cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.
CVE-2026-41940
Score elevated to 9.8 because this CVE is listed on the CISA Known Exploited Vulnerabilities catalog (added 2026-04-30), indicating real-world exploitation has been confirmed by US federal agencies. NVD baseline CVSS 9.8 retained for reference. Confidence: HIGH.
- Actively exploited in the wild (CISA-KEV)
No vendor fix yet — apply a workaround or compensating control (WAF / firewall / segmentation) and watch for a patch.
- CVSS v3
- 9.8
- EG Score
- 9.8(high)
- EG Risk
- 99(Act)EG Risk 99/100SSVC: Act
EG Risk is EchelonGraph's 0–100 priority score: it fuses intrinsic severity with real-world exploitation and automatability so you can rank equal-severity CVEs and fix the most dangerous first. Higher = act sooner. Distinct from the 0–10 EG Score (severity).
How it’s computedSeverity98% × 45%Exploitation100% × 40%Automatability100% × 15%Action: Fix now — active exploitation, automatable, high impact. - EPSS PROB
- 98%
- EPSS %ILE
- 100%
- KEV
- ⚠ Exploited
Published
April 29, 2026
Last Modified
May 4, 2026
Advisory Details (8)
Auto-updated Jul 27, 2026Known Exploited Vulnerabilities Catalog | CISA
Known Exploited Vulnerabilities Catalog | CISA. Listed in CISA Known Exploited Vulnerabilities catalog.
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-41940GitHub - watchtowrlabs/watchTowr-vs-cPanel-WHM-AuthBypass-to-RCE.py · GitHub
https://github.com/watchtowrlabs/watchTowr-vs-cPanel-WHM-AuthBypass-to-RCE.pyCritrical cPanel flaw mass-exploited in "Sorry" ransomware attacks
https://www.bleepingcomputer.com/news/security/critrical-cpanel-flaw-mass-exploited-in-sorry-ransomware-attacks/The Internet Is Falling Down, Falling Down, Falling Down (cPanel & WHM Authentication Bypass CVE-2026-41940)
https://labs.watchtowr.com/the-internet-is-falling-down-falling-down-falling-down-cpanel-whm-authentication-bypass-cve-2026-41940/WebPros cPanel and WHM Authentication Bypass via Login Flow | Advisories | VulnCheck
https://www.vulncheck.com/advisories/cpanel-and-whm-authentication-bypass-via-login-flowNamecheap Status - Namecheap Status
https://www.namecheap.com/status-updates/ongoing-critical-security-vulnerability-in-cpanel-april-28-2026Release Notes | cPanel & WHM Documentation
https://docs.cpanel.net/release-notes/release-notesWeakness Classification(1)
MITRE Common Weakness Enumeration — the root-cause categories this CVE belongs to.
Data Freshness Timeline
(refreshed 35× in last 7d / 185× in last 30d)
Each row is a source pipeline that fetched or updated this CVE on that date, with what changed. For example, "NVD update" means NVD published or revised its analysis for this CVE; "MITRE cvelistV5" means we ingested or refreshed it from the CNA feed. Most recent first.
Showing the most recent 100 of 408 total refreshes for this CVE.
- 2026-07-28 02:56 UTCGHSA enrichment
- 2026-07-27 22:54 UTCGHSA enrichment
- 2026-07-27 19:24 UTCCISA KEV update
- 2026-07-27 18:51 UTCGHSA enrichment
- 2026-07-27 17:17 UTCCISA KEV update
- 2026-07-27 14:46 UTCEG score recompute
- 2026-07-27 14:46 UTCGHSA enrichment
- 2026-07-27 14:13 UTCEPSS rescore
- 2026-07-27 10:03 UTCGHSA enrichment
- 2026-07-27 06:01 UTCGHSA enrichment
- 2026-07-27 01:57 UTCGHSA enrichment
- 2026-07-26 21:54 UTCGHSA enrichment
- 2026-07-26 17:52 UTCGHSA enrichment
- 2026-07-26 13:48 UTCEG score recompute
- 2026-07-26 13:47 UTCGHSA enrichment
- 2026-07-26 09:44 UTCGHSA enrichment
- 2026-07-26 05:41 UTCGHSA enrichment
- 2026-07-26 01:38 UTCEG score recompute
- 2026-07-26 01:38 UTCGHSA enrichment
- 2026-07-24 14:17 UTCEPSS rescore
- 2026-07-23 03:11 UTCEG score recompute
- 2026-07-22 21:36 UTCEG score recompute
- 2026-07-22 21:35 UTCGHSA enrichment
- 2026-07-22 19:40 UTCCISA KEV update
- 2026-07-22 17:23 UTCGHSA enrichment
Show 75 moreShow fewer
- 2026-07-22 13:20 UTCGHSA enrichment
- 2026-07-22 09:16 UTCGHSA enrichment
- 2026-07-22 05:13 UTCGHSA enrichment
- 2026-07-22 01:10 UTCGHSA enrichment
- 2026-07-21 21:05 UTCGHSA enrichment
- 2026-07-21 17:01 UTCGHSA enrichment
- 2026-07-21 14:37 UTCCISA KEV update
- 2026-07-21 12:58 UTCGHSA enrichment
- 2026-07-21 08:55 UTCGHSA enrichment
- 2026-07-21 04:52 UTCGHSA enrichment
- 2026-07-21 00:50 UTCGHSA enrichment
- 2026-07-20 20:47 UTCGHSA enrichment
- 2026-07-20 16:45 UTCGHSA enrichment
- 2026-07-20 12:42 UTCGHSA enrichment
- 2026-07-20 08:39 UTCGHSA enrichment
- 2026-07-20 04:37 UTCGHSA enrichment
- 2026-07-20 00:34 UTCGHSA enrichment
- 2026-07-19 20:31 UTCGHSA enrichment
- 2026-07-19 16:29 UTCGHSA enrichment
- 2026-07-19 12:26 UTCGHSA enrichment
- 2026-07-19 08:24 UTCGHSA enrichment
- 2026-07-19 04:21 UTCGHSA enrichment
- 2026-07-19 00:18 UTCGHSA enrichment
- 2026-07-18 20:15 UTCGHSA enrichment
- 2026-07-18 16:11 UTCGHSA enrichment
- 2026-07-18 12:08 UTCGHSA enrichment
- 2026-07-18 08:05 UTCGHSA enrichment
- 2026-07-18 04:02 UTCGHSA enrichment
- 2026-07-17 23:59 UTCGHSA enrichment
- 2026-07-17 19:55 UTCGHSA enrichment
- 2026-07-17 15:52 UTCGHSA enrichment
- 2026-07-17 11:49 UTCGHSA enrichment
- 2026-07-17 07:46 UTCEG score recompute
- 2026-07-17 07:46 UTCGHSA enrichment
- 2026-07-17 03:43 UTCGHSA enrichment
- 2026-07-16 23:41 UTCGHSA enrichment
- 2026-07-16 19:38 UTCGHSA enrichment
- 2026-07-16 17:04 UTCCISA KEV update
- 2026-07-16 15:36 UTCGHSA enrichment
- 2026-07-16 11:33 UTCGHSA enrichment
- 2026-07-16 07:31 UTCGHSA enrichment
- 2026-07-16 03:28 UTCGHSA enrichment
- 2026-07-15 23:26 UTCGHSA enrichment
- 2026-07-15 19:23 UTCGHSA enrichment
- 2026-07-15 16:57 UTCEPSS rescore
- 2026-07-15 16:49 UTCCISA KEV update
- 2026-07-15 15:20 UTCGHSA enrichment
- 2026-07-15 15:04 UTCCISA KEV update
- 2026-07-15 11:17 UTCGHSA enrichment
- 2026-07-15 07:13 UTCGHSA enrichment
- 2026-07-15 03:10 UTCGHSA enrichment
- 2026-07-14 23:08 UTCGHSA enrichment
- 2026-07-14 19:04 UTCGHSA enrichment
- 2026-07-14 18:05 UTCCISA KEV update
- 2026-07-14 14:56 UTCGHSA enrichment
- 2026-07-14 10:53 UTCGHSA enrichment
- 2026-07-14 06:50 UTCGHSA enrichment
- 2026-07-14 02:47 UTCGHSA enrichment
- 2026-07-13 22:45 UTCGHSA enrichment
- 2026-07-13 18:42 UTCGHSA enrichment
- 2026-07-13 17:07 UTCCISA KEV update
- 2026-07-13 14:39 UTCGHSA enrichment
- 2026-07-13 10:36 UTCGHSA enrichment
- 2026-07-13 06:34 UTCGHSA enrichment
- 2026-07-13 02:29 UTCGHSA enrichment
- 2026-07-12 22:26 UTCGHSA enrichment
- 2026-07-12 18:23 UTCGHSA enrichment
- 2026-07-12 14:19 UTCGHSA enrichment
- 2026-07-12 10:17 UTCGHSA enrichment
- 2026-07-12 06:14 UTCGHSA enrichment
- 2026-07-12 02:11 UTCGHSA enrichment
- 2026-07-11 22:08 UTCGHSA enrichment
- 2026-07-11 18:06 UTCGHSA enrichment
- 2026-07-11 14:03 UTCGHSA enrichment
- 2026-07-11 10:00 UTCGHSA enrichment
Publicly available exploits
(10 references)Working exploit code is in the public domain (9 GitHub PoCs) (1 Exploit-DB entry). Defenders should treat patch urgency accordingly — public PoCs typically lead to mass-exploitation within 24-72 hours.
- GitHub PoCCerberusMrXi/cPanel-WHM-CVE-2026-41940-auth-bypass-exploitFirst seen Jul 26, 2026
Critical authentication bypass exploit for cPanel/WHM CVE-2026-41940. Leverages CRLF injection in cpsrvd daemon to gain root WHM access without credentials. Includes version detection, verbose logging, proxy support, JSON reporting, and post-exploitation account enumeration. For authorized security testing only.
Open source ↗ - GitHub PoCaquace/CVE-2026-41940-PoCFirst seen Jun 28, 2026
CVE-2026-41940 authentication bypass vulnerability proof-of-concept
Open source ↗ - GitHub PoCclsmight/CVE-2026-41940-PoCFirst seen Jun 16, 2026
CVE-2026-41940 exploitation proof-of-concept project
Open source ↗ - GitHub PoColofsatte/CVE-2026-41940-PoCFirst seen Jun 4, 2026
CVE-2026-41940 is a critical authentication bypass vulnerability affecting cPanel and WHM. This repository is designed to demonstrate its Proof-Of-Concept
Open source ↗ - GitHub PoCwillygailo/CVE-2026-41940-LinuxFirst seen May 27, 2026
⚠️ DISCLAIMER: This tool is intended for authorized penetration testing and educational purposes only. Using this tool against systems without explicit written permission is illegal. The developers are not responsible for any misuse or damage caused.
Open source ↗ - Exploit-DBEDB-52574First seen May 26, 2026
cPanel - CRLF Injection
Open source ↗ - GitHub PoCtc4dy/CVE-2026-41940-PoC-ExploitFirst seen May 12, 2026
🚀 CVE-2026-41940 cPanel/WHM Auth Bypass Exploit - Best Flow 💥 CRLF injection leads to auth bypass, session hijacking & account leak. ✅ Proxy, custom UA, keep-alive, retries, SSL verify, colored output, file save support. ⚡ Advanced PoC for pentesters.
Open source ↗ - GitHub PoC44pie/cpsniperFirst seen May 10, 2026
cPanelSniper STABLE - CVE-2026-41940 optimized for 10M+ targets
Open source ↗ - GitHub PoCbughunt4me/cpanelCVE-2026-41940First seen May 6, 2026
CVE-2026-41940 Auto Root Login
Open source ↗ - GitHub PoChabibkaratas/sorry-ransomware-analysisFirst seen May 4, 2026
Sorry ransomware (.sorry) IOCs, YARA rules and forensic analysis - CVE-2026-41940 cPanel campaign
Open source ↗
Related CVEs(same CWE)
Same CWE
10 shownCWE-306
- CVE-2011-10013EG 10.0CRITICAL
- CVE-2014-125124EG 10.0CRITICAL
- CVE-2017-2637EG 10.0EPSS p91CRITICAL
- CVE-2010-5326EG 10.0 KEVEPSS p97CRITICAL
- CVE-2007-0956EG 10.0EPSS p98HIGH
- CVE-2017-12822EG 9.9CRITICAL
- CVE-2016-8355EG 9.9CRITICAL
- CVE-2012-10030EG 9.8CRITICAL
- CVE-2014-3449EG 9.8CRITICAL
- CVE-2006-0062EG 9.8CRITICAL
Frequently asked(6)
What is CVE-2026-41940?
When was CVE-2026-41940 disclosed?
Is CVE-2026-41940 actively exploited?
What is the CVSS score of CVE-2026-41940?
Which products are affected by CVE-2026-41940?
How do I remediate CVE-2026-41940?
Dependency Blast Radius
Explore the affected products and dependency analysis for CVE-2026-41940
Is Your Infrastructure Affected by CVE-2026-41940?
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.