CVE-2026-41940Critical· 9.8▾ Hadal⚠ Exploited in the wild0dayPoC availablecPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.
▾ Hadal zone — Critical and actively exploited (CISA KEV / 0day)
impact 53.9 · likelihood 19.7 · exploitation 25 · ransomware 5
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 4 sources. Availability, not in-the-wild use.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Federal remediation due May 3, 2026
Last analysed / modified upstream
99%
Exploit-DB · 78 GitHub repos · Metasploit ×1 · Nuclei ×1 (last check)
Added to the CISA catalog on Apr 30, 2026. Federal remediation due May 3, 2026. View catalog ↗
cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.
cpanel >= 11.40, < 86.0.41cpanel >= 88.0.0, < 110.0.97cpanel >= 112.0.0, < 118.0.63cpanel >= 120.0.0, < 124.0.35cpanel >= 126.0.1, < 126.0.54cpanel >= 128.0.0, < 130.0.19cpanel >= 132.0.0, < 132.0.29cpanel >= 134.0.0, < 134.0.20cpanel >= 136.0.0, < 136.0.5whm >= 11.40, < 86.0.41whm >= 88.0.0, < 110.0.97whm >= 112.0.0, < 118.0.63whm >= 120.0.0, < 124.0.35whm >= 126.0.1, < 126.0.54whm >= 128.0.0, < 130.0.19whm >= 132.0.0, < 132.0.29whm >= 134.0.0, < 134.0.20whm >= 136.0.0, < 136.0.5wp_squared < 136.1.7Upgrade past the affected range:
cpanel 136.0.5whm 136.0.5wp_squared 136.1.7Connected by shared product, vendor, weakness, or advisory.
CVE-2025-0108Critical· 9.1An authentication bypass in the Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web interface to bypass the authentication otherwise required by the PAN-OS management web inter…
CVE-2026-67401Critical· 9.9A vulnerability in cPanel allows a mail-enabled account to achieve remote code execution as root through SQLi in EmailTrack component
CVE-2019-5591Medium· 6.5A Default Configuration vulnerability in FortiOS may allow an unauthenticated attacker on the same subnet to intercept sensitive information by impersonating the LDAP server.
CVE-2024-0012Critical· 9.8An authentication bypass in Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web interface to gain PAN-OS administrator privileges to perform administrative actions, tamper with…
CVE-2024-51567Critical· 10.0upgrademysqlstatus in databases/views.py in CyberPanel (aka Cyber Panel) before 5b08cd6 allows remote attackers to bypass authentication and execute arbitrary commands via /dataBases/upgrademysqlstatus by bypassing secMiddleware (which i…
CVE-2025-3248Critical· 9.8Langflow versions prior to 1.3.0 are susceptible to code injection in the /api/v1/validate/code endpoint