1.
CVE-2026-41940 (CVSS 9.8) is an authentication bypass in cPanel & WHM and WP Squared that injects values into server-side session files for root-level access, and was exploited before the patch.
Skip to content
Curated 1 security research writeups, vulnerability advisories and exploitation analyses for CVE-2026-41940.