cPanel/WHM authentication bypass — mass exploitation ongoing (KEV deadline 2026-05-21)
cve · CVE-2026-41940
Coverage timeline
1
first 2026-05-06 → last 2026-05-06
Briefs
1
1 distinct
Sources cited
7
7 hosts
Sections touched
1
active_vulns
Co-occurring entities
0
no co-occurrence
Story timeline
- 2026-05-06CTI Daily Brief — 2026-05-06
Where this entity is cited
- active_vulns1
Source distribution
- cyberscoop.com1 (14%)
- helpnetsecurity.com1 (14%)
- labs.watchtowr.com1 (14%)
- panelica.com1 (14%)
- rapid7.com1 (14%)
- security-hub.ncsc.admin.ch1 (14%)
- thehackernews.com1 (14%)
External references
All cited sources (7)
- labs.watchtowr.comprimaryinlinewatchTowr Labshttps://labs.watchtowr.com/the-internet-is-falling-down-falling-down-falling-down-cpanel-whm-authentication-bypass-cve-2026-41940/
- cyberscoop.cominlineCyberScoop, 2026-05-05https://cyberscoop.com/cpanel-authentication-bypass-vulnerability-cve-2026-41940-exploited/
- helpnetsecurity.cominlineHelp Net Security, 2026-05-04https://www.helpnetsecurity.com/2026/05/04/multiple-threat-actors-actively-exploit-cpanel-vulnerability-cve-2026-41940/
- panelica.cominlinePanelica technical analysis, 2026-05-08https://panelica.com/blog/cpanel-cve-2026-29201-29202-29203-may-2026-tsr-advisory
- rapid7.cominlineRapid7 ETRhttps://www.rapid7.com/blog/post/etr-cve-2026-41940-cpanel-whm-authentication-bypass/
- security-hub.ncsc.admin.chinlineNCSC-CH Security Hub post 12550, 2026-05-08https://security-hub.ncsc.admin.ch/api/posts/12550/details
- thehackernews.cominlineThe Hacker News, 2026-05-09https://thehackernews.com/2026/05/cpanel-whm-patch-3-new-vulnerabilities.html
Items in briefs about cPanel/WHM authentication bypass — mass exploitation ongoing (KEV deadline 2026-05-21)
No parsed item heading or body matches this entity yet. Items match by exact CVE id (for CVE entities), by lead-segment substring of the title in the item heading or body, or by a distinctive anchor token from the title appearing in the item heading. Coverage that lives inside a broader section (no per-item heading) is captured by the Story timeline above.