20 13:36 UTC |
Scanner Artifacts
Nuclei and Metasploit references linked to this CVE.
| Scanner | Reference | Detected |
|---|---|---|
| Nuclei | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-41940.yaml | Jun 01, 2026 |
Virtual Patch
Compensating WAF rules to help reduce exposure to this CVE. Rule content and deployable vendor exports are available with KEVIntel Enterprise.
KEVIntel does not currently have a virtual patch for this CVE. When available, KEVIntel virtual patches ship as deployable ModSecurity, Cloudflare, and AWS WAF rules.
Enterprise feature. Virtual patch rule content and deployable vendor exports (ModSecurity, Cloudflare, AWS WAF) are available to KEVIntel Enterprise users.
CVSS Scores
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitation Status
Exploited in the wild
Recorded 2026-06-01 13:26:04 UTC · CVE
Used in malware
Recorded 2026-06-02 14:01:12 UTC · CVE
Proof of concept available
Recorded 2026-05-06 18:08:48 UTC · GitHub
Weaknesses (CWE)
-
Missing Authentication for Critical Function
Scanner Integrations
| Scanner | Reference | Detected |
|---|---|---|
| Nuclei | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-41940.yaml | Jun 01, 2026 |
Recent Mentions
Tenable Blog · Jul 20, 2026
An unauthenticated attacker can chain two WordPress Core vulnerabilities, CVE-2026-63030 and CVE-2026-60137, to achieve remote code execution against affected WordPress installations. Multiple security firms have confirmed active in-the-wild exploitation within days of public disclosure, and public proof-of-concept exploits are circulating.Key takeaways:Two WordPress Core vulnerabilities, CVE-2026-63030 and CVE-2026-60137, can be chained together to achieve pre-authentication remote code execution against WordPress 6.9.x and 7.0.x installations. Multiple security firms have confirmed in-the-wild exploitation, with public proof-of-concept exploits appearing within hours of the July 17, 2026 disclosure. Patches are available in WordPress 7.0.2 and 6.9.5; WordPress.org has enabled forced automatic updates across affected supported installations. BackgroundTenable's Research Special Operations (RSO) team has compiled this blog to answer Frequently Asked Questions (FAQ) regarding wp2shell, two vulnerabilities in WordPress Core that can be chained together to achieve pre-authentication remote code execution.FAQWhat is wp2shell?wp2shell is the name given to two vulnerabilities in WordPress Core.When was wp2shell first disclosed?On July 17, 2026, WordPress released security updates addressing the wp2shell vulnerabilities alongside two GitHub Security Advisories. Adam Kues of Searchlight Cyber, who discovered and disclosed CVE-2026-63030, published research on the same day and chose to hold back the technical specifics given the severity of the finding. Searchlight Cyber also launched wp2shell.com, a testing tool that allows administrators to check whether their WordPress installation is vulnerable. On July 20, Searchlight Cyber published a full technical breakdown of the attack chain.What are the vulnerabilities associated with wp2shell?wp2shell is a two-vulnerability exploit chain affecting WordPress Core.CVEDescriptionCVSSv3CVE-2026-63030WordPress Core REST API...
Daily CyberSecurity · Jun 08, 2026
Critical Authentication Bypass Threatens Remote Access Deployments A serious security warning has been issued for corporate virtual private The post Check Point VPN Vulnerability Exploited in the Wild with Ransomware Links appeared first on Daily CyberSecurity. Related posts: Critical Warning: QNAP Patches Seven Zero-Days Exploited at Pwn2Own 2025 Critical Triofox Zero-Day (CVE-2025-12480) Under Active Exploit: Host Header Bypass Allows Unauthenticated Admin Takeover Exploited in the Wild: PoC Released for cPanel CVE-2026-41940 Authentication Bypass Zero-Day
Potential Proof of Concepts
These PoCs are unverified and could contain malware. Use at your own risk.
github · Created 2026-07-18 05:44:09 UTC · 0 stars
Technical analysis of the cPanel/WHM auth bypass
github · Created 2026-06-28 07:13:52 UTC · 0 stars
CVE-2026-41940 authentication bypass vulnerability proof-of-concept
github · Created 2026-06-16 17:49:03 UTC · 0 stars
CVE-2026-41940 exploitation proof-of-concept project
github · Created 2026-06-06 12:49:33 UTC · 0 stars
Redacted cPanel/WHM authentication bypass analysis and authorized checker
github · Created 2026-06-05 21:20:32 UTC · 0 stars
github · Created 2026-06-04 17:17:49 UTC · 116 stars
CVE-2026-41940 is a critical authentication bypass vulnerability affecting cPanel and WHM. This repository is designed to demonstrate its Proof-Of-Concept
github · Created 2026-05-27 00:16:57 UTC · 1 stars
⚠️ DISCLAIMER: This tool is intended for authorized penetration testing and educational purposes only. Using this tool against systems without explicit written permission is illegal. The developers are not responsible for any misuse or damage caused.
github · Created 2026-05-24 11:10:55 UTC · 1 stars
Automated scanner & post-exploitation toolkit for CVE-2026-41940 — cPanel & WHM root authentication bypass via session-file CRLF injection
github · Created 2026-05-12 14:47:21 UTC · 1 stars
🚀 CVE-2026-41940 cPanel/WHM Auth Bypass Exploit - Best Flow 💥 CRLF injection leads to auth bypass, session hijacking & account leak. ✅ Proxy, custom UA, keep-alive, retries, SSL verify, colored output, file save support. ⚡ Advanced PoC for pentesters.
github · Created 2026-05-06 18:08:48 UTC · 0 stars
Test authentication bypass vulnerabilities in cPanel and WHM using this proof of concept exploit tool written in Go.
github · Created 2026-05-01 15:43:28 UTC · 4 stars
Bulk scanner and mass exploitation tool for CVE-2026-41940 on cPanel/WHM, built for automated target validation and high-speed multi-threaded execution.
github · Created 2026-05-01 00:17:32 UTC · 2 stars
nuclei · Created Unknown
Timeline
Key exploitation, disclosure, scanner coverage, and KEV attestation events for this CVE.
-
13:36 UTC 1 day ago13:36 UTC · 1 day ago
KEV confirmed by Tenable Blog
Exploitation attested by an external source
-
13:20 UTC about 1 month ago13:20 UTC · about 1 month ago
KEV confirmed by Daily CyberSecurity
Exploitation attested by an external source
-
14:01 UTC about 2 months ago14:01 UTC · about 2 months ago
First public exploitation report
Exploit observed in malware
-
14:01 UTC about 2 months ago14:01 UTC · about 2 months ago
Added to CISA KEV
Listed in the CISA Known Exploited Vulnerabilities catalog
-
15:34 UTC about 2 months ago15:34 UTC · about 2 months ago
Nuclei template available
Scanner coverage available
-
13:26 UTC about 2 months ago13:26 UTC · about 2 months ago
KEV confirmed by CVE
Exploitation attested by an external source
-
00:00 UTC about 2 months ago00:00 UTC · about 2 months ago
Added to KEVIntel KEV Feed
High-confidence, third-party attested exploitation
-
00:17 UTC 3 months ago00:17 UTC · 3 months ago
Public PoC available
Public proof-of-concept code published
-
15:10 UTC 3 months ago15:10 UTC · 3 months ago
CVE published
Vulnerability disclosed publicly
-
18:50 UTC 3 months ago18:50 UTC · 3 months ago
CVE ID reserved
Identifier reserved by the CNA
Automate This Intelligence with the Pro API
Confidence scoring, exploit status, sensor telemetry, PoCs, scanner integrations, mentions, and tags are available programmatically for VM, SOC, and CTI workflows.
Pro API Example
GET /api/v2/pro/kevs/CVE-2026-41940
{
"cve_id": "CVE-2026-41940",
"title": "WebPros cPanel and WHM Authentication Bypass via Login Flow",
"affected_vendor": "WebPros",
"affected_product": "cPanel, WP Squared, WHM",
"affected_versions": [
{ "vendor": "...", "product": "...", "status": "affected", "display_label": "..." }
],
"confidence": "Confirmed",
"cvss_score": 9.3,
"epss_score": 0.981,
"exploit_status": {
"exploited_in_the_wild": true,
"active_exploitation_observed": false
},
"sensor_telemetry": { "...": "Pro API fields" },
"proof_of_concepts": [ "..." ],
"scanner_integrations": [ "..." ]
}