CVE-2026-41940: WebPros cPanel & WHM and WP2 (WordPress Squared) Missing Authentication for Critical Function Vulnerability
Critical severity, CVSS 9.8. Actively exploited: in CISA KEV since 2026-04-30. EPSS: 98.5% chance of exploitation in the next 30 days.
cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.
Affected products
- cPanel cPanel: from 11.40, before 86.0.41 (fixed in 86.0.41); from 88.0.0, before 110.0.97 (fixed in 110.0.97); from 112.0.0, before 118.0.63 (fixed in 118.0.63); from 120.0.0, before 124.0.35 (fixed in 124.0.35); from 126.0.1, before 126.0.54 (fixed in 126.0.54); from 128.0.0, before 130.0.19 (fixed in 130.0.19); …
- cPanel WHM: from 11.40, before 86.0.41 (fixed in 86.0.41); from 88.0.0, before 110.0.97 (fixed in 110.0.97); from 112.0.0, before 118.0.63 (fixed in 118.0.63); from 120.0.0, before 124.0.35 (fixed in 124.0.35); from 126.0.1, before 126.0.54 (fixed in 126.0.54); from 128.0.0, before 130.0.19 (fixed in 130.0.19); …
- cPanel Wp Squared: before 136.1.7 (fixed in 136.1.7)
Published 2026-04-29. Last modified 2026-09-30.