Vulnerabilities · 125 days ago

cPanel Control Plane Breach Threatens Entire Hosting Fleets

cPanel/WHM is the control plane for hosted environments, so an auth bypass there turns one panel compromise into access across every site and account it manages. The standard response of patching the panel misses the backdoor problem already seen in the wild: attackers are keeping access with a Filemanager implant and using it to steal credentials.

QiAnXin XLab tied CVE-2026-41940 exploitation to Mr_Rot13 and said more than 2,000 attacker source IPs are involved in automated attacks. The activity has already been linked to backdoor implantation, persistence, credential theft, and other abuse on cPanel and WHM systems.

That changes the risk from a single vulnerable host to a durable foothold inside hosting environments. If the panel stays trusted after compromise, attackers can reuse it to reach hosted services and the credentials tied to them.

CVE-2026-41940

NVD KEV

Known exploited · CISA KEV

CVSS 9.8 CRITICAL: cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows… EPSS 99% (100th percentile).

CISA federal remediation date May 3 · date passed

Timeline

Sources

2 sources covering this story

Entities

Part of the PlainSec briefing for 2026-05-17

Editions

Related stories