Hosting providers worldwide are responding to an authentication bypass vulnerability in the ubiquitous cPanel software, which is used for server and site management, and some providers have reported active exploitation of the flaw going back several weeks. 

On Tuesday afternoon, cPanel published a terse advisory saying that there was an issue with “session loading and saving” and that it affects every version of the software. There were few other details, but by Wednesday hosting providers and security researchers had sussed out more information about the bug–which is now identified as CVE-2026-41940–and figured out that it was an authentication issue. 

“An authentication bypass security issue has been identified in the cPanel software (including DNSOnly) affecting all versions after 11.40,” the cPanel advisory says.

cPanel and WHM are used to manage tens of millions of domains across the internet, so the exposure for this vulnerability is as broad as it gets.

cPanel has updated its advisory and has pushed out an emergency patch for all of the affected versions. The fixed versions include:

  • 11.110.0.97
  • 11.118.0.63
  • 11.126.0.54
  • 11.130.0.18
  • 11.132.0.29
  • 11.136.0.5
  • 11.134.0.20

The company has also released a script to detect known indicators of compromise. 

Security researchers at watchTowr Labs have done a detailed analysis of the vulnerability and VulnCheck has details, as well. 

“Well, dear reader - for those that have never had the joyous experience of managing shared hosting infrastructure, cPanel and WHM is the control panel solution that runs, depending on who you ask, somewhere north of 70 million domains,” the watchTowr Labs analysis says.

“WHM is the administrative interface - root-level access to the server, SSL certificates, security protocols, the lot - and cPanel is the user-facing panel for individual hosting accounts.

Think of it as the keys to the kingdom, and then the keys to every individual apartment inside the kingdom. If the kingdom was the Internet and the apartments were websites. For everything.”

The potential scope of this bug is quite large, and as researchers at Censys point out in their analysis, a large chunk of the cPanel/WHM instances are located in a small number of hosting providers. So patching is on their shoulders.

"The exposed cPanel/WHM control plane is heavily clustered in a handful of large shared hosting operators: GoDaddy, Bluehost, Oracle Cloud, OVH, Network Solutions, A2 Hosting, Namecheap, Liquid Web, and InMotion together account for nearly half of the cPanel/WHM hosts we see. That concentration means the speed of Internet-wide remediation is largely gated by how quickly a small number of operators patch their fleets," Censys said.

cPanel said it is working on a method to get a fix out to versions of the software that have not been updated yet.