Published • loading... • Updated
Critical cPanel and WHM Bug Exploited as a Zero-Day, PoC Now Available
Researchers say the flaw lets attackers log in without a password, and Rapid7 estimates about 1.5 million cPanel instances are exposed online.
Summary by BleepingComputer
7 Articles
7 Articles
'The Internet is falling down': Critical cPanel CRLF injection vulnerability puts tens of millions of websites at risk of total compromise – hosting providers urged to apply CVE-2026-41940 patch immediately
A new critical severity vulnerability can give attackers full control over WHM servers, allowing them to steal data, upload malware, and delete websites.
·United Kingdom
Read Full ArticleThe discovery of a vulnerability in the cPanel identified as CVE-2026-41940 ignited an urgent alert in the hosting and security community. The failure, classified as zero-day, is being actively explored since February and allows authentication bypasses, opening the way for unauthorized access to servers. Considering the wide adoption of cPanel and WHM in shared hosting environments and VPS, the potential impact is significant. System administrat…
Coverage Details
Total News Sources7
Leaning Left0Leaning Right0Center2Last UpdatedBias Distribution100% Center
Bias Distribution
- 100% of the sources are Center
100% Center
C 100%
Factuality
To view factuality data please Upgrade to Premium


