CyberSecurityBoardThreat Intel · CVEs · Products
Critical CVEs

CVE-2026-41940: Authentication Bypass in cPanel and WHM

April 30, 2026

CVE-2026-41940 is an authentication bypass vulnerability in cPanel and WebHost Manager (WHM) that allows remote attackers to gain elevated control of the control panel. It is being actively exploited in a campaign that uses compromised GitHub repositories and GitHub Actions runners to scan for vulnerable servers.