Saturday, September 12, 2026

Attackers Exploit cPanel Authentication Bypass 0-Day After PoC Release

A critical zero-day vulnerability, tracked as CVE-2026-41940, is currently being actively exploited across the web hosting industry.

This CVSS 9.8 flaw allows unauthenticated remote attackers to bypass cPanel and WHM login mechanisms, granting them full administrative control over servers.

The vulnerability stems from a Carriage Return Line Feed (CRLF) injection flaw within the application’s session loading and saving process.

Attackers exploit this by injecting a malicious security token into a pre-authenticated session, completely bypassing standard password validation checks. Because this exploit requires no user interaction, threat actors can easily automate attacks against internet-facing management panels.

PoC and Active Exploitation

Security firm watchTowr Labs recently accelerated attacks by publishing a Proof-of-Concept (PoC) exploit script that easily achieves Remote Code Execution.

The PoC mints a pre-authentication session and manipulates the do_token_denied function to extract root access tokens. Due to widespread automated exploitation, many global hosting providers have been forced to block control panel ports to protect customer data.

When attackers successfully exploit this vulnerability, they can manipulate server configurations, databases, and hosted email accounts. This level of access allows them to deploy ransomware, exfiltrate sensitive customer data, or use the compromised infrastructure for downstream attacks.

The severity of the flaw means that even servers running outdated or unsupported cPanel versions remain highly vulnerable to complete system takeover.

Patched Versions

The vulnerability impacts all currently supported builds of cPanel, WHM, and WP Squared. Administrators must prioritize updating their infrastructure to the following secure releases:

Software BranchVulnerable StatusPatched Release
cPanel & WHM 110Vulnerable11.110.0.97
cPanel & WHM 118Vulnerable11.118.0.63
cPanel & WHM 126Vulnerable11.126.0.54
cPanel & WHM 132Vulnerable11.132.0.29
cPanel & WHM 134Vulnerable11.134.0.20
WP Squared 136Vulnerable136.1.7

Threat hunters should investigate their session logs for signs of multi-line password values or unexpected token_denied entries.

Furthermore, any pre-authentication session containing a successful_external_auth_with_timestamp attribute is a critical indicator of unauthorized session elevation.

Organizations that discover these artifacts must immediately purge all active sessions, force root password resets, and audit their systems for potential persistence mechanisms, such as backdoors.

Administrators should immediately run the cPanel update script and restart the cpsrvd service to apply the permanent fix. If patching is delayed, organizations must configure firewalls to block inbound traffic on TCP ports 2083, 2087, 2095, and 2096 to prevent unauthorized access.

Security teams can also utilize cPanel’s official detection script to scan the /var/cpanel/sessions directory for compromise indicators, such as attacker-injected cp_security_token values.

Follow us on Google NewsLinkedIn, and X to Get Instant Updates and Set GBH as a Preferred Source in Google.

Divya
Divya
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

Threat Actors Use Claude AI Agents to Automate Cyberattacks and Steal Sensitive Data

Threat actors are increasingly using Claude-based AI workflows to...

China-Linked Hackers Chain Chrome Zero-Day With Windows Kernel Flaw in Attacks

China-linked threat actors UTA0560 and JungleBamboo chained a Google...

New Phishing Campaign Abuses Windows Mshta.exe to Steal Credentials and Secrets

A newly identified phishing campaign is abusing the legitimate...

CISA Warns of Critical GitLab Vulnerability Exploited in Attacks

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has...

Researchers Uncover 10,000+ Malware Loaders Behind YouTube and SEO Poisoning Campaign

A long-running pay-per-install (PPI) operation that used YouTube gaming...

VLC Media Player Flaws Let Attackers Corrupt Memory and Leak Sensitive Data

Two security vulnerabilities in VLC media player versions 3.0.0...

CISA Adds Exploited MikroTik RouterOS Flaws to Security Alert

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has...

Related Articles

Recent News