In cPanel a vulnerability was discovered that allows access to the admin panel without a password for millions of sites

In cPanel a vulnerability was discovered that allows access to the admin panel without a password for millions of sites

30 hardware

Short summary

* Attackers are actively exploiting the critical vulnerability CVE‑2026‑41940 in cPanel and WHM – popular server software for web hosting management.

* The flaw allows bypassing the login screen, gaining full access to the administration panel and therefore all sites, mail, databases, and configurations on the server.

* The vulnerability affects all supported versions of cPanel/WHM.

* Major hosting providers have already applied updates or temporarily blocked access to the panels.

1. What is CVE‑2026‑41940?
Parameter Description Purpose Software
cPanel and WebHost Manager (WHM) – web hosting management systems used by tens of millions of sites worldwide. Type of vulnerability Authentication bypass: remote access to the panel without entering a password. Consequences Full control over the server: sites, mail, databases, domain configurations.

2. How providers are responding
Provider Action
Namecheap Immediately after learning about the vulnerability blocked access to cPanel to prevent exploitation and give time for updates.
HostGator Applied a patch and labeled the issue as a “critical authentication bypass vulnerability.”
KnownHost Reported that attackers had used the vulnerability before its public disclosure (since February 23). About 30 servers were logged with attempts of unauthorized access; no confirmed breaches were found. The company temporarily blocked client systems pending updates.
cPanel Recommended all users verify they have the latest patches, even if their provider has already applied fixes.

3. Position of cybersecurity authorities
* Canadian Centre for Cyber Security (CCCS) – in a bulletin warned about the possibility of sites on shared hosting servers being compromised, including large providers.
* Stated that “exploitation is highly likely” and demanded immediate action from cPanel clients and their providers to prevent unauthorized access.

4. Additional updates
cPanel released a security patch for WP Squared – a similar WordPress site management tool – to close the same vulnerabilities in that system.

Conclusion
The critical vulnerability CVE‑2026‑41940 allows remote bypass of authentication in cPanel/WHM and full server control. All supported software versions are affected, so it is essential to install updates or temporarily block panel access as soon as possible. Major providers have already taken action, and CCCS strongly urges clients to act quickly.

Comments (0)

Share your thoughts — please be polite and stay on topic.

No comments yet. Leave a comment — share your opinion!

To leave a comment, please log in.

Log in to comment