A critical vulnerability CVE-2026-41940 has been identified in cPanel, WHM, and WP Squared, affecting cPanel & WHM versions after 11.40, as well as WP Squared. These web hosting control panels are commonly used to manage websites, email, databases, and server configurations, making unauthorized access a serious security concern.
CVE-2026-41940 carries a CVSS score of 9.8 (Critical) and a Bitsight Dynamic Vulnerability Exploit (DVE) score of 9.3, signaling both severe technical risk and elevated real-world threat activity. The vulnerability can be exploited remotely over the network, requires low attack complexity, and does not require privileges or user interaction.
According to Bitsight Threat Intelligence
Bitsight Threat Intelligence indicates active exploitation of CVE-2026-41940 in the wild. A public proof-of-concept (PoC) is now available, which may increase the likelihood of broader exploitation. There is currently no known exploit kit or Metasploit module associated with this vulnerability, and it is not trending on GitHub. There is no confirmed association with APT activity based on available intelligence.
CVE-2026-41940 overview
This vulnerability allows unauthenticated remote attackers to bypass authentication mechanisms in cPanel, WHM, and WP Squared. Successful exploitation may allow unauthorized access to the control panel, bypass MFA protections, and potentially grant root-level control over affected servers and hosted domains.
Exploitation activity has been observed prior to patch availability, with reports indicating execution attempts as early as February 23, 2026\. Internet-facing environments are especially important to review, as the vulnerability can be exploited remotely without valid credentials.