The new urgent warning from the US Cybersecurity and Infrastructure Security Agency (CISA) has raised alarm in the global cybersecurity community about a critical security flaw affecting two of the most widely used hosting management platforms: WebPros cPanel & WHM and WP2 (WordPress Squared) .

The US agency added the vulnerability to the Known Exploited Vulnerabilities (KEV), a move that is only made when there is confirmed evidence of active exploitation by cybercriminals.
The flaw, tracked as CVE-2026-41940, is considered extremely serious as it allows complete bypass of authentication mechanisms, giving remote attackers the ability to gain administrator access without using valid credentials.
What exactly is the CVE-2026-41940 vulnerability?
This particular vulnerability has been classified as “Missing Authentication for Critical Function”, known as CWE-306. This is a particularly dangerous category of vulnerabilities, as it essentially means that the software fails to properly verify the user’s identity before allowing them access to critical functions.
See also: NCSC: Warns of hidden vulnerabilities in software
In the case of cPanel and WP2, the problem is located directly in the login process.
This means that an attacker can bypass the login mechanism and gain administrative privileges without needing a username or password.
Simply put, the "locked door" of the server opens without even requiring a key.
Why cPanel is such an attractive target
cPanel & WHM has been a popular hosting control panel worldwide for years. It is used by hosting providers, data centers, web agencies and businesses to manage websites, databases, email accounts, SSL certificates and server configurations.
WP2 , on the other hand, is geared towards WordPress environments and has a significant presence in professional hosting ecosystems .
The massive use of these tools means that a single vulnerability can simultaneously expose thousands of servers and millions of websites.
For an attacker, successful exploitation equates to complete control of the hosting environment.

The consequences of a successful attack
Bypassing authentication on platforms of this type doesn't just lead to unauthorized access.
See also: CISA adds Linux vulnerability to KEV List
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
The attacker gains the ability to modify web page files, install web shells, redirect traffic to malicious destinations, and extract sensitive data from databases.
Even more worrying is the possibility of creating persistent backdoors, which allow access to be maintained even after an apparent system recovery.
In many cases, such breaches are the first step in broader attacks. Compromised servers can be used for phishing campaigns, malware hosting, cryptomining , or even as intermediate stations for attacks on third-party networks.
It hasn't been linked to ransomware yet, but the risk remains
CISA clarifies that so far there is no confirmed evidence linking the vulnerability to active ransomware campaigns. However, security experts emphasize that the ability to fully control a server is an ideal basis for later deployment of ransomware payloads.
In practice, an attacker can first gain access, map the environment, collect data, and then trigger file encryption or extortion actions.
This multi-stage attack model is now the dominant tactic of organized groups.
Immediate measures to be taken
CISA has already required U.S. federal agencies to take immediate remediation. The compliance deadline was set for May 3, 2026, underscoring the urgency of the situation.
System administrators are urged to apply available security patches, review access logs, and check for suspicious connections.
In cases where an immediate upgrade is not possible, it is recommended to temporarily disable the affected software.
See also: WordPress: Backdoor detected in Quick Page/Post Redirect plugin
In addition, it is recommended to enable multi-factor authentication, tighten firewall rules, and isolate critical management interfaces.

A resounding bell for the hosting industry
The CVE-2026-41940 case is a stark reminder that hosting management platforms remain among the most attractive targets for cybercriminals.
For businesses that rely on an online presence, control panel security is not just a technical issue but a critical operational factor.
The speed of response in the next few hours will determine whether the incident will remain under control or develop into one of the largest hosting security incidents of the year.
