:

CPANEL ZERO-DAY ACTIVELY EXPLOITED, POC RELEASED

AI DESK2 MIN READ
THU, APR 30, 2026

■ AI-SUMMARIZED FROM 1 SOURCE BELOW

A critical authentication bypass vulnerability in cPanel, WHM, and WP Squared is being actively exploited in the wild since late February. A proof-of-concept is now publicly available.

The Vulnerability CVE-2026-41940 is a critical authentication bypass flaw affecting cPanel, WHM, and WP Squared. The vulnerability allows attackers to circumvent authentication mechanisms, potentially granting unauthorized access to hosting control panels and administrative functions. Active Exploitation Security researchers have confirmed active exploitation attempts dating back to late February. The release of a public proof-of-concept has significantly expanded the attack surface, enabling a broader range of threat actors to leverage the flaw. Risk Assessment The combination of a critical severity rating and public exploit code creates an urgent threat landscape. Organizations running affected versions face elevated risk of unauthorized access, data breaches, and potential lateral movement within hosting infrastructure. Affected Systems The vulnerability impacts multiple cPanel and WHM versions. WP Squared installations are also vulnerable. Administrators should immediately identify and inventory affected systems across their infrastructure. Recommended Actions Organizations should prioritize patching to the latest available versions. Interim mitigations may include restricting access to administrative interfaces, monitoring authentication logs for suspicious activity, and implementing network-level controls on management ports. Timeline While initial exploitation attempts occurred in late February, the public release of proof-of-concept code has accelerated the threat timeline. The window for remediation has narrowed considerably. cPanel and WHM administrators should treat this as a critical priority and coordinate patching across their infrastructure immediately. The availability of public exploit code means this vulnerability will likely see widespread exploitation efforts in the coming days.

■ SOURCES

Bleeping Computer

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

OpenAI is launching GPT-5.5-Cyber, a specialized cybersecurity model restricted to vetted "cyber defenders" rather than the general public. The limited rollout begins within days.

1H AGOAI Desk

International authorities dismantled nine cryptocurrency investment fraud operations and arrested 276 suspects in a coordinated crackdown. The operation involved U.S. and Chinese law enforcement agencies targeting organized crypto scams.

1H AGOIndustry Desk

Two Republican-led House committees are investigating Airbnb and Cursor maker Anysphere for their use of Chinese artificial intelligence models. The probes reflect broader congressional efforts to limit national security risks and counter China's AI advancement.

5H AGOAI Desk

CVE-2026-31431 is a newly disclosed security flaw affecting copy operations across multiple platforms. The vulnerability allows attackers to manipulate data during transfer, potentially compromising system integrity.

8H AGOAI Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.