CVE-2026-41940: Authentication Bypass in cPanel and WHM
CVE-2026-41940 is an authentication bypass vulnerability in cPanel and WebHost Manager (WHM) that allows remote attackers to gain elevated control of the…
Critical and exploited CVEs, vulnerability intelligence and remediation guidance.
CVE-2026-41940 is an authentication bypass vulnerability in cPanel and WebHost Manager (WHM) that allows remote attackers to gain elevated control of the…
ConnectWise ScreenConnect Path Traversal Vulnerability Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of…
Microsoft Windows Protection Mechanism Failure Vulnerability Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use…
SimpleHelp Missing Authorization Vulnerability Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the…
D-Link DIR-823X Command Injection Vulnerability Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of…
Samsung MagicINFO 9 Server Path Traversal Vulnerability Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue…
SimpleHelp Path Traversal Vulnerability Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the…
A vulnerability in Marimo exploited by the Chinese-speaking threat actor.
A previously disclosed Defender vulnerability by researcher Chaotic Eclipse, later patched by Microsoft.