Missing authentication in cPanel & WHM (CVE-2026-41940) — control-panel takeover without authentication, ransomware use confirmed
cPanel & WHM and WP2, a widely used web-hosting control panel, have a missing-authentication flaw in the login flow that lets an unauthenticated remote attacker gain unauthorized access to the control panel. CISA listed it as known-exploited (KEV) with confirmed ransomware use (CVSS 9.8 Critical).
Key facts
- CVE IDCVE-2026-41940
- CVSS base score9.8 CRITICAL
- CVSS vectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Affected (vendor / product)WebPros cPanel & WHM and WP2 (WordPress Squared)
- CWECWE-306
- ExploitationListed in CISA KEV (exploitation confirmed); also confirmed used in ransomware
- Remediation due2026-05-03 (U.S. federal civilian agencies, BOD 22-01)
Key points
- Missing authentication (CWE-306) in the login flow of cPanel & WHM / WP2
- An unauthenticated remote attacker gains unauthorized access to the control panel
- cPanel/WHM is the most widely used hosting control panel = one compromise ripples to many sites
- Listed in CISA KEV = exploitation confirmed; ransomware use also confirmed (CVSS 9.8 Critical)
- Response: fix per vendor; minimize control-panel exposure and enforce multi-factor authentication
- In shared hosting one control panel holds many customer sites, so an authentication bypass cascades.
1cPanel & WHM as hosting management
CVE-2026-41940 is a missing-authentication-for-a-critical-function vulnerability (CWE-306) in WebPros cPanel & WHM (WebHost Manager) and WP2 (WordPress Squared). It was added to CISA's KEV catalog on April 30, 2026, with ransomware use also confirmed.
2An authentication bypass in the login flow
Per NVD, an authentication bypass in the login flow lets an unauthenticated remote attacker gain unauthorized access to the control panel. cPanel & WHM is one of the most widely used control panels in the hosting industry, centrally managing sites, email, databases, and domains on a web server.
Seizing it without authentication lets an attacker manipulate the many websites and data on that server, so damage can escalate rapidly.
3Ransomware exploitation also confirmed
CISA has also confirmed exploitation in ransomware campaigns, making priority high. In setups like shared hosting, where a single server hosts many customer sites, compromising the control panel can lead to cascading damage.
4One control panel connects to many customers
cPanel & WHM is the control panel managing sites, mail, databases and domains on a web server in one place. In shared hosting, that one machine holds many customers.
- 1Reach the control panel without authenticationThe login flow carries an authentication bypass
- 2Reach every site on the serverSites, mail, databases and domains are managed from one place
- 3Propagate to many customersIn a configuration where one server holds many customer sites, damage cascades
CISA also confirms exploitation in ransomware campaigns, which raises the priority. Minimising internet exposure of the control panel and enforcing multi-factor authentication are effective too. The remediation date for federal civilian agencies is 3 May 2026, a short window.
Why it matters
Missing authentication in a hosting control panel plus confirmed ransomware use. Hosting providers and server admins should apply fixes immediately, minimize control-panel exposure, enforce MFA, and verify backups — addressing the risk that one compromise ripples to many sites.
FAQ
What are cPanel & WHM?
Why can damage be so large?
What should I do?
Sources (primary)
This article is an independent organization based on the U.S. official data below. Always verify the exact, latest details and applicability with the official and vendor sources.
- CISA KEV Catalog (known exploited list)
- NVD (CVE details / CVSS)
- Vendor / reference advisory
- Vendor / reference advisory
- Vendor / reference advisory
- This product uses data from the NVD API but is not endorsed or certified by the NVD. KEV data is CC0 (public domain).