CVE-2026-41940CRITICAL 9.8CISA KEVEPSS p99.8%

CVE-2026-41940WebPros cPanel & WHM and WP2 (WordPress Squared) Missing Authentication for Critical Function Vulnerability

WebPros / cPanel & WHM and WP2 (WordPress Squared)

Description

WebPros cPanel & WHM (WebHost Manager) and WP2 (WordPress Squared) contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.

Scoring

CVSS 3.19.8 (CRITICAL)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS90.54% probability of exploitation · percentile 99.8% · 2026-06-15T12:03:41Z
Published2026-04-29
Last modified2026-05-04

CISA KEV entry

Added to KEV: 2026-04-30

Underlying weaknesses· 1

CWE-306

References

  1. https://docs.cpanel.net/release-notes/release-notes
  2. https://docs.wpsquared.com/changelogs/versions/changelog/#13617
  3. https://support.cpanel.net/hc/en-us/articles/40073787579671-cPanel-WHM-Security-Update-04-28-2026
  4. https://www.namecheap.com/status-updates/ongoing-critical-security-vulnerability-in-cpanel-april-28-2026
  5. https://www.vulncheck.com/advisories/cpanel-and-whm-authentication-bypass-via-login-flow
  6. https://labs.watchtowr.com/the-internet-is-falling-down-falling-down-falling-down-cpanel-whm-authentication-bypass-cve-2026-41940/
  7. https://www.bleepingcomputer.com/news/security/critrical-cpanel-flaw-mass-exploited-in-sorry-ransomware-attacks/
  8. https://github.com/watchtowrlabs/watchTowr-vs-cPanel-WHM-AuthBypass-to-RCE.py

1

TypeTargetConfidenceTier
WeaknessMissing Authentication for Critical Functioncwe-3060%live

(incoming)1

TypeTargetConfidenceTier
KEVEntryWebPros cPanel & WHM and WP2 (WordPress Squared) Missing Authentication for Critical Function Vulnerabilitykev-cve-2026-419400%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
CVE-2025-66428
CVE
CVE-2026-49782
CVE
CVE-2022-44877
CVE
CVE-2025-39491
CVE
CVE-2026-42654
CVE
CVE-2025-26871
Sourced from NVD + CISA KEV + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.