Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

CVE-2026-41940 cPanel & WHM Authentication Bypass Overview and Takeaways

Summary

CVE-2026-41940 (CVSS 9.8) is an authentication bypass in cPanel & WHM and WP Squared that injects values into server-side session files for root-level access, and was exploited before the patch.
CVE
CVE-2026-41940
Published
Collected

original ↗