Post by @jorijn

An authentication bypass security issue has been identified in the cPanel software (including DNSOnly) affecting all versions after 11.40.

This one is ugly, folks. Go update your servers now, and run the detection script.

https://support.cpanel.net/hc/en-us/articles/40073787579671-Security-CVE-2026-41940-cPanel-WHM-WP2-Security-Update-04-28-2026

#webhosting #Cpanel #whm

Replying to @jorijn

The sad thing here is, I had to find out on Reddit. I would've expected #Cpanel to email me or use more urgent means of reaching out.