CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

The Internet Is Falling Down, Falling Down, Falling Down (cPanel & WHM Authentication Bypass CVE-2026-41940)

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 560

As cited

Copy frozen at (site build).

vulnerabilities

The Internet Is Falling Down, Falling Down, Falling Down (cPanel & WHM Authentication Bypass CVE-2026-41940)

cPanel & WHM, which manages over 70 million domains, contains an authentication bypass vulnerability (CVE-2026-41940) affecting all currently supported versions. The flaw in session loading and saving mechanisms has been exploited in the wild as a zero-day, and cPanel has released patches across multiple version tracks (110.0.x through 136.0.x) to address the issue.

Why it matters: Hosting providers and system administrators using cPanel & WHM must immediately patch affected systems, as this authentication bypass provides administrative access to the management plane and has already been exploited by threat actors.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

The Internet Is Falling Down, Falling Down, Falling Down (cPanel & WHM Authentication Bypass CVE-2026-41940)

cPanel & WHM, which manages over 70 million domains, contains an authentication bypass vulnerability (CVE-2026-41940) affecting all currently supported versions. The flaw in session loading and saving mechanisms has been exploited in the wild as a zero-day, and cPanel has released patches across multiple version tracks (110.0.x through 136.0.x) to address the issue.

Why it matters: Hosting providers and system administrators using cPanel & WHM must immediately patch affected systems, as this authentication bypass provides administrative access to the management plane and has already been exploited by threat actors.

VendorsZoom
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary