Home / May 01, 2026 / Story
0
#2 CyberScoop general April 30, 2026 at 20:49 UTC

cPanel’s authentication bypass bug is being exploited in the wild, CISA warns

By Greg Otto

AI Summary

CISA added CVE-2026-41940, a critical authentication bypass vulnerability in cPanel and WHM, to its Known Exploited Vulnerabilities catalog after hosting providers confirmed active exploitation attempts since late February. The vulnerability allows attackers to gain administrative access to vulnerable servers.

Relevance score: 95.0/100

# More from May 01