Vulnerability
Published 2026-05-01
Verified 2026-09-19
cPanel/WHM authentication bypass, exploited in Australia
ASD's ACSC is aware of active exploitation in Australia of a critical authentication-bypass in cPanel/WHM that can lead to control-panel access and remote code execution. The vendor and the ACSC advisory body identify the issue as CVE-2026-41940 (ACSC listing text also used CVE-2026-4194). Affects versions after 11.40. Vendor patches were published from 28 April 2026; ACSC noted patches as of 30 April 2026.
- Product
- cPanel/WHM
- Versions
- All versions after 11.40 until patched
- CVSS
- (CVSS 4.0, ACSC listing)
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N - Exploited in Australia?
- yes
- Patch to
- Vendor April 2026 security update (see cPanel support article)
Primary: ASD's ACSC advisory · Vendor: cPanel security update · CVE: CVE-2026-41940, CVE-2026-4194 · cPanel support article
