cPanel Security Update – 30 April 2026

cPanel has released a security update to address a vulnerability in cPanel software and WebHost Manager (WHM) affecting all versions after 11.40.

The addressed vulnerability could allow the remote unauthorized attacker to bypass authentication and gain access to the affected systems.

The addressed vulnerability:

cPanel & WHM Login Flow Authentication Bypass Vulnerability (CVE-2026- 41940):

  • CVSS: 9.8
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: None
  • Consequences: Gain Access

It should be highlighted that security researchers have discovered that the zeroday vulnerability “CVE-2026-41940” is being exploited in the wild.

Vulnerabilities

CVE-2026-41940

Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

cPanel Security Advisory

References