Active exploitation of cPanel/WHM critical vulnerability

Published: 12/05/2026 01:36 AM Category: Alert CVE: CVE-2026-41940
CRITICAL SEVERITY

Background

Fiji CERT is aware of active exploitation in Australia of a critical vulnerability (CVE-2026-41940) affecting cPanel/WHM products. 

  • The vulnerability is an authentication bypass, which can allow unauthenticated remote attackers to gain access to the control panel, as well as conduct remote code execution (RCE).

The vulnerability affects all versions after 11.40 (which was released in 2013).

  • Patches have been released as of 30 April 2026.

Fiji CERT does not have information to indicate that a specific industry or sector is being targeted, however it is noted that products managed by several Managed Service Providers have been impacted, resulting in the compromise of their customers.

Mitigation advice

Fiji CERT advises organisations to ensure the following:

  • Review networks and environments for use of vulnerable versions of cPanel and WHM products.
  • Review the need to continue to have the interface exposed to the internet.
  • If your cPanel and WHM products are managed by a third party such as a Managed Service Provider, you should contact this manager to ensure the products have been patched and are being monitored for suspicious activity.
  • Apply patches as soon as practicable, if required.
  • Monitor for suspicious activity. Indicator of Compromise (IoC) detection scripts have been released by the vendor, which may assist in detecting compromise. This can be found on the vendor support page.
  • If suspicious activity is detected, notify Fiji CERT