TGViewer
🥳靠谱VPS推荐(默认带aff) - VPS仓/古博 🥳靠谱VPS推荐(默认带aff) - VPS仓/古博 @vpscang · 11.8K subscribers
Post #7865 6.94K
We are writing to inform you of a critical security vulnerability, CVE-2026-41940, affecting cPanel & WHM — the web hosting control panel software used to manage websites and servers. This vulnerability has a CVSS score of 9.8 (Critical) and is being actively exploited in the wild. We strongly urge you to take action immediately.


━━ WHAT IS THE VULNERABILITY? ━━

CVE-2026-41940 is an authentication bypass vulnerability caused by a CRLF (Carriage Return Line Feed) injection flaw in the cPanel login and session-handling process. It allows unauthenticated remote attackers to bypass the login process entirely and gain full administrative access to the cPanel or WHM control panel — without any username or password.

Successful exploitation could give an attacker complete control over:
• Your cPanel host system and its configuration
• All databases hosted on the server
• All websites and accounts managed under the panel

The vulnerability affects all cPanel & WHM versions after v11.40, as well as v136.1.7 of WP Squared (a managed WordPress hosting platform built on cPanel).


━━ IS THIS BEING ACTIVELY EXPLOITED? ━━

Yes. Active exploitation has been observed in the wild since at least 23 February 2026 — several weeks before the public disclosure. A proof-of-concept exploit was published by security firm watchTowr on 29 April 2026, which means exploitation attempts are now expected to increase significantly. Security researchers have observed nearly 4,000 attack attempts targeting exposed cPanel instances, spanning multiple industries and countries.


━━ WHAT SHOULD YOU DO? ━━

1. Update immediately
Apply the security patch released by cPanel/WebPros on 28 April 2026. Verify your cPanel build version after updating and restart the cPanel service (cpsrvd).

2. Block access at the firewall (if you cannot patch immediately)
Block inbound traffic on the following ports:
*2083 (cPanel HTTPS)
*2087 (WHM HTTPS)
*2095 (Webmail HTTP)
*2096 (Webmail HTTPS)

3. Check for signs of compromise
cPanel has released a detection script to help identify known indicators of compromise. We recommend running this against any affected systems. Additionally:
* Review WHM access logs for any unauthorised activity
*Inspect session files for anomalies
*Purge existing sessions and force password resets for root and WHM users
*Check for any persistence mechanisms (new admin accounts, changed configurations, etc.)

4. Contact your hosting provider
If your cPanel environment is managed by a hosting provider, contact them to confirm that the patch has been applied to your server.


━━ FURTHER RESOURCES ━━

• cPanel Security Advisory: https://support.cpanel.net
• Rapid7 Technical Analysis: https://www.rapid7.com/blog/post/etr-cve-2026-41940-cpanel-whm-authentication-bypass/
• NVD Entry: https://nvd.nist.gov/vuln/detail/CVE-2026-41940

If you have any questions or need assistance applying this patch, please do not hesitate to contact our support team.

We take the security of your infrastructure seriously and will continue to monitor this situation and provide updates as new information becomes available.


https://t.me/zaihuapd/41138
这个和上次的 CVE-2026-31431 名为"Copy Fail" 的还不同,这次是CVE-2026-41940,主要是cpanel和whm,很多商家都用这两个
More from @vpscang
  1. Sep 29, 2026DMIT HKG.AS3.EB.WEE 1 vCPU 1.0 GB RAM 20G SSD Storage 550GB Transfer 500Mbps VirtIO Interf…
  2. Sep 24, 2026CloudIPLC - 沪日 IPLC-NAT 秒杀,中秋限时返场!🔥 - 老牌靠谱IPLC商家了 - 贵,稳,强制实名 - 可以叠加他家经常有的满赠优惠,典型的是充999赠20…
  3. Sep 24, 2026DMIT 本次补货 LAX(PRO,T1)正价套餐。 正价价格较高,非刚需建议继续等待特价。 如果追求顶级优化线路且预算充足,也建议优先选择低配套餐,性价比相对更高。 #优化线路…
  4. Sep 3, 2026加利福尼亚州骨干光缆出现故障,多个本土运营商均受到影响,出现丢包、拥塞的情况 目前暂无修复 ETR https://t.me/SaltyFishIO/655
  5. Aug 13, 2026DMIT LAX AS3系列 近期最后一次补货 购买入口: LAX.AS3.Pro (1TB 10.9U/mo 起) LAX.AS3.EB (1.5TB 10.9U/mo 起) L…
  6. Aug 5, 2026https://billing.tcscloud.net/index.php?rp=/store/taiwan-vps-dynamic/dh2-hinet-1000m-dyn Hi…
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →