cPanel WHM Authentication Bypass Zero-Day | MSSP Advisory
Critical
DateMay 1, 2026
📋Executive Summary
CVE-2026-41940 is a critical authentication bypass vulnerability in cPanel and WHM that bypasses all login protections and grants attackers full administrative access to hosting control panels. Attackers have been exploiting this zero-day since late February, and a public proof-of-concept is now available making exploitation trivial.
⚠️Why It Matters for MSSPs
Your clients running shared hosting, dedicated servers, or VPS environments with cPanel are sitting ducks for complete server takeover through their hosting control panels. If you manage hosting infrastructure for clients or use cPanel in your own lab environments, attackers can bypass every security control and gain root-level access to compromise your entire client base.
📬
Get notified when client-ready advisories like this are published each week.
Join the MSSP Watchlist →🏷️Threat Category
Zero-Day
Partner MSSPs receive the full advisory — talking points, actions, and social posts — under their own brand.