The web hosting world is reeling from the full disclosure of a critical authentication bypass in cPanel and WHM that has left as many as 1.5 million servers vulnerable. Tracked as **CVE-2026-41940**, this vulnerability allows an unauthenticated, remote attacker to gain root-level administrative control over the host system. [Cybersecurity Dive](https://www.cybersecuritydive.com/news/critical-vulnerability-cpanel-widespread-exploitation/819208) [Help Net Security](https://www.helpnetsecurity.com/2026/04/30/cpanel-zero-day-vulnerability-cve-2026-41940-exploited)
Evidence has surfaced that attackers have been weaponizing this flaw as a zero-day since at least February 23, 2026. The Shadowserver Foundation recently recorded over 44,000 compromised servers participating in scanning and brute-force attacks. CISA has added the flaw to its KEV catalog, mandating federal agencies to patch within four days. [SecurityWeek](https://www.securityweek.com/critical-cpanel-whm-vulnerability-exploited-as-zero-day-for-months/amp) [eBuilder Security](https://ebuildersecurity.se/en/cyber-news/cpanel-cve-2026-41940-zero-day-exploited-months-before-patch)
The exploit chains three weaknesses: a CRLF injection in the HTTP Basic Authentication handler, an encryption-skip triggered by a malformed cookie, and a quirk in session caching. This allows an attacker to inject attributes like ‘user=root’ and ‘tfa_verified=1’, tricking the server into granting full access. [Picus Security](https://www.picussecurity.com/resource/blog/cve-2026-41940-explained-cpanel-whm-authentication-bypass-hit-1-5m-servers) [Halo Security](https://blog.halosecurity.com/cve-2026-41940-critical-cpanel-whm-authentication-bypass-under-active-exploitation)
Because exploitation yields root-level control, it has become a primary target for ransomware groups. Security researchers are urging immediate action: patch to a fixed build, restart the service, and rotate all administrative credentials. [Bank Info Security](https://www.bankinfosecurity.com/ransomware-wielding-attackers-target-cpanel-whm-software-a-31598) [Malwarebytes](https://www.malwarebytes.com/blog/news/2026/05/actively-exploited-cpanel-bug-exposes-millions-of-websites-to-takeover)