Security: CVE-2026-41940 - cPanel & WHM / WP2 Security Update

Friday, May 1, 2026

Critical Security Update: CVE-2026-41940

Essential Steps to Secure Your Servers and Accounts | Updated 8 hours ago

Dear Valued Clients,

We are writing to inform you about a critical security vulnerability recently identified in the cPanel & WHM platform, documented under the identifier CVE-2026-41940. Immediate action is necessary to protect your systems and data.

Urgent: A significant authentication bypass vulnerability has been discovered, impacting multiple versions of cPanel. Systems not updated are at risk of exploitation.

Impacted Versions

The identified vulnerability affects all versions post-release 11.40. Immediate updates are crucial for the following cPanel & WHM versions:

  • 11.86.0.41
  • 11.110.0.97
  • 11.118.0.63
  • 11.126.0.54
  • 11.130.0.19
  • 11.132.0.29
  • 11.134.0.20
  • 11.136.0.5

WP Squared Version

The security patch extends to WP Squared, with version 136.1.7 receiving updates.

Steps for Server Administrators

Follow these steps immediately to secure your server:

  1. Execute the update script: /scripts/upcp --force
  2. Verify the updated build version: /usr/local/cpanel/cpanel -V
  3. Restart the cPanel service to apply changes: /scripts/restartsrv_cpsrvd --hard
  4. For CentOS 6 / CloudLinux 6 (using version 110.0.50), update directly: whmapi1 set_tier tier=11.110.0.103
  5. Ensure cPanel update preferences are correctly configured. Manual updates are necessary for specific custom configurations.

Additional Recommendations

To enhance security, consider the following:

  • Block inbound traffic on ports 2083, 2087, 2095, and 2096.
  • If unable to update, stop services temporarily: whmapi1 configureservice...

Actions for Hosting Account Clients

Our systems are reset to the most stable backup available. We urge you to change your account passwords immediately to strengthen security.

Detection & Mitigation

Utilize the provided script to scan for potential security breaches:

#!/bin/bash\n# Scan for compromised session files\nSESSIONS_DIR=\"/var/cpanel/sessions\"...\n

Run the script to identify any indicators of compromise and take appropriate action.

Full Article & Additional Resources

Detailed information and command references are available in the full cPanel Security Notice.

Need Assistance?

If you require further assistance or have questions, please don't hesitate to reach out to our technical support team. Your security remains our priority.