Fixed Intel

CISA Known Exploited Vulnerability

This vulnerability is actively exploited in the wild and listed in the CISA Known Exploited Vulnerabilities catalog.

Remediation Deadline: May 3, 2026

CVE-2026-41940

High
CISA KEV
WebPros/cPanel & WHM and WP2 (WordPress Squared)

Description

WebPros cPanel & WHM (WebHost Manager) and WP2 (WordPress Squared) contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.

Required Action

https://support.cpanel.net/hc/en-us/articles/40073787579671-cPanel-WHM-Security-Update-04-28-2026 ; https://docs.cpanel.net/release-notes/release-notes/ ; https://docs.wpsquared.com/changelogs/versions/changelog/#13617 ; https://nvd.nist.gov/vuln/detail/CVE-2026-41940"

Risk Assessment

ELEVATED
In CISA KEV

Details

Severity
High
CISA KEV
Yes
Ransomware
Unknown
Articles
0

Timeline

Published

Apr 30, 2026

Added to KEV

Apr 30, 2026

Remediation Due

May 3, 2026

Affected Product

WebPros

cPanel & WHM and WP2 (WordPress Squared)

View all WebPros CVEs