Critical cPanel Zero-Day vulnerability confirmed — Update servers now

One of the most used web hosting control panels, cPanel, has confirmed a critical zero-day vulnerability that can enable an unauthenticated, remote attacker to gain admin access. A vulnerability that’s CVSS rated at 9.8. The advice is simple: update your servers now, at once, immediately.

The emergency update, issued by cPanel on 28 April, addresses a vulnerability that was officially assigned the following day as CVE-2026-41940. An analysis by Rapid7 stated: “Successful exploitation of CVE-2026-41940 grants an attacker control over the cPanel host system, its configurations and databases, and websites it manages.”

Daniel Pearson, the CEO of hosting provider KnownHost, has confirmed that this is a zero-day that has already been used in attacks. “I can say we’ve personally seen execution attempts as early as 2/23/2026,” he said.

A technical analysis has already been published, with Watchtower Labs stating that the zero-day affects both cPanel and WebHost Manager (WHM). The latter being the admin interface that has root-level access to the server, SSL certificates and so on.

“Think of it as the keys to the kingdom, and then the keys to every individual apartment inside the kingdom,” the analysis said. Oh, and CVE-2026-41940 affects “all currently supported versions of cPanel & WHM,” the report confirmed; “Not some, or a few, or a specific release track.”

Likelihood of attacks

The fact this detailed confirmation and technical expose of the exploit path has now been published means that the exploitation is likely to explode in short order. And bear in mind attacks have been seen since February.

Rapid7 analysis, which included a very simple Shodan query for potential targets, found 1.5 million cPanel instances exposed to the internet that could be vulnerable. That’s a lot of opportunity right there.

At the risk of repeating myself, update as a matter of some urgency.

“The fallout of this might end up being worse than last year’s biggest vulnerability, which was arguably React2Shell,” Dan Andrew, Head of Security at Intruder, told me. The good news, as Andrew said, is that “most cPanels auto update themselves pretty regularly, which will greatly shorten the window of exploitation available to attackers”.

My advice would be not to wait and to slam that window firmly shut right now.

cPanel Zero-Day security advisory

Please refer to the cPanel security advisory for full details, but note that this confirms that updates are only currently available for the following cPanel & WHM versions:

  • 11.86.0.41
  • 11.110.0.97
  • 11.118.0.63
  • 11.126.0.54
  • 11.130.0.19
  • 11.132.0.29
  • 11.136.0.5
  • 11.134.0.20
  • And WP Squared version 136.1.7

“We are currently working on finding paths to get a patch to versions not included above, especially for versions that have higher quantities of servers,” the advisory states.

In the meantime, however, cPanel has released a detection script and “highly recommended” that users without an update patch  “work toward updating your server as soon as possible, as it may also be affected”.

In other cybersecurity news

The Cyber Security Breaches Survey, which provides a comprehensive overview of the cyber security landscape for UK businesses and charities, and was commissioned by the Department for Science, Innovation and Technology (DSIT) and the Home Office, was released this week. We spoke to experts in the field to get their view, including Jay Kaplan, CEO and Co-founder of Synack. Here’s what he had to say:

“This year’s Cyber Security Breaches Survey shows boards taking on more responsibility for cyber on paper while paying it less attention in practice. Board-level responsibility rose from 27% to 31%, which looks like progress on paper. But the share of medium-sized business boards receiving at least annual cyber updates dropped from 78% to 70%. This signals more accountability with less visibility.

The fix requires speaking the board’s language. Vulnerability management needs to be a corporate goal, not just a security team metric. Frame a breach in terms the board understands: what does it cost the business for every hour critical systems are offline? That calculation changes how leadership prioritises investment far more than any compliance report will. And once a year isn’t enough on a threat landscape that moves in hours. Boards need a continuous read on what’s actually exploitable, what it would cost the business to lose, and what’s been validated against real attack conditions.”

About The Author

Avatar photo
Davey Winder

With four decades of experience, Davey is one of the UK's most respected cybersecurity writers and a contributing editor to PC Pro magazine. He is also a senior contributor at Forbes. You can find him at TechFinitive covering all things cybersecurity.

Read more from this author.

We take journalism seriously. To learn more on why you should trust us, head to our editorial guidelines page or meet our team.