Skip to main content
Get a quote
Menu
← All news and updates

cPanel/WHM critical vulnerability (CVE-2026-41940)

  • A critical authentication bypass vulnerability, CVE-2026-41940, affects cPanel and WebHost Manager (WHM).
  • This flaw has a CVSS base score of 9.8 and is currently under active exploitation.
  • The Cybersecurity and Infrastructure Security Agency (CISA) added this CVE to its Known Exploited Vulnerabilities (KEV) catalog, showing its immediate threat level.
  • Organizations using cPanel and WHM instances are at risk; hosting providers reported successful attacks before a public patch was available. Administrators and security teams need to address this urgently.
  • You will be pleased to know Helpwise hosting accounts are fully protected from this exploit.

More info from cyber.gov.au

Originally published 6 May 2026.

← Back to all news

Let's talk

Got a website project in mind?

Tell us what you need. We'll come back with honest advice, a clear quote and a realistic timeline – no jargon, no hard sell.