Critical Vulnerability in cPanel and WebHost Manager Software

A critical security vulnerability (CVE-2026-41940) has been discovered in cPanel and WHM/WP2 software, allowing an attacker to bypass authentication. This means an attacker can gain unauthorized access to the control panel without a user account. All versions after 11.40 are affected (all supported versions). A patch is currently available for the following versions: Users are urged to install the patches published by the vendor as soon as possible, following the instructions on the vendor's website: https://support.cpanel.net/hc/en-us/articles/40073787579671-Security-CVE-2026-41940-cPanel-WHM-WP2-Security-Update-04-28-2026. If updating is not possible for some reason, it is necessary to restrict incoming traffic to ports 2083, 2087, 2095, and 2096.

This article was collected and archived by Digital Sovereignty Watch from an institutional or public source relevant to digital sovereignty, technology policy, cybersecurity, cloud services, artificial intelligence or European regulation.

Read original source