Skip to main content
Back to Blog
6 May 2026, byZebrabyte Breaches and incidents

CVE-2026-41940: Critical Vulnerability cPanel/WHM — Complete Remedial Guide

CVE-2026-41940: Critical Vulnerability cPanel/WHM — Complete Remedial Guide

On April 28, 2026, cPanel quietly released an emergency patch. The next day, watchTowr Labs released the exploit. Between the two moments, over two million hosting servers...

On April 28, 2026, cPanel quietly released an emergency patch. The next day, watchTowr Labs released the exploit. Between the two moments, over two million hosting servers stood literally with the wide open door to the internet.

If you manage a cPanel/WHM server — or have a website hosted on one — the next 14 minutes of reading can make the difference between a quiet weekend and a 72 hourGDPRnotification.

Rezumat executiv

Critical Vulnerability authentication bypass affects it toate versiunile suportate With one carefully built HTTP application — no user, no password, no token, no interaction by anyone — an internet attacker can get a full privileged administrative session.

  • Identificator: CVE-2026-41940

  • Severitate: CVSS 9.8 (Critical) — Confirmed operation in real environments

  • Cauza: CRLF (\r\n) injection into the session file creation stream

  • The immediate action: Apply the official patch or block ports 2083 and 2087

  • Customers ofZebraByte: Our managed hosting infrastructure is not affected (we run theZebraBytepanel, not the cPanel)

What you find in this article

  1. Anatomy of vulnerability — what it means, in simple language

  2. How exploitation works — the story of a \r\n

  3. Chronology of the incident — from zero-day to public PoC in 24h

  4. Who is affected and who is not

  5. Real Impact — Why It's a Disaster for a Host

  6. How to apply the patch – step by step

  7. Temporary mitigations if you can’t update immediately

  8. Compromise Indicators (IOCs) — How to Check If You've Been Attacked

  9. Lessons for Online Business Owners

  10. HowZebraBytehelps you

  11. Frequently asked questions

Anatomy of Vulnerability

For those who do not administer daily hosting servers: cPanel and WHM (WebHost Manager) are the web control panels used to administer most shared hosting servers in the world. cPanel is the client interface — where you manage your emails, databases, websites,SSLcertificates. WHM is the administrator interface — virtually the keys of the entire kingdom.

According to watchTowr Labs and estimates published by Eye Security, we are talking about More than 70 million areas and More than 2 million cPanel courts exposed directly on the InternetIt is one of the largest attack areas in the entire hosting ecosystem.

On April 28, 2026, cPanel released an emergency security update described as “a problem with loading and saving sessions”. CVE-2026-41940, CVSS score 9.8, and has been reclassified as what it actually is: a bypass complet de autentificare.

What does “authentication bypass” mean in this context:* The attacker doesn’t have to guess passwords. He doesn’t have to intercept sessions. He doesn’t have to persuade anyone to click a link. He doesn’t even need a valid account on the server. He sends a normal HTTP request, formulated in a certain way, and the server returns him a session with permission to rootand so much. *

Where it comes from, structural

cPanel has evolved for two decades. During this period, around the login stream have gradually been added Multiple auxiliary authentication methods: HTTP Basic Auth, fallback streams,APIintegrations, session recovery after service restart. Each path was added with a valid intention — but with a slightly different set of assumptions about what "authenticated request" means.

When cpsrvd (cPanel Service Daemon) service receives a login request, write a message on the disk File of Session The logic is: we write the file, generate the token, validate credentials, then overwrite the file if necessary.

In practice, this order creates a window in which the session file exists on the disk before the actual authentication happened. And there comes the brilliant (and for hosting providers, terrifying) part of the exploit.

How the exploitation works

Technically, CVE-2026-41940 is a CRLF injection — injection of Carriage Return and Line Feed (\r\n) characters in a context where the user input is written without sanitization in a file structured on lines.

When you send a login request to WHM, the server responds with a session cookie, regardless of whether the login is successful or not:

POST /login/?login_only=1 HTTP/1.1
Host: target:2087
Content-Type: application/x-www-form-urlencoded
Content-Length: 20
user=root&pass=wrong

Response from the server:

HTTP/1.1 401 Access Denied
Set-Cookie: whostmgrsession=:Wg_mjzgt1hyfXefK,1bd3d4bf...; HttpOnly; secure
Content-Type: text/plain
{"status":0,"message":"see_login_log"}

The Critical Observation: The session cookie is issued even on a failed logincPanel issues it so that it can correlate authentication logs. The cookie has the form name_session,hash, where nume_sesiune It is controlled by the server. hashIt is derived from the user’s input through encryption.

Here is the trap: if the attacker deliberately omitted Part with the hash in the cookie and instead uses an Authorization header: Basic with a special payload, cPanel jumps over the normal encryption routine and directly writes the raw content of the Basic Auth credentials into the session file.

And Basic Auth credentials can contain \r\n after base64 decoding. and the session file is a text format structured on lines (key=value, an attribute per line).

The logical conclusion:* the attacker encodes a sequence of any type in Basic Auth. cPanel decodes it, writes it into the session file without sanitizing it, and at the next request — with the same session name — the server reads the file, sees the user=root attribute entered by the attacker himself, and issues a fully privileged session.

This is not a code execution vulnerability, broken encryption, or exotic buffer overflow. logically — the exact type of error that manages to get into production when several authentication paths evolve independently from each other and someone forgets to check what is happening at the intersection.

Ironically, it is one of the oldest classes of vulnerabilities known. CRLF injection has appeared in the web security literature since the 2000s. The fact that it manages to make its appearance in 2026 in a product that manages 70 million domains is, in itself, a lesson.

3. Cronologia incidentului

28 April 2026, morning — cPanel releases the security update. The official bulletin discreetly mentions “a problem with loading and saving sessions”. Patches for all supported branches. KnownHost subsequently confirms that the vulnerability was already used as zero-day against their clients.

29 April 2026, morning — CVE-2026-41940 (CVSS 9.8) is assigned. Namecheap is implementing temporary blocking of ports 2083 and 2087 at firewall level for all clients until the patch is applied.

29 April 2026, afternoon — watchTowr Labs releases the exploit. Researcher Sina Kheirkhah publishes complete technical analysis with proof-of-concept function. Eye Security identifies over 2 million cPanel courts directly on the Internet at the time of disclosure.

29–30 April 2026 — Public adoption of the exploit. Telemetry providers observe massive scans on ports 2083/2087 from residential IP spaces and abused clouds. Rapid7, GreyNoise and Field Effect publish their own alerts. The Belgian CCB Center classifies the incident as “critical warning”.

30 April 2026, today — the patch window is open but closes quickly. Conservative estimates suggest that tens of thousands of exposed servers are still vulnerable. cPanel Auto-Update is the safest solution for those who have not responded within the first 48 hours.

Who is affected (and who is not)

Vulnerability affects toate versiunile curent suportate by cPanel & WHM, plus the WP Squared product. The table below includes the version lines and the minimum patch-forgotten review:

Version line Previous status (vulnerable) Patch-forgotten version

  • cPanel & WHM 110.0.x — ≤ 11.110.0.96 — 11.110.0.97

  • cPanel & WHM 118.0.x — ≤ 11.118.0.61 — 11.118.0.63

  • cPanel & WHM 126.0.x — ≤ 11.126.0.53 — 11.126.0.54

  • cPanel & WHM 132.0.x — ≤ 11.132.0.27 — 11.132.0.29

  • cPanel & WHM 134.0.x — ≤ 11.134.0.19 — 11.134.0.20

  • cPanel & WHM 136.0.x — ≤ 11.136.0.4 — 11.136.0.5

  • WP Squared — ≤ 136.1.6 — 136.1.7

If you are running any version prior to the above, or a Unbearable (each prior to 11.40), your server is vulnerabil Apply the patch.

And theZebraBytecustomers?

TheZebraByteinfrastructure is not affected. Our managed hosting services —WordPress, Odoo, shared hosting — run on theZebraBytein house panel and on proprietary stacks protected byCloudflareEnterpriseWAF. We do not use cPanel/WHM on the managed hosting line. NoZebraBytehosting account is exposed to CVE-2026-41940.

If you manage a VPS sau server dedicat propriu where you have installed cPanel/WHM (even through third-party providers), you are responsible for applying the patch. TheZebraByteteam can take over the remedy for a fee — see the final section.

5. Impactul real

When we say “CVSS 9.8”, it’s easy to get out of the numbers. But in a shared hosting context, this vulnerability concrete means:

  • Completion of the server. This means access to every hosted site, every MySQL database, every email box, every FTP/SSH account, every locally stored privateSSLkey.

  • Escalate to Code Execution (RCE) The WHM session allows the installation of packets, cron scripts, PHP configuration changes — which leads directly to OS control on the machine.

  • Pivot to the customer network. If the cPanel server has VPN connections or access to internal networks (often in SMB settings), the attacker enters directly into the client infrastructure beyond the hosting.

  • Backdoor-uri persistente. Newly created WHM accounts, SSH keys added to ~/.ssh/authorized_keys, programmed crons, malware injected into all hosted clients’WordPressthemes.

  • Theft of credentials and lateral escalation. The databases contain hash-uites, but alsoAPIkeys, payment tokens, third-party integrations. Modern attackers don’t stop at the compromised server.

  • Implications are severe. For hosts with EU/UK clients, a compromise of this nature triggers the obligation to report to ANSPDCP/ICO within 72 hours (Art. 33GDPR), plus individual notification to the data subjects if the risk is high (Art. 34).

“Imagine your keys to the kingdom, and the kingdom is the internet, and the apartments are the sites of everyone.” — watchTowr Labs, about WHM

6. Cum aplici patch-ul

The official cPanel patch is distributed through the standard update channel. auto-update activatIt is very likely that it has already been applied in the night of April 28 to 29.

Step 1: Check the current version

# Conectat ca root prin SSH
/usr/local/cpanel/cpanel -V
# Output exemplu — caută versiunile patch-uite din tabel
11.134.0.20 (build 1)

Step 2 – Forcing the update

# Rulează update-ul oficial cPanel forțat
/usr/local/cpanel/scripts/upcp --force
# Apoi restartează serviciul de daemon
/scripts/restartsrv_cpsrvd
# Verifică că noua versiune rulează
/usr/local/cpanel/cpanel -V

Step 3 — Activate Auto-Update (if not already)

Connect to WHM as root and navigate to WHM → Server Configuration → Update PreferencesMake sure that:

  • Daily Updates: setat pe Automatic (RECOMMENDED)

  • cPanel Release Tier: RELEASE or STABLE — never EDGE on production servers unless you have a good reason

  • Operating System Package Updates: setat pe Automatic

Step 4 – Restart with discipline

The patch touches cpsrvd and session flow. After updating, make sure that the daemon has really been restarted:

ps -ef | grep cpsrvd
# Caută PID-ul recent — uptime-ul procesului trebuie să fie post-update
# Verifică și serviciile aferente
/scripts/restartsrv_cpdavd
/scripts/restartsrv_dovecot
/scripts/restartsrv_exim

Temporary mitigations

If for operational reasons you cannot apply the patch at this time (e.g. scheduled maintenance, backup in progress, reliance on a third-party release manager), you must block the attack at network level until you can update.

Basic mitigation — port blocking

The most effective temporary measure is to restrict access to cPanel/WHM ports only to trusted IPs:

# iptables — permite doar IP-ul tău administrativ
iptables -I INPUT -p tcp --dport 2083 -j DROP
iptables -I INPUT -p tcp --dport 2087 -j DROP
iptables -I INPUT -p tcp -s "YOUR.ADMIN.IP/32" --dport 2083 -j ACCEPT
iptables -I INPUT -p tcp -s "YOUR.ADMIN.IP/32" --dport 2087 -j ACCEPT
# Salvează regulile
iptables-save > /etc/iptables/rules.v4
# Opțional, poți bloca și 2095 (Webmail) și 2096 (Webmail SSL)
# dacă serviciile respective nu sunt critice pentru clienții tăi

Mitigare la edge — Cloudflare WAF

If your server is behindCloudflare(recommended in 2026), you can create a custom rule to block suspicious requests to the /login/ endpoint:

(http.request.uri.path eq "/login/") and
(http.request.method eq "POST") and
(http.request.headers["authorization"][0] contains "Basic ") and
(not ip.src in {YOUR.ADMIN.IP})

Important: mitigarea ≠ remediere. Port blocking andWAFrules buy time — no more than a few days. The only permanent solutionDon’t leave your server in “paranoid mode” for weeks hoping it will be enough.

8. Indicatori de compromis (IOC)

If your server has been exposed to the internet in recent days, it assumes compromise until you prove the opposite. The patch closes the door for the future — but it does not fix anything if the attacker has already entered before Monday morning.

What to look for in logs

# 1. Cereri POST către endpoint-ul de login cu Basic Auth — punctul de injecție
grep -E "POST /login/.*login_only=1" /usr/local/cpanel/logs/access_log
grep "Authorization: Basic" /usr/local/cpanel/logs/access_log
# 2. Caractere CR/LF anormale în log-ul de login
grep -P "[\r\n]" /usr/local/cpanel/logs/login_log
# 3. Sesiuni create fără login_log corespunzător
ls -la /var/cpanel/sessions/raw/*/
# Compară timestamp-urile fișierelor de sesiune cu intrările din login_log
# 4. Conturi WHM noi sau privilegii modificate recent
grep -i "createacct" /usr/local/cpanel/logs/access_log | tail -50
cat /var/cpanel/users/* | grep -i "OWNER\|RESELLER"
# 5. Chei SSH adăugate recent
find /root /home -name authorized_keys -mtime -7 -ls
# 6. Job-uri cron suspecte create recent
find /var/spool/cron /etc/cron.d -mtime -7 -type f -ls
# 7. Fișiere cu setuid scrise recent (frecvent pentru backdoor-uri)
find / -perm -4000 -mtime -7 -type f 2>/dev/null
# 8. Procese rulate de utilizatori neașteptați
ps -eo user,pid,cmd | grep -vE "^(root|nobody|mysql|named|mail|cpanel)"

Network indicators

  • Outbound connections to unknown domains or IPs, especially on unusual ports (4444, 8080, 1337, 31337)

  • Increased DNS traffic to external resolvers in the *.dyndns, *.duckdns, *.no-ip space

  • Regular ICMP/UDP outbound requests to the same destination (C2 beacon sign)

If you find positive IOCs: Do not attempt to “cut” the server. Restart from zero., restores data from a pre-incident backup, rotates all credentials (SSH, MySQL, WHM, client emails), notifies ANSPDCP/ICO within 72 hours underGDPRArt. 33, and contacts a specialist in response to incidents.ZebraBytecan take over this process — see the final section.

Lessons for Online Business Owners

Even if you don’t manage your cPanel server — even if all you do is have a site that’s hosted somewhere — this story should tell you something.

Your hosting provider is part of your security chain

Many business owners treat hosting like electricity — an invisible resource that “just works”.But your provider has access to every email of your customers, every database, every payment form. What panel version do you run? What SLA do you have for critical patches? Do you have public security audits?

Auto-update is not optional in 2026

The window between disclosure and mass exploitation fell below 24 hours. The argument “I prefer to manually check every patch” expired around 2018. If you don’t have self-updates, you have a clock that ticks.

Defense in depth matters.

Your stack must have layers:WAFto edge (Cloudflare), account-level isolation (PHP-FPM separately per user, OS-level confinement), immutable backups (snapshots at another provider), behavioral monitoring, and an incident response plan you have tested.

Backups should be tested, not just created

The most painful data losses in recent years are not those where there were no backups. They are those where backups existed but were corrupted, encrypted by the same attack, or simply didn’t recover. Test restoration at least quarterly.

Crisis communication is as important as technology

If you have an incident, your customers will find out. The question is: will they find out from you, or from a third party?status.example.comCustomer communication templates, and relationship with a legal specialist for notificationsGDPR before In the middle, not in the middle.

HowZebraBytehelps you

If you manage a VPS or dedicated server with cPanel/WHM and you are not sure about its status, our incident response team can complete evaluation, patch and hardening in hours, not days. We work on third-party stacks — Hetzner, Contabo, OVH, own infrastructure — without changing provider.

For existingZebraBytecustomers, this rating is offered free of charge if you have a subscription Security ManagedFor new customers, the intervention is a single, fixed purpose, no surprises.

Contact us to:

11 frequently asked questions

If my cPanel server is not exposed to the internet (it’s only on the internal network), am I safe?

Less exposed, but not immune. The attacker only needs network access to the WHM port. This means that anyone with access to your VPN, anyone on the internal segment, or any other compromised machine in the network can attack the cPanel server. The patch remains mandatory. Single-tenant, network isolation and zero-trust internal are no excuses to skip over a 9.8 CVSS patch.

Can I detect if my server has been attacked retroactively through a commercial scanner?

Suppliers such as Rapid7 (Nexpose/InsightVM), Tenable (Nessus) and GreyNoise have released authenticated signatures for CVE-2026-41940 as of April 30, 2026. You are vulnerableTo detect an active compromise you need log analysis (see IOC section) and ideally an EDR (Endpoint Detection & Response) such as Wazuh, CrowdStrike or SentinelOne.

Furnizorul meu de hosting (Namecheap, Bluehost, etc.) a aplicat deja patch-ul?

Major shared hosting providers (Namecheap, HostGator, GoDaddy, Bluehost, A2 Hosting) have applied patches in the first 24-48 hours after disclosure, some with temporary port blocking in parallel. If you are a shared hosting customer at one of them, you don’t have to do anything — but it’s a good opportunity to proactively spin your cPanel passwords. Check their status page for confirmation.

I use Plesk instead of cPanel — am I affected?

No. CVE-2026-41940 is specific to cpsrvd implementation in cPanel & WHM. Plesk, DirectAdmin, ISPConfig, CWP, HestiaCP — all use different authentication streams and are not affected by this vulnerability. That doesn’t mean you don’t have your own patches to do — check your panel’s update cycle.

Could the attacker decrypt my data if the server was compromised?

Yes, if the cryptographic keys were stored on the server. WHM with root privileges has access to theSSL/TLSprivate keys of all hosted sites, MySQL plaintext passwords in /etc/my.cnf, e-mail passwords in the Dovecot database, and — if you’ve stored something without encryption at application level — all your customer data. That’s why a WHM compromise is usually treated as a full breach, not just a partial incident.

Should I report to ANSPDCP/ICO if I was compromised?

GDPRArt. 33 obliges the data controller to notify the supervisory authority within 72 hours of the time it has learned of the incident, if there is a risk to the rights of the data subjects. A cPanel/WHM compromise with full access to your customer database almost always reaches this threshold. ForZebraByte(UK), the notification goes to the ICO; for entities headquartered in Romania, to ANSPDCP. Consult a legal specialist — or the GPR teamZebraByte(gpr@zebrabyte.co.uk).

How much does a security audit cost for a cPanel/WHM server?

AtZebraBytea standard cPanel/WHM audit (version evaluation, WHM configuration, SSH hardening, account audit, IOC scan, mitigation recommendations) is a single intervention starting from a fixed invoice, delivered within 48 hours along with a brand-out report. legal@zebrabyte.co.uk Or call the +44 330 533 0334.

Official Sources and References

  1. cPanel Security Bulletin – Security Update 04/28/2026: support.cpanel.net

  2. NVD — CVE-2026-41940: nvd.nist.gov

  3. watchTowr Labs — complete technical analysis with PoC: labs.watchtowr.com

  4. Rapid7 — ETR pentru CVE-2026-41940: rapid7.com

  5. BleepingComputer — cPanel emergency update: bleepingcomputer.com

  6. The Hacker News — Critical cPanel Authentication Vulnerability: thehackernews.com

  7. Centre for Cybersecurity Belgium (CCB) — Warning: ccb.belgium.be

This article is published for informational purposes. The information reflects the state of public knowledge on the date of publication (30 April 2026). For concrete evaluation of your own infrastructure, consult a security specialist.ZebraByte® and theZebraBytelogo are registered trademarks ofZEBRABYTELIMITED (UK Reg. 15194067, ICO Ref ZB748706).


Scris de Zebrabyte

ZebraByteeditorial material on digital security, infrastructure, privacy and compliance, kept in the company's technical archive.

ReceiveZebraByteanalytics and guidelines on cyber security, privacy and compliance.
ZebraByte

Framework-uri gestionate Managed frameworks

Can’t find the framework you are looking for?
Talk to us — we may be able to include it in the program.
Don’t see the framework you are looking for?
Reach out – it may already be supported in the program.

SOC 2 Type 1
ISO 27001
ISO 42001
CCPA
GDPR
ISO 27701
HIPAA
FERPA
CASA
SOC 2
Talk to an expert Talk to an expert