INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

cPanel Authentication Bypass Vulnerability

| 2026-05-10 15:59 CRITICAL HIGH
Executive Summary AI-generated
The newly discovered cPanel vulnerabilities could allow attackers to read arbitrary files, execute code, and escalate privileges on vulnerable systems. These exploits have been patched across multiple supported cPanel & WHM releases, including versions 11.136.0.9, 11.134.0.25, 11.132.0.31, and newer builds. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a flaw in Microsoft Defender to its Known Exploited Vulnerabilities catalog, which could lead to the exploitation of CVE-2026-41940, an authentication bypass flaw affecting cPanel and WHM versions after 11.40.
Technical Mitigations AI-generated
* Implement secure login mechanisms: Ensure that all users log in to cPanel using a strong password and consider implementing additional security measures such as multi-factor authentication, session timeouts, or IP blocking. * Regularly update and patch software: Keep your WHM (Web Host Manager) and cPanel versions up-to-date with the latest security patches to prevent exploitation of known vulnerabilities like CVE-2026-41940. * Use secure file permissions: Set strict file permissions for sensitive files and directories, such as /var/cpanel/sessions/raw/, to limit access to unauthorized users or scripts. * Monitor system logs and activity: Regularly review system logs and monitor user activity to detect potential security breaches or suspicious login attempts. * Implement network segmentation and isolation: Segment your network into separate zones for cPanel and WHM, as well as other sensitive systems, to prevent lateral movement in case of a breach.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-29202CVE-2026-29202 CVE-2026-29201CVE-2026-29201 CVE-2026-29203CVE-2026-29203 CVE-2026-41940CVE-2026-41940
Target & Sectors
Global Scope
Incident Timeline
‎late February 2026
Threat actors exploited a known cPanel authentication bypass vulnerability in several hosting providers.
‎28 April 2026
Threat actors exploited a previously unknown vulnerability in cPanel authentication, compromising servers two months prior to the release of an urgent patch.
organisation WebPros International
organisation L.L.C.
‎April 29, 2026
Threat actors exploited a cPanel Authentication Bypass Vulnerability to gain unauthorized access.
‎May 3, 2026
Threat actors exploited a cPanel Authentication Bypass Vulnerability.
vulnerability CVE-2026-41940
attribution Known Exploited
tactic T1588.006 - Vulnerabilities
attribution KEV
general_metric 41940 CVE-2026
attribution Federal Civilian Executive Branch
attribution FCEB
‎2026/05/10
CPanel fixed three flaws that could allow file reads, code execution, and privilege escalation.
organisation cPanel
organisation New cPanel
organisation WHM
organisation SecurityAffairs
organisation CVE-2026
organisation API
organisation Mirai
infrastructure 11.40
organisation CVSS
organisation Flaw Now Tracked
organisation CVE
organisation a Carriage Return Line Feed
infrastructure 9.8
organisation EoL
organisation WP Squared
organisation WebHost
organisation WordPress
infrastructure 11.136.0
infrastructure 11.134.0
infrastructure 11.132.0
infrastructure 11.86.0
infrastructure 11.110.0
infrastructure 11.118.0
infrastructure 11.126.0
infrastructure 11.130.0
infrastructure 11.136.1
infrastructure 110.0
infrastructure 118.0
infrastructure 126.0
infrastructure 132.0
infrastructure 134.0
infrastructure 136.0
organisation Known Exploited
organisation KEV
organisation NIST
organisation National Vulnerability Database
organisation NVD
organisation WebPros
organisation cPanel & WHM
infrastructure 136.1.7
organisation KnownHost
organisation the Shadowserver Foundation
organisation InMotion
organisation Reseller
organisation Stellar Business
organisation the Namecheap Support Team
organisation Password
organisation LinkedIn, Eye Security
organisation The Hacker News
organisation Missing Authentication for Critical Function
organisation Update Details
organisation Shodan
organisation WatchTowr
Tactical Metrics
Metrics
infrastructure
‎11.136.0
Software Version
Metrics
infrastructure
‎11.134.0
Software Version
Metrics
infrastructure
‎11.132.0
Software Version
Metrics
infrastructure
‎11.40
Software Version
Metrics
infrastructure
‎11.86.0
Software Version
Metrics
infrastructure
‎11.110.0
Software Version
Metrics
infrastructure
‎11.118.0
Software Version
Metrics
infrastructure
‎11.126.0
Software Version
Metrics
infrastructure
‎11.130.0
Software Version
Metrics
infrastructure
‎136.1.7
Software Version
Metrics
infrastructure
‎9.8
Software Version
Metrics
infrastructure
‎110.0
Software Version
Metrics
infrastructure
‎118.0
Software Version
Metrics
infrastructure
‎126.0
Software Version
Metrics
infrastructure
‎132.0
Software Version
Metrics
infrastructure
‎134.0
Software Version
Metrics
infrastructure
‎136.0
Software Version
Metrics
infrastructure
‎11.136.1
Software Version