HomeSecurityCISA: cPanel & WHM Vulnerability in the KEV List

CISA: cPanel & WHM Vulnerability in KEV List

The new urgent warning from the US Cybersecurity and Infrastructure Security Agency (CISA) has raised alarm in the global cybersecurity community about a critical security flaw affecting two of the most widely used hosting management platforms: WebPros cPanel & WHM and WP2 (WordPress Squared) .

CISA cPanel & WHM

The US agency added the vulnerability to the Known Exploited Vulnerabilities (KEV), a move that is only made when there is confirmed evidence of active exploitation by cybercriminals.

The flaw, tracked as CVE-2026-41940, is considered extremely serious as it allows complete bypass of authentication mechanisms, giving remote attackers the ability to gain administrator access without using valid credentials.

What exactly is the CVE-2026-41940 vulnerability?

This particular vulnerability has been classified as “Missing Authentication for Critical Function”, known as CWE-306. This is a particularly dangerous category of vulnerabilities, as it essentially means that the software fails to properly verify the user’s identity before allowing them access to critical functions.

See also: NCSC: Warns of hidden vulnerabilities in software

In the case of cPanel and WP2, the problem is located directly in the login process.

This means that an attacker can bypass the login mechanism and gain administrative privileges without needing a username or password.

Simply put, the "locked door" of the server opens without even requiring a key.

Why cPanel is such an attractive target

cPanel & WHM has been a popular hosting control panel worldwide for years. It is used by hosting providers, data centers, web agencies and businesses to manage websites, databases, email accounts, SSL certificates and server configurations.

WP2 , on the other hand, is geared towards WordPress environments and has a significant presence in professional hosting ecosystems .

The massive use of these tools means that a single vulnerability can simultaneously expose thousands of servers and millions of websites.

For an attacker, successful exploitation equates to complete control of the hosting environment.

CISA: cPanel & WHM Vulnerability in KEV List

The consequences of a successful attack

Bypassing authentication on platforms of this type doesn't just lead to unauthorized access.

See also: CISA adds Linux vulnerability to KEV List

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

The attacker gains the ability to modify web page files, install web shells, redirect traffic to malicious destinations, and extract sensitive data from databases.

Even more worrying is the possibility of creating persistent backdoors, which allow access to be maintained even after an apparent system recovery.

In many cases, such breaches are the first step in broader attacks. Compromised servers can be used for phishing campaigns, malware hosting, cryptomining , or even as intermediate stations for attacks on third-party networks.

It hasn't been linked to ransomware yet, but the risk remains

CISA clarifies that so far there is no confirmed evidence linking the vulnerability to active ransomware campaigns. However, security experts emphasize that the ability to fully control a server is an ideal basis for later deployment of ransomware payloads.

In practice, an attacker can first gain access, map the environment, collect data, and then trigger file encryption or extortion actions.

This multi-stage attack model is now the dominant tactic of organized groups.

Immediate measures to be taken

CISA has already required U.S. federal agencies to take immediate remediation. The compliance deadline was set for May 3, 2026, underscoring the urgency of the situation.

System administrators are urged to apply available security patches, review access logs, and check for suspicious connections.

In cases where an immediate upgrade is not possible, it is recommended to temporarily disable the affected software.

See also: WordPress: Backdoor detected in Quick Page/Post Redirect plugin

In addition, it is recommended to enable multi-factor authentication, tighten firewall rules, and isolate critical management interfaces.

CISA: cPanel & WHM Vulnerability in KEV List

A resounding bell for the hosting industry

The CVE-2026-41940 case is a stark reminder that hosting management platforms remain among the most attractive targets for cybercriminals.

For businesses that rely on an online presence, control panel security is not just a technical issue but a critical operational factor.

The speed of response in the next few hours will determine whether the incident will remain under control or develop into one of the largest hosting security incidents of the year.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS