Signal
Critical cPanel authentication bypass vulnerability exploited in the wild
Evidence first: scan the strongest sources, then decide whether to go deeper.
Published 2026-04-30 20:49 UTCUpdated 2026-05-01 16:20 UTC
rss
cveexploitssecurity_toolingincident_responsesecurity_policy
Source links open
Source links and full evidence are open here. Pro adds archive history, compare-over-time, alerts, exports, and workflow. Business adds Feed API integrations and team usage.
No card needed for the free brief.
Evidence trail (top sources)
top sources (4 domains)domains are deduped. counts indicate coverage, not truth.4 top sources shown
Overview
A severe authentication bypass vulnerability (CVE-2026-41940) affecting cPanel and WebHost Manager (WHM) is actively exploited, exposing millions of websites to takeover.
Entities
cPanelKnownHostNamecheapHostGatorRapid7Cybersecurity and Infrastructure Security AgencyWP SquaredwatchTowr
Score total
1.42
Momentum 24h
5
Posts
5
Origins
5
Source types
1
Duplicate ratio
0%
Why now
- Exploitation began before patches were available, increasing urgency.
- CISA has mandated immediate patching for federal agencies.
- Hosting providers have taken emergency measures to mitigate risk during patch deployment.
Why it matters
- cPanel powers over a million websites, including critical sectors like banking and healthcare.
- The vulnerability allows attackers to bypass authentication and take full control of servers.
- Active exploitation before patch release led to real-world impacts including ransomware demands.
LLM analysis
Topic mix: lowPromo risk: lowSource quality: high
Recurring claims
- CVE-2026-41940 is a critical authentication bypass vulnerability in cPanel and WHM actively exploited in the wild.
- The vulnerability allows attackers to gain administrative access without credentials, risking server and website takeover.
- CISA has added the vulnerability to its Known Exploited Vulnerabilities list and ordered federal agencies to patch it urgently.
How sources frame it
- CyberScoop: neutral
- Malwarebytes Threat Analysis: neutral
- The Register: neutral
- The Record (Recorded Future News): neutral
This critical vulnerability in cPanel/WHM highlights the importance of rapid patching in widely used hosting platforms to prevent large-scale compromises.
All evidence
All evidence
Federal agencies must patch cPanel bug by Sunday, CISA says
The Record (Recorded Future News) · therecord.media · 2026-05-01 16:20 UTC
First reports come in of victims of critical cPanel vuln as 'millions' of sites potentially exposed
theregister_security · go.theregister.com · 2026-05-01 13:10 UTC
Actively exploited cPanel bug exposes millions of websites to takeover
Malwarebytes Threat Analysis · malwarebytes.com · 2026-05-01 10:48 UTC
Critical cPanel vulnerability actively exploited in the wild
SC Media · scworld.com · 2026-04-30 23:13 UTC
cPanel’s authentication bypass bug is being exploited in the wild, CISA warns
CyberScoop · cyberscoop.com · 2026-04-30 20:49 UTC
Show filters & breakdown
Posts loaded: 0Publishers: 5Origin domains: 5Duplicates: -
Showing 5 / 5
Top publishers (this list)
- The Record (Recorded Future News) (1)
- theregister_security (1)
- Malwarebytes Threat Analysis (1)
- SC Media (1)
- CyberScoop (1)
Top origin domains (this list)
- therecord.media (1)
- go.theregister.com (1)
- malwarebytes.com (1)
- scworld.com (1)
- cyberscoop.com (1)