The flaw, tracked as CVE-2026-41940, affects both cPanel & WHM and WP2 (WordPress Squared), two widely used web hosting management platforms.
The vulnerability is classified as a missing authentication issue, mapped to CWE-306. It exists in the login flow of the affected systems and allows remote attackers to bypass authentication entirely.
This means an attacker does not need valid credentials to access the control panel.
Once exploited, threat actors can gain unauthorized administrative access, potentially leading to full compromise of hosted websites, databases, and server configurations.
The vulnerability impacts:
These platforms are commonly used by hosting providers and enterprises to manage websites, email services, and server operations, making the vulnerability particularly critical in shared hosting environments.
CISA added CVE-2026-41940 to its Known Exploited Vulnerabilities (KEV) catalog on April 30, 2026, confirming active exploitation.
While there is currently no confirmed link to ransomware campaigns, the nature of the flaw makes it highly attractive to attackers.
Unauthorized access to hosting control panels can allow attackers to:
The lack of authentication significantly lowers the barrier for exploitation, increasing the risk of widespread attacks.
Under Binding Operational Directive (BOD) 22-01, U.S. federal agencies are required to address this vulnerability by May 3, 2026.
Although the directive applies specifically to federal systems, CISA strongly urges all organizations to take immediate action.
Recommended steps include:
This vulnerability highlights ongoing risks in web hosting infrastructure, where a single flaw can expose multiple websites and services.
Authentication bypass issues are particularly dangerous because they eliminate the need for credential theft or brute-force attacks.
Organizations relying on cPanel & WHM should treat this issue as critical and assume potential compromise if systems remain unpatched.
The inclusion of CVE-2026-41940 in CISA’s KEV catalog signals a high level of urgency. With active exploitation already observed, organizations must prioritize remediation to prevent unauthorized access and potential large-scale compromise.
Follow us on Google News , LinkedIn and X to Get More Instant Updates. Set Cyberpress as a Preferred Source in Google
The post CISA Alerts on cPanel & WHM Flaw Actively Exploited in Attacks appeared first on Cyber Security News.
Marvel Studios is currently going through a crucial transitional period. Correspondingly, the LEGO sets are…
The post Gravity Media Taps Custom Consoles For Work On Production Center appeared first on…
Historically, cybercriminals had to assemble phishing campaigns piece by piece. They would purchase a credential-harvesting…
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent alert regarding a…
The Apache Software Foundation has released security updates for Apache MINA versions 2.2.7 and 2.1.12,…
A dangerous new supply chain attack has hit the developer community. A malicious threat actor…
This website uses cookies.