CVE-2026-41940 exploitation pushes cPanel and WHM remediation
Case score 70
Case score is a discovery signal based on public evidence, not a guaranteed risk rating. Use it to decide what to review first, then verify important details from the linked sources.
- Total
- 70
- Main story score
- 64
- Related evidence lift
- +6 / 20
- Contributing updates
- 2
- Context updates
- 3
- Vulnerability Critical authentication-bypass flaw in cPanel and WHM anchors the case. main
- Advisory Mitigation Vendor containment and detection guidance explains the response posture. context
- Security Patch Release Initial patch release and fixed builds define the remediation path. context
- Exploitation Wave Broad exploitation wave and likely-compromise reporting strengthen the active-abuse picture. contributes
Overview
Latest development Open development history cPanel emergency update for authentication bypass cPanel released emergency updates for an unauthenticated authentication-bypass flaw in cPanel and WHM that can let remote attackers obtain control-panel access; the issue affects all currently supported versions, has no official identifier at release, and was later tracked as CVE-2026-41940.
-
Active CVE-2026-41940 exploitation hits cPanel & WHM servers
Threat actors are actively exploiting CVE-2026-41940 against internet-facing cPanel & WHM instances, enabling unauthenticated administrative access that can compromise host systems, configurations, databases, and websites. Defenders observed scanning, exploit, and brute-force activity tied to more than 40,000 likely compromised servers, while cPanel published fixed releases and CISA added the CVE to the KEV catalog.
-
Rapid exploitation of CVE-2026-41940 targets cPanel, WHM, and WP Squared
CVE-2026-41940 in cPanel, WebHost Manager (WHM), and WP Squared was rapidly exploited after public disclosure, with Censys reporting attacks from multiple threat actors within 24 hours and about 15,000 potentially compromised instances in the first day. KnownHost said about 30 managed cPanel servers showed attempted exploitation, WatchTowr Labs published a PoC exploit and technical analysis, and Defused said much of the observed activity copied WatchTowr's PoC exactly.
-
CVE-2026-41940 targeted exploitation against government and MSP domains
A previously unknown threat actor used publicly-available proof-of-concepts for CVE-2026-41940 from 95.111.250[.]175 to target government and military domains tied to the Philippines (*.mil.ph and (*.ph)) and Laos (*.gov.la), plus MSPs and hosting providers in the Philippines, Laos, Canada, South Africa, and the U.S., in an attempt to gain elevated control of cPanel / WebHost Manager (WHM).
-
Namecheap blocks management ports and cPanel urges patching
Namecheap applied a firewall rule to block TCP ports 2083 and 2087, temporarily restricting customer access to cPanel and WHM interfaces until patching was complete, while cPanel urged administrators to update with `/scripts/upcp --force`, verify the build, restart services, or temporarily block inbound traffic on ports 2083, 2087, 2095, and 2096 or stop `cpsrvd` and `cpdavd`; the fix was reported as applied across Namecheap servers by April 29, 2026, 02:42 a.m. UTC.