Critical cPanel Authentication Bypass CVE-2026-41940 Exploited as Zero-Day for Two Months Before April 28 Patch
A CVSS 9.8 CRLF-injection bug in cPanel and WHM let unauthenticated attackers gain root, exploited since February 23 against roughly 1.5 million exposed servers and now weaponized against governments in Southeast Asia.