Signal
Critical cPanel authentication bypass vulnerability exploited in the wild
Evidence first: scan the strongest sources, then decide whether to go deeper.
Published 2026-04-30 20:49 UTCUpdated 2026-05-01 16:20 UTC
rss
cveexploitssecurity_toolingincident_responsesecurity_policy
Trend in the last 24h
Source links open
Source links and full evidence are open here. Archive history, compare-over-time, alerts, exports, API, integrations, and workflow are paid.
No card needed for the free brief.
Evidence trail (top sources)
top sources (4 domains)domains are deduped. counts indicate coverage, not truth.4 top sources shown
Overview
A severe authentication bypass vulnerability (CVE-2026-41940) affecting cPanel and WebHost Manager (WHM) is actively exploited, exposing millions of websites to takeover.
Entities
cPanelKnownHostNamecheapHostGatorRapid7Cybersecurity and Infrastructure Security AgencyWP SquaredwatchTowr
Score total
1.42
Momentum 24h
5
Posts
5
Origins
5
Source types
1
Duplicate ratio
0%
Why now
- Exploitation began before patches were available, increasing urgency.
- CISA has mandated immediate patching for federal agencies.
- Hosting providers have taken emergency measures to mitigate risk during patch deployment.
Why it matters
- cPanel powers over a million websites, including critical sectors like banking and healthcare.
- The vulnerability allows attackers to bypass authentication and take full control of servers.
- Active exploitation before patch release led to real-world impacts including ransomware demands.
LLM analysis
Topic mix: lowPromo risk: lowSource quality: high
Recurring claims
- CVE-2026-41940 is a critical authentication bypass vulnerability in cPanel and WHM actively exploited in the wild.
- The vulnerability allows attackers to gain administrative access without credentials, risking server and website takeover.
- CISA has added the vulnerability to its Known Exploited Vulnerabilities list and ordered federal agencies to patch it urgently.
How sources frame it
- CyberScoop: neutral
- Malwarebytes Threat Analysis: neutral
- The Register: neutral
- The Record (Recorded Future News): neutral
This critical vulnerability in cPanel/WHM highlights the importance of rapid patching in widely used hosting platforms to prevent large-scale compromises.
All evidence
All evidence
Federal agencies must patch cPanel bug by Sunday, CISA says
The Record (Recorded Future News) · therecord.media · 2026-05-01 16:20 UTC
First reports come in of victims of critical cPanel vuln as 'millions' of sites potentially exposed
theregister_security · go.theregister.com · 2026-05-01 13:10 UTC
Actively exploited cPanel bug exposes millions of websites to takeover
Malwarebytes Threat Analysis · malwarebytes.com · 2026-05-01 10:48 UTC
Critical cPanel vulnerability actively exploited in the wild
SC Media · scworld.com · 2026-04-30 23:13 UTC
cPanel’s authentication bypass bug is being exploited in the wild, CISA warns
CyberScoop · cyberscoop.com · 2026-04-30 20:49 UTC
Show filters & breakdown
Posts loaded: 0Publishers: 5Origin domains: 5Duplicates: -
Showing 5 / 0
Top publishers (this list)
- The Record (Recorded Future News) (1)
- theregister_security (1)
- Malwarebytes Threat Analysis (1)
- SC Media (1)
- CyberScoop (1)
Top origin domains (this list)
- therecord.media (1)
- go.theregister.com (1)
- malwarebytes.com (1)
- scworld.com (1)
- cyberscoop.com (1)