U.S. CISA adds a flaw in WebPros cPanel to its Known Exploited Vulnerabilities catalogSecurity Affairs·May 3, 14:41 UTC · May 3, 2026Exploit / PoC in the wildCVE-2026-4194060
cPanel zero-day exploited for months before patch release (CVE-2026-41940)Help Net Security·May 5, 12:05 UTC · May 5, 2026Exploit / PoC in the wildCVE-2026-4194060
Critical cPanel Authentication Vulnerability Identified — Update Your Server ImmediatelyThe Hacker News·May 4, 16:03 UTC · May 4, 2026Vulnerability in the wildCVE-2026-4194060