Federal agencies must patch cPanel bug by Sunday, CISA says
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-41940 | Missing-Authentication Bypass in WebPros cPanel & WHM (AuthBypass to RCE) CVE-2026-41940 is a critical missing-authentication flaw (CWE-306) in the login flow of WebPros cPanel & WHM (versions after 11.40) and WP2 (WordPress Squared) that lets unauthenticated remote attackers bypass authentication and gain unauthorized access to the control panel. Because no privileges, user interaction, or special conditions are required, any attacker who can reach the login endpoint over the network can attempt it. Beyond control-panel account takeover, public proofs of concept — including watchTowr's 'AuthBypass to RCE' exploit — show the flaw can be chained to remote code execution, and reporting indicates a single hosting customer could obtain root control of an entire shared server. Any hosting provider, MSP, reseller, or organization running cPanel/WHM or WP Squared is affected; cPanel is the dominant commercial hosting control panel, implying a very large installed base of shared-hosting servers and hosted domains. Exploitation is confirmed in the wild: CISA added it to the KEV on 2026-04-30 with known ransomware use, EPSS assigns a 98.5% probability of exploitation within 30 days (100th percentile), and multiple threat actors are actively exploiting it, including against government and MSP networks. Do: Patch immediately per WebPros' advisory — the source data does not specify fixed version numbers, so follow vendor instructions for exact patched releases; CISA KEV/BOD 22-01 requires federal agencies to apply mitigations or discontinue use by the stated deadline (reported as Sunday). Until patched, restrict access to the cPanel/WHM login interface (IP allowlisting, VPN, or limiting management-interface exposure) and hunt for indicators of compromise such as unexpected control-panel logins, new admin accounts, webshells, or ransomware artifacts. The referenced public PoCs can be used to validate whether your instances are exploitable. | 9.3 | 99% | KEV ransomware PoC ×4 |
| mass≈100,000+ internet-exposed cPanel/WHM servers, spanning tens of millions of hosted domains and millions of end users |
Full article416 words · extracted from therecord.media · click to collapse
Federal agencies have until May 3 to resolve a security issue impacting a critical system for server and website management. The Cybersecurity and Infrastructure Security Agency (CISA) ordered all federal agencies to patch CVE-2026-41940 — a high-severity vulnerability affecting cPanel & WHM. WebPros International owns cPanel and WHM, and the Linux-based tools are part of a web hosting control panel suite of software deployed to manage websites and servers. Millions of domains are run through the cPanel and WHM control panel solutions. Incident responders at Rapid7 said successful exploitation of CVE-2026-41940 “grants an attacker control over the cPanel host system, its configurations and databases, and websites it manages.” The bug carries a CVSS score of 9.8 out of 10. Experts warned that hackers could use the bug to completely compromise a server, steal data or manipulate hosted data. There are also larger service disruptions that could be enabled by the vulnerability. Multiple cybersecurity firms said there are thousands cPanel instances exposed to the internet that may be vulnerable. CISA confirmed Thursday that the bug is being exploited. In addition to fixes for the bug, cPanel released a tool that allows companies to see if they have been compromised. The bug was first spotlighted earlier this week by cybersecurity experts at watchTowr, which also released a tool that allows defenders to identify vulnerable hosts in their estates. Other companies shared evidence that showed the bug has been exploited since February. U.S. domain name register Namecheap released an advisory this week warning customers that actions it is taking to address the vulnerability may temporarily restrict users from access to their cPanel and WHM interfaces. Benjamin Harris, CEO of watchTowr, said that within hours of the initial cPanel advisory dropping, nearly every major hosting provider on the planet had firewalled their own customers off their own product. “Hosting.com, Namecheap, KnownHost, HostPapa, InMotion and the rest all pulled the emergency brake because the alternative was watching their entire customer base get owned in real-time,” Harris said. “Once again, we’re running around with half the Internet seemingly ablaze, and given the increased usage of AI in vulnerability research, we anticipate this new normal to become increasingly familiar.”
No previous article
No new articles
Jonathan Greig
is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.
Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/cisa-orders-federal-agencies-to-patch-cpanel-bug