ZeroHour

Vulnerabilities

384 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-65643
Authenticated eval injection in cPanel enables root code execution

cPanel 11.138.0.0 and earlier contains an eval injection flaw (CWE-95) in which attacker-controlled input reaches dynamic code evaluation without proper neutralization. A remote attacker holding any authenticated account on a cPanel server, such as an ordinary hosting customer, can trigger the flaw with crafted input and no user interaction. Successful exploitation yields arbitrary code execution as root, meaning a single low-privilege tenant can compromise the entire server and every site hosted on it. All deployments running version 11.138.0.0 or earlier are affected, which at disclosure covers essentially all active cPanel servers given that this was the current release. No public proof-of-concept or confirmed in-the-wild exploitation is known; the issue is not in CISA KEV and EPSS assigns only a 0.9% probability of exploitation within 30 days.

Do: Upgrade cPanel/WHM to a fixed release above 11.138.0.0 published under WebPros advisory AV26-861, prioritizing multi-tenant shared servers where any customer account can reach the vulnerable code. Until patched, restrict shell and feature access for untrusted accounts and review authentication logs and unexpected root-owned processes. No workaround is documented in the available data, so updating is the primary action.

8.7<1%
  • cPanel 11.138.0.0 and earlier
massroughly hundreds of thousands of cPanel/WHM servers (millions of hosted sites on multi-tenant shared hosting)
CVE-2026-29205
+1 in the same advisory: …32992
Incorrect privileges management and insufficient path filtering allow to read arbitrary file on the server via the cpdavd attachment download endpoints.

Incorrect privileges management and insufficient path filtering allow to read arbitrary file on the server via the cpdavd attachment download endpoints.

NVD description · AI analysis pending
8.6
group max
8%
  • cpanel cpanel
  • cpanel wp squared
  • cpanel whm
CVE-2026-41940
Missing-Authentication Bypass in WebPros cPanel & WHM (AuthBypass to RCE)

CVE-2026-41940 is a critical missing-authentication flaw (CWE-306) in the login flow of WebPros cPanel & WHM (versions after 11.40) and WP2 (WordPress Squared) that lets unauthenticated remote attackers bypass authentication and gain unauthorized access to the control panel. Because no privileges, user interaction, or special conditions are required, any attacker who can reach the login endpoint over the network can attempt it. Beyond control-panel account takeover, public proofs of concept — including watchTowr's 'AuthBypass to RCE' exploit — show the flaw can be chained to remote code execution, and reporting indicates a single hosting customer could obtain root control of an entire shared server. Any hosting provider, MSP, reseller, or organization running cPanel/WHM or WP Squared is affected; cPanel is the dominant commercial hosting control panel, implying a very large installed base of shared-hosting servers and hosted domains. Exploitation is confirmed in the wild: CISA added it to the KEV on 2026-04-30 with known ransomware use, EPSS assigns a 98.5% probability of exploitation within 30 days (100th percentile), and multiple threat actors are actively exploiting it, including against government and MSP networks.

Do: Patch immediately per WebPros' advisory — the source data does not specify fixed version numbers, so follow vendor instructions for exact patched releases; CISA KEV/BOD 22-01 requires federal agencies to apply mitigations or discontinue use by the stated deadline (reported as Sunday). Until patched, restrict access to the cPanel/WHM login interface (IP allowlisting, VPN, or limiting management-interface exposure) and hunt for indicators of compromise such as unexpected control-panel logins, new admin accounts, webshells, or ransomware artifacts. The referenced public PoCs can be used to validate whether your instances are exploitable.

9.399% KEV ransomware PoC ×5
  • WebPros cPanel versions after 11.40 (per CISA description)
  • WebPros WHM versions after 11.40 (per CISA description)
  • WebPros WP2 (WordPress Squared)
mass≈100,000+ internet-exposed cPanel/WHM servers, spanning tens of millions of hosted domains and millions of end users
CVE-2025-66429
An issue was discovered in cPanel 110 through 132.

An issue was discovered in cPanel 110 through 132. A directory traversal vulnerability within the Team Manager API allows for overwrite of an arbitrary file. This can allow for privilege escalation to the root user.

NVD description · AI analysis pending
8.8<1%
  • cpanel cpanel
CVE-2023-29489
An issue was discovered in cPanel before 11.109.9999.116.

An issue was discovered in cPanel before 11.109.9999.116. XSS can occur on the cpsrvd error page via an invalid webcall ID, aka SEC-669. The fixed versions are 11.109.9999.116, 11.108.0.13, 11.106.0.18, and 11.102.0.31.

NVD description · AI analysis pending
6.166% PoC
  • cpanel cpanel
CVE-2021-38589
In cPanel before 96.0.13, scripts/fix-cpanel-perl does not properly restrict the overwriting of files (SEC-588).

In cPanel before 96.0.13, scripts/fix-cpanel-perl does not properly restrict the overwriting of files (SEC-588).

NVD description · AI analysis pending
8.1
group max
<1%
  • cpanel cpanel
CVE-2021-31803
cPanel before 94.0.3 allows self-XSS via EasyApache 4 Save Profile (SEC-581).

cPanel before 94.0.3 allows self-XSS via EasyApache 4 Save Profile (SEC-581).

NVD description · AI analysis pending
6.1<1%
  • cpanel cpanel
CVE-2021-26267
+1 in the same advisory: …26266
cPanel before 92.0.9 allows a MySQL user (who has an old-style password hash) to bypass suspension (SEC-579).

cPanel before 92.0.9 allows a MySQL user (who has an old-style password hash) to bypass suspension (SEC-579).

NVD description · AI analysis pending
7.5<1%
  • cpanel cpanel
CVE-2020-29136
+2 in the same advisory: …29137 …29135
In cPanel before 90.0.17, 2FA can be bypassed via a brute-force approach (SEC-575).

In cPanel before 90.0.17, 2FA can be bypassed via a brute-force approach (SEC-575).

NVD description · AI analysis pending
6.5
group max
1%
  • cpanel cpanel
CVE-2020-26098
cPanel before 88.0.3 mishandles the Exim filter path, leading to remote code execution (SEC-485).

cPanel before 88.0.3 mishandles the Exim filter path, leading to remote code execution (SEC-485).

NVD description · AI analysis pending
9.8
group max
3%
  • cpanel cpanel
CVE-2020-12785
+1 in the same advisory: …12784
cPanel before 86.0.14 allows attackers to obtain access to the current working directory via the account backup feature (SEC-540).

cPanel before 86.0.14 allows attackers to obtain access to the current working directory via the account backup feature (SEC-540).

NVD description · AI analysis pending
8.1
group max
<1%
  • cpanel cpanel
CVE-2020-10119
cPanel before 84.0.20 allows a demo account to achieve remote code execution via a cpsrvd rsync shell (SEC-544).

cPanel before 84.0.20 allows a demo account to achieve remote code execution via a cpsrvd rsync shell (SEC-544).

NVD description · AI analysis pending
9.8
group max
2%
  • cpanel cpanel