Critical Known exploited (KEV) Ransomware use CVE-2026-41940

Missing authentication in cPanel & WHM (CVE-2026-41940) — control-panel takeover without authentication, ransomware use confirmed

WebPros cPanel & WHM and WP2 (WordPress Squared) Added to KEV Apr 30, 2026 Federal remediation due 2026-05-03

cPanel & WHM and WP2, a widely used web-hosting control panel, have a missing-authentication flaw in the login flow that lets an unauthenticated remote attacker gain unauthorized access to the control panel. CISA listed it as known-exploited (KEV) with confirmed ransomware use (CVSS 9.8 Critical).

Key facts

  • CVE IDCVE-2026-41940
  • CVSS base score9.8 CRITICAL
  • CVSS vectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Affected (vendor / product)WebPros cPanel & WHM and WP2 (WordPress Squared)
  • CWECWE-306
  • ExploitationListed in CISA KEV (exploitation confirmed); also confirmed used in ransomware
  • Remediation due2026-05-03 (U.S. federal civilian agencies, BOD 22-01)

Key points

  • Missing authentication (CWE-306) in the login flow of cPanel & WHM / WP2
  • An unauthenticated remote attacker gains unauthorized access to the control panel
  • cPanel/WHM is the most widely used hosting control panel = one compromise ripples to many sites
  • Listed in CISA KEV = exploitation confirmed; ransomware use also confirmed (CVSS 9.8 Critical)
  • Response: fix per vendor; minimize control-panel exposure and enforce multi-factor authentication
  • In shared hosting one control panel holds many customer sites, so an authentication bypass cascades.

1cPanel & WHM as hosting management

CVE-2026-41940 is a missing-authentication-for-a-critical-function vulnerability (CWE-306) in WebPros cPanel & WHM (WebHost Manager) and WP2 (WordPress Squared). It was added to CISA's KEV catalog on April 30, 2026, with ransomware use also confirmed.

2An authentication bypass in the login flow

Per NVD, an authentication bypass in the login flow lets an unauthenticated remote attacker gain unauthorized access to the control panel. cPanel & WHM is one of the most widely used control panels in the hosting industry, centrally managing sites, email, databases, and domains on a web server.

Seizing it without authentication lets an attacker manipulate the many websites and data on that server, so damage can escalate rapidly.

3Ransomware exploitation also confirmed

CISA has also confirmed exploitation in ransomware campaigns, making priority high. In setups like shared hosting, where a single server hosts many customer sites, compromising the control panel can lead to cascading damage.

4One control panel connects to many customers

cPanel & WHM is the control panel managing sites, mail, databases and domains on a web server in one place. In shared hosting, that one machine holds many customers.

  1. 1Reach the control panel without authenticationThe login flow carries an authentication bypass
  2. 2Reach every site on the serverSites, mail, databases and domains are managed from one place
  3. 3Propagate to many customersIn a configuration where one server holds many customer sites, damage cascades

CISA also confirms exploitation in ransomware campaigns, which raises the priority. Minimising internet exposure of the control panel and enforcing multi-factor authentication are effective too. The remediation date for federal civilian agencies is 3 May 2026, a short window.

Why it matters

Missing authentication in a hosting control panel plus confirmed ransomware use. Hosting providers and server admins should apply fixes immediately, minimize control-panel exposure, enforce MFA, and verify backups — addressing the risk that one compromise ripples to many sites.

FAQ

What are cPanel & WHM?
Widely used hosting control panels that centrally manage sites, email, databases, and domains on a web server. WHM is for server administrators; cPanel is the per-account interface.
Why can damage be so large?
In shared hosting, a single server hosts many customer sites. If the control panel is taken over without authentication, those sites and their data are all put at risk at once.
What should I do?
Apply fixes/mitigations per WebPros/cPanel, minimize the control panel's internet exposure, and enforce multi-factor authentication. Prompt action is advised given confirmed ransomware use.

Sources (primary)

This article is an independent organization based on the U.S. official data below. Always verify the exact, latest details and applicability with the official and vendor sources.

#cPanel#WHM#Hosting#Missing authentication#Ransomware
Disclaimer: This site independently summarizes and classifies information based on official data sources. Always verify the latest and accurate information with the official sources. Content on finance, health, legal, and security is information, not advice. This site is not an official website of the U.S. government.