LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2026-41940: WebPros cPanel & WHM and WP2 (WordPress Squared) Missing Authentication for Critical Function Vulnerability

RBRecent Breaches Vulnerability Intelligence·Apr 30, 2026
Critical⚠ Actively exploited (CISA KEV)Ransomware-linked
Critical
Severity
Active
CISA KEV
Yes
Ransomware use
May 3, 2026
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2026-41940 to its Known Exploited Vulnerabilities catalog on Apr 30, 2026, with a federal patch deadline of May 3, 2026 — meaning attackers are actively using it. If you run the affected software, patch it immediately. Ransomware crews are known to exploit this flaw.

WebPros cPanel & WHM (WebHost Manager) and WP2 (WordPress Squared) contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized…

WebPros cPanel & WHM and WP2 contain an authentication bypass vulnerability that lets unauthenticated remote attackers reach the control panel without valid credentials. The flaw is tracked as CVE-2026-41940 and is a CWE-306 weakness. Because the products manage web hosting environments, successful exploitation can expose customer sites, email, and server configuration data; known ransomware activity has been associated with this class of access.

How it works

CWE-306 describes missing authentication for a critical function. In this case the login flow does not enforce credential checks for certain requests, allowing an attacker to reach administrative interfaces directly. An attacker supplies crafted requests that the affected component treats as already authenticated. No further details on request construction or bypass technique are provided in the available information; confirm exact mechanics against the vendor advisory.

Am I affected? How to find it in your systems

Inventory all internet-facing or internally accessible installations of cPanel & WHM and WP2. These control panels are typically deployed on Linux-based web hosting servers and are reached through standard web ports. Check installed versions and any custom login or authentication configurations. Review vendor-supplied patch lists or release notes to determine whether a given instance is covered; specific version checks must be confirmed against the vendor advisory. Look for authentication logs that show successful logins without corresponding credential events or from unexpected source addresses.

How to remediate

Apply the vendor update referenced in the official advisory as the primary remediation. After patching, review authentication settings for the login flow and ensure that all administrative paths require valid credentials. Disable or restrict any legacy or alternative login mechanisms that bypass the primary flow. Follow applicable CISA BOD 22-01 guidance for cloud-hosted instances.

If you can't patch immediately

If your data may have been exposed

Actively exploited vulnerabilities of this type have led to unauthorized access and subsequent data exposure or ransomware deployment. Organizations can run a free exposure scan of their email addresses against known breach data to determine whether credentials or other information have already appeared in public datasets.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedWebPros · cPanel & WHM and WP2 (WordPress Squared)
WeaknessCWE-306
Added to CISA KEVApr 30, 2026
Federal patch deadlineMay 3, 2026
Known ransomware useYes
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities