cPanel and WHM CVE-2026-41940: Critical Auth Bypass Exploited Since February 2026
A critical pre-auth bypass in cPanel/WHM (CVE-2026-41940) has been actively exploited since Feb 2026 and is listed on the CISA KEV. With 1.5M instances exposed to ransomware and botnets, GCC hosting operators and enterprise networks must apply the vendor patches immediately.

Web hosting server rack with amber and red warning indicators in a data centre, representing the critical authentication bypass in cPanel and WHM CVE-2026-41940 that has been actively exploited across enterprise hosting infrastructure since February 2026
A critical pre-authentication vulnerability in cPanel and WHM, the world's most widely deployed web hosting control panel, has been actively exploited in the wild since at least February 2026, two months before the vendor published its advisory and emergency patch. The flaw, tracked as CVE-2026-41940, carries a CVSS 3.1 score of 9.8 and allows an unauthenticated remote attacker to gain root-level access to the WHM administrative interface without any credentials. CISA added CVE-2026-41940 to its Known Exploited Vulnerabilities catalogue on 1 May 2026. Multi-actor exploitation has since been confirmed across the global hosting ecosystem, with ransomware operators, credential-harvesting groups, and Mirai botnet variants all observed targeting vulnerable instances.
How the Vulnerability Works
The flaw lies in how cPanel's service daemon, cpsrvd, handles session file creation before authentication completes. During a failed login attempt, cpsrvd writes a new pre-authenticated session file to disk. An attacker can manipulate the whostmgrsession cookie by omitting an expected segment of its value, triggering a code path that skips the encryption process normally applied to attacker-controlled cookie data. A subsequent request then promotes that manipulated session into a fully authenticated WHM root session, granting complete administrative access to the server. The entire chain requires no credentials, no prior access, and no user interaction. A free account and network access to the target are sufficient.
The disclosure timeline is particularly concerning. According to managed hosting provider KnownHost, exploitation was observed on their infrastructure as early as 23 February 2026. cPanel was reportedly notified approximately two weeks before the 28 April public advisory, and initial internal assessments indicated nothing was wrong. That gap between confirmed in-the-wild exploitation and vendor response left millions of instances exposed without mitigation guidance.
The Scope of Exposure
A Shodan query for internet-exposed cPanel instances returns approximately 1.5 million potential targets. At peak exploitation following the public disclosure, the Shadowserver Foundation detected more than 44,000 unique IP addresses scanning, running exploits, or engaging in brute-force attacks against honeypot sensors. Exploitation evolved rapidly from proof-of-concept probing into multi-actor campaigns. Confirmed post-compromise activity includes website defacement, file encryption by a Go-based Linux ransomware encryptor, deployment of Mirai botnet variants that created new administrative accounts and disabled security logging, installation of cryptocurrency miners, and credential harvesting from other accounts hosted on the same infrastructure. The Indonesian defence-sector and Chinese railway-sector targeting documented by threat researcher Ctrl-Alt-Intel indicates that nation-state adjacent operators have also used this vulnerability for targeted intelligence collection alongside opportunistic criminal exploitation.
WHM compromise is not limited to the target server. Because WHM manages multiple cPanel accounts on a single host, a successful breach effectively compromises every website, database, and email system running on that server. For shared hosting providers, a single compromised WHM instance exposes the entire hosted customer base simultaneously.
GCC Relevance
cPanel and WHM are deeply embedded across GCC enterprise hosting environments, managed service providers, telecommunications companies running hosting services, and government-adjacent organisations using hosted web infrastructure. The UAE and Saudi Arabia have rapidly expanding digital infrastructure ecosystems where cPanel-powered hosting is a standard component of web presence management, e-commerce operations, and public-sector portal hosting. Organisations that host their web properties on cPanel-powered infrastructure, whether directly or through managed hosting providers, should verify patch status immediately regardless of whether they manage the server themselves. For UAE enterprises subject to NESA Information Assurance Standards, this vulnerability falls directly within mandated patch management and critical infrastructure protection obligations.
Remediation
cPanel released patched builds across all supported branches on 28 April 2026. Administrators should run /usr/local/cpanel/cpanel -V to confirm the installed build reflects the patched release, or verify with their hosting provider directly. If using a hosting provider, confirm patch status with them in writing rather than assuming updates have been applied.
For organisations assessing whether prior exploitation may have occurred, cPanel's vendor detection script performs filesystem-based triage. Security teams should specifically check /var/cpanel/sessions/raw/ for pre-auth session files containing user=root, hasroot=1, tfa_verified=1, or multiple pass= lines on separate rows, as these are confirmed forensic indicators of exploitation. WHM should also be audited for unexpected user accounts, SSH keys, and cron jobs. Cato Networks has confirmed that exploitation attempts were associated with source infrastructure geolocated to Ireland, Japan, and the United States, linked to DigitalOcean, Amazon, and Latitude.sh ASNs. Blocking inbound traffic on ports 2083, 2087, 2095, and 2096 is the primary interim mitigation for organisations unable to patch immediately.
The FortiBleed credential harvesting campaign documented across GCC enterprise environments this month demonstrates the direct consequence of delayed patching on network perimeter infrastructure. CVE-2026-41940 represents the same class of unauthenticated pre-auth bypass, applied to the web hosting control plane rather than the network gateway. Organisations that move promptly remove a critical attack vector. Those that wait inherit the same exposure window that has already produced confirmed ransomware deployments and credential theft across the global cPanel estate.
Omar Al-Hakeem
Senior Cyber Threat Analyst | MENA RegionOmar Al-Hakeem is a cybersecurity researcher specializing in threat intelligence, ransomware trends, and nation-state activity across the Middle East and North Africa. With over 12 years of experience in SOC operations and incident response, he provides deep technical breakdowns of emerging attacks and regional cyber risks. At MENA Cyber Wire, Omar focuses on real-world threat analysis and actionable defense strategies for enterprises and startups.