CVE-2026-41940 is a critical authentication bypass vulnerability in cPanel/WHM actively exploited in the wild. Over 100,000 servers are at risk.
On April 30, 2026, security researchers discovered attackers exploiting a zero-day vulnerability in cPanel/WHM that allows unauthenticated remote code execution. The vulnerability affects:
Attackers can:
Run: /scripts/upcp --force
This updates to version 11.119+ which patches CVE-2026-41940.
Look for suspicious activity:
WHM → Security Center → Two-Factor Authentication
WHM → Security Center → cPHulk Brute Force Protection
If you're concerned about cPanel security, consider these alternatives:
Pros: Modern UI, better security track record, Windows support
Cons: More expensive than cPanel
Price: $10-15/mo
Pros: Lightweight, affordable, good security
Cons: Less feature-rich than cPanel
Price: $5/mo
Pros: Free, open-source, LiteSpeed integration
Cons: Smaller community, fewer plugins
Price: Free
Check your cPanel version: WHM → Server Information. If it's 11.110-11.118, you're vulnerable.
Restrict WHM access to specific IPs via firewall rules. This reduces attack surface but doesn't eliminate the vulnerability.
cPanel remains widely used and generally secure. This zero-day is serious but not unprecedented. Keep your system updated and follow security best practices.
Most managed hosting providers will patch automatically. Contact your provider to confirm.
Run: grep "authentication bypass" /var/log/messages and check for suspicious root logins in /var/log/secure.
Last updated: May 2, 2026 by Sarah Chen