Disclosed in late April 2026, CVE-2026-41940 is the most dangerous of the bunch, carrying a CVSS score of 9.8.
The flaw exists in cPanel’s session management and authentication flow, where attackers can send crafted requests with manipulated cookies to trick the platform into treating them as a logged-in user, with no credentials required.
What makes this especially alarming is that the bypass can sidestep multi-factor authentication entirely.
Once inside, an attacker gains full administrative control over the hosting environment, including websites, databases, email accounts, configuration files, and API tokens.
Security researchers confirmed active exploitation in the wild weeks before patches became available, prompting CISA to add CVE-2026-41940 to its Known Exploited Vulnerabilities catalog.
The April advisory was just the beginning. cPanel followed up with two additional rounds of security fixes in May 2026.
May 2026 Patch Batches Add More CVEs
cPanel and hosting providers describe these as server-side issues in supported cPanel & WHM versions, with severities reaching up to High.
Full technical details for some of these May flaws may remain limited, but their presence alongside CVE-2026-41940 creates a dangerous attack surface.
When combined, these vulnerabilities give determined attackers multiple paths into a cPanel-managed server.
Beyond the initial authentication bypass, adversaries could chain the May flaws to escalate privileges, pivot between hosting accounts, or plant web shells for long-term persistence, a serious concern on shared hosting platforms where one compromised instance can expose dozens of customer environments.
Hosting companies like InMotion Hosting are already automatically rolling out patches for managed environments. However, self-managed VPS and dedicated server customers must act manually.
/scripts/upcp process immediately to apply all the latest fixesSecurity teams should treat this as more than a routine patch cycle. The combination of active exploitation, a high CVSS score, and multiple chained vulnerabilities makes delayed action a significant liability for hosting providers and site owners alike.
Follow us on Google News , LinkedIn and X to Get More Instant Updates. Set Cyberpress as a Preferred Source in Google
The post Multiple cPanel Bugs Allow Access to Critical System Resources appeared first on Cyber Security News.
Disguise is partnering with Creative Technology to provide the visual playback backbone for the Eurovision…
The Weather Company introduced Max On Demand, a cloud-native extension of its Max Cloud platform…
Motion designer Jon Berry of jonberrydesign has expanded Nightspeed, a custom motion graphics package created…
The post IAB Releases Campaign Data Standards 1.0 For Public Comment appeared first on TV…
The post Stop The False Choice: 5G Broadcast Can Ride Inside ATSC 3.0, And We…
Canon U.S.A. is expanding its EOS V-series with the EOS R6 V full-frame body and…
This website uses cookies.