CISA has added a critical authentication bypass flaw in WebPros cPanel, tracked as CVE-2026-41940, to its Known Exploited Vulnerabilities catalog. This vulnerability allows attackers to gain unauthorized access to servers and manage hosting settings or sensitive data, posing significant risks to web hosts using the affected versions of cPanel and WHM.
Federal agencies must address this vulnerability by May 3, 2026, to protect against ongoing exploitation reported by Shadowserver Foundation.
Read the full article at Security Affairs
Want to create content about this topic? Use Nemati AI tools to generate articles, social posts, and more.

![[AINews] The Unreasonable Effectiveness of Closing the Loop](/_next/image?url=https%3A%2F%2Fmedia.nemati.ai%2Fmedia%2Fblog%2Fimages%2Farticles%2F600e22851bc7453b.webp&w=3840&q=75)



