Critical cPanel and WHM bug exploited as a zero-day, PoC now available
Source: BleepingComputer · Category: Security News — Technology
Critical CVE-2026-41940 authentication bypass in cPanel, WHM, and WP Squared actively exploited in the wild since late February. If firm uses cPanel/WHM for internal or client websites, patch immediately. Zero-day exploitation ongoing; do not delay.