Return to Global Matrix
CLASSIFIED: EYES ONLY

Critical cPanel and WHM bug exploited as a zero-day, PoC now available

TELEMETRY SUMMARY DECRYPTION

SITREP: A critical authentication bypass vulnerability (CVE-2026-41940) in cPanel, WHM, and WP Squared is currently being exploited as a zero-day. Proof of Concept (PoC) for the vulnerability is now publicly available, indicating an escalation in threat activity since late February. TACTICAL ASSESSMENT: The exploitation of this vulnerability poses significant risks to web hosting environments, potentially allowing unauthorized access to sensitive data. This incident highlights the ongoing challenges in cybersecurity, particularly in the realm of widely used software platforms. PROJECTED VECTORS: Future attacks may increase as more malicious actors gain access to the PoC and develop tailored exploits.

SAT-COM 4LAT: 45.192LON: 34.021UTC: 2026-04-30

Event Telemetry

STATUS IDENTIFIERNORMAL TRAFFIC
ORIGIN DESKCYBER
ACQUISITION TIME04/3011:57 ZULU
AUTHORSYSTEM.AUTO[992]