cPanel Releases Emergency Patch After Authentication Bypass Ransomware Attack
Patch cPanel to the latest emergency security release to mitigate the authentication bypass vulnerability.
Patch cPanel to the latest version immediately.
Summary
On May 8, 2026, cPanel released a second emergency security patch following the CVE‑2026‑41940 authentication bypass that was used to compromise 44,000 web hosting servers and deploy ransomware. The patch addresses three new vulnerabilities that could allow attackers to execute arbitrary code, elevate privileges, or bypass authentication controls. cPanel’s security team emphasized that the vulnerabilities were actively exploited and that the patch must be applied immediately to prevent further compromise. The update includes fixes for directory traversal, remote code execution via malformed requests, and a privilege escalation flaw in the WHM interface. Users are urged to update to the latest cPanel version and verify that the new security headers are correctly configured. The patch also adds additional logging for failed authentication attempts to aid in forensic analysis. cPanel recommends running a full audit of server configurations after applying the update.
Key changes
- Fixes CVE‑2026‑41940 authentication bypass used in ransomware attacks
- Removes directory traversal vulnerability in the cPanel API
- Prevents remote code execution via malformed WHM requests
- Blocks privilege escalation through the WHM interface
- Adds enhanced logging for failed authentication attempts
- Requires cPanel version 1.8.3 or later to apply the patch