Fixing and finding
Jump to remediation plan
CVE ID

CVE-2026-41940

Published 2026-04-29
Updated 3 months ago
Vendor/s
WebPros
Product/s
cPanel & WHM and WP2 (WordPress Squared)
Version/s
11.40 > 86.0.41
KEV Status
Active Exploitation
Listed in CISA's Known Exploited Vulnerabilities catalog. Active exploitation observed in the wild.
CVSS Score (v3.1)
9.8
/ 10
Critical
Severity Details
Base score
9.8 Critical
Attack vector
Network
Attack complexity
Low
Privileges required
None
User interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Description

CVE-2026-41940 is a critical authentication bypass in WebPros cPanel, WHM, and WP2 (CVSS 9.8) allowing remote attackers to gain full control.

CPE

WebPros logo
WebPros
Product Version Start Version End (excl.) Status
cpanel 11.40 86.0.41 vulnerable
cpanel 88.0.0 110.0.97 vulnerable
cpanel 112.0.0 118.0.63 vulnerable
cpanel 120.0.0 124.0.35 vulnerable
cpanel 126.0.1 126.0.54 vulnerable
cpanel 128.0.0 130.0.19 vulnerable
cpanel 132.0.0 132.0.29 vulnerable
cpanel 134.0.0 134.0.20 vulnerable
cpanel 136.0.0 136.0.5 vulnerable
whm 11.40 86.0.41 vulnerable
whm 88.0.0 110.0.97 vulnerable
whm 112.0.0 118.0.63 vulnerable
whm 120.0.0 124.0.35 vulnerable
whm 126.0.1 126.0.54 vulnerable
whm 128.0.0 130.0.19 vulnerable
whm 132.0.0 132.0.29 vulnerable
whm 134.0.0 134.0.20 vulnerable
whm 136.0.0 136.0.5 vulnerable
wp_squared * 136.1.7 vulnerable

Related weakness (CWE)

CWE-306

Remediation plan

1

Apply official patches

Visit the cPanel Security Advisor or the official WebPros support portal to download and apply the emergency security updates released on April 28, 2026, which address the login flow flaw.

2

Update affected systems

Upgrade cPanel & WHM to versions 86.0.41, 110.0.97, 118.0.63, 124.0.35, 126.0.54, 130.0.19, 132.0.29, 134.0.20, 136.0.5 or later, and WP Squared to 136.1.7 or higher to resolve the vulnerability.

3

Restrict access

Implement network-level access controls or a Web Application Firewall (WAF) to limit access to the cPanel/WHM login ports (2082, 2083, 2086, 2087) to known, trusted IP addresses only.

4

Monitor for exploitation

Review authentication logs for unusual login patterns, specifically looking for successful logins from unknown IP addresses that bypass standard multi-factor authentication or originate from suspicious geographic regions.

Detection Guidance

Detect exploitation by auditing /usr/local/cpanel/logs/access_log and /var/log/secure for successful login events without corresponding authentication challenges. Look for unusual POST requests to /login/ or /cpsess/ endpoints from external IPs. Network signatures should flag unauthorized traffic to ports 2083 and 2087. Monitor for the creation of unauthorized administrative accounts or unexpected changes to system configuration files immediately following suspicious login activity.

References

Sources

NIST National Vulnerability Database (NVD)
CISA Known Exploited Vulnerabilities (KEV)

Experience superior visibility and a simpler approach to cyber risk management