CVE-2026-41940
WebPros cPanel & WHM and WP2 (WordPress Squared) Missing Authentication for Critical Function Vulnerability
// Description
WebPros cPanel & WHM (WebHost Manager) and WP2 (WordPress Squared) contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.
// Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Federal remediation due May 3, 2026 — past due
Advertisement
// Coverage
- cPanel CVE-2026-41940 Exploited for Authentication Bypass, Backdoor
May 11, 2026
- cPanel CVE-2026-41940 Exploitation: 40,000 Servers Compromised
May 4, 2026
- CVE-2026-41940: Critical cPanel Vulnerability Exploited by Sorry Ransomware
May 3, 2026
- CVE-2026-41940: Active Zero-Day Exploitation in cPanel and WHM
Apr 30, 2026