<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[CVE-2026-41960: cPanel auth bypass EITW]]></title><description><![CDATA[<p>This is gonna burn some folks.</p><p></p><div class="card col-md-9 col-lg-6 position-relative link-preview p-0">



<a href="https://www.bleepingcomputer.com/news/security/cpanel-whm-emergency-update-fixes-critical-auth-bypass-bug/" title="cPanel, WHM emergency update fixes critical auth bypass bug">
<img src="https://www.bleepstatic.com/content/hl-images/2026/04/29/cpanel.jpg" class="card-img-top not-responsive" style="max-height:15rem" alt="Link Preview Image" />
</a>



<div class="card-body">
<h5 class="card-title">
<a href="https://www.bleepingcomputer.com/news/security/cpanel-whm-emergency-update-fixes-critical-auth-bypass-bug/">
cPanel, WHM emergency update fixes critical auth bypass bug
</a>
</h5>
<p class="card-text line-clamp-3">A critical vulnerability affecting all but the latest versions of cPanel and the WebHost Manager (WHM) dashboard could be exploited to obtain access to the control panel without authentication.</p>
</div>
<a href="https://www.bleepingcomputer.com/news/security/cpanel-whm-emergency-update-fixes-critical-auth-bypass-bug/" class="card-footer text-body-secondary small d-flex gap-2 align-items-center lh-2">



<img src="https://www.bleepstatic.com/favicon/bleeping.ico" alt="favicon" class="not-responsive overflow-hiddden" style="max-width:21px;max-height:21px" />





<p class="d-inline-block text-truncate mb-0">BleepingComputer <span class="text-secondary">(www.bleepingcomputer.com)</span></p>
</a>
</div><p></p><p></p><div class="card col-md-9 col-lg-6 position-relative link-preview p-0">



<a href="https://www.namecheap.com/status-updates/ongoing-critical-security-vulnerability-in-cpanel-april-28-2026/" title="[RESOLVED] CRITICAL SECURITY VULNERABILITY WITH CPANEL/WHM, APRIL 28, 2026 - Namecheap Status">
<img src="https://www.namecheap.com/status-updates/wp-content/themes/theme_1_2/build/images/logo.png" class="card-img-top not-responsive" style="max-height:15rem" alt="Link Preview Image" />
</a>



<div class="card-body">
<h5 class="card-title">
<a href="https://www.namecheap.com/status-updates/ongoing-critical-security-vulnerability-in-cpanel-april-28-2026/">
[RESOLVED] CRITICAL SECURITY VULNERABILITY WITH CPANEL/WHM, APRIL 28, 2026 - Namecheap Status
</a>
</h5>
<p class="card-text line-clamp-3">Namecheap Status - Get the latest updates regarding current problems and scheduled or emergency maintenance releases for our products - Namecheap.com</p>
</div>
<a href="https://www.namecheap.com/status-updates/ongoing-critical-security-vulnerability-in-cpanel-april-28-2026/" class="card-footer text-body-secondary small d-flex gap-2 align-items-center lh-2">



<img src="https://www.namecheap.com/favicon.ico" alt="favicon" class="not-responsive overflow-hiddden" style="max-width:21px;max-height:21px" />



<p class="d-inline-block text-truncate mb-0">Namecheap Status <span class="text-secondary">(www.namecheap.com)</span></p>
</a>
</div><p></p><p></p><div class="card col-md-9 col-lg-6 position-relative link-preview p-0">

<div class="card-body">
<h5 class="card-title">
<a href="https://support.cpanel.net/hc/en-us/articles/40073787579671-cPanel-WHM-Security-Update-04-28-2026">
Just a moment...
</a>
</h5>
<p class="card-text line-clamp-3"></p>
</div>
<a href="https://support.cpanel.net/hc/en-us/articles/40073787579671-cPanel-WHM-Security-Update-04-28-2026" class="card-footer text-body-secondary small d-flex gap-2 align-items-center lh-2">



<img src="https://support.cpanel.net/favicon.ico" alt="favicon" class="not-responsive overflow-hiddden" style="max-width:21px;max-height:21px" />



<p class="d-inline-block text-truncate mb-0"> <span class="text-secondary">(support.cpanel.net)</span></p>
</a>
</div><p></p><p></p><div class="card col-md-9 col-lg-6 position-relative link-preview p-0">



<a href="https://labs.watchtowr.com/the-internet-is-falling-down-falling-down-falling-down-cpanel-whm-authentication-bypass-cve-2026-41940/" title="The Internet Is Falling Down, Falling Down, Falling Down (cPanel &amp; WHM Authentication Bypass CVE-2026-41940)">
<img src="https://storage.ghost.io/c/a0/dc/a0dcbbe4-0ae7-4d7e-90f7-ebbc3a0f5a84/content/images/size/w1200/2026/04/Group-8730--2-.png" class="card-img-top not-responsive" style="max-height:15rem" alt="Link Preview Image" />
</a>



<div class="card-body">
<h5 class="card-title">
<a href="https://labs.watchtowr.com/the-internet-is-falling-down-falling-down-falling-down-cpanel-whm-authentication-bypass-cve-2026-41940/">
The Internet Is Falling Down, Falling Down, Falling Down (cPanel &amp; WHM Authentication Bypass CVE-2026-41940)
</a>
</h5>
<p class="card-text line-clamp-3">Hello! Yes, it's all a disaster again!

Let's get this party started:
























0:00

/0:12


1×

















No comments today, so imagine this:

 * We wrote something that we find very funny,
 * Nobody else gets it,
 * But everyone humors us

Just like a typical watchTowr Labs blog introduction.

As with all</p>
</div>
<a href="https://labs.watchtowr.com/the-internet-is-falling-down-falling-down-falling-down-cpanel-whm-authentication-bypass-cve-2026-41940/" class="card-footer text-body-secondary small d-flex gap-2 align-items-center lh-2">



<img src="https://storage.ghost.io/c/a0/dc/a0dcbbe4-0ae7-4d7e-90f7-ebbc3a0f5a84/content/images/size/w256h256/2022/05/Logo.png" alt="favicon" class="not-responsive overflow-hiddden" style="max-width:21px;max-height:21px" />



<p class="d-inline-block text-truncate mb-0">watchTowr Labs <span class="text-secondary">(labs.watchtowr.com)</span></p>
</a>
</div><p></p><br /><br /><a href="https://discourse.ifin.network/t/cve-2026-41960-cpanel-auth-bypass-eitw/339/1">Discuss this on our forum.</a>

<div class="row mt-3"><div class="col-12 mt-3"><img class="img-thumbnail" src="https://discourse.ifin.network/uploads/default/original/1X/432f8dbcfc711ce874528c4e0d866b4f7eed2e2e.png" alt="Link Preview Image" /><img class="img-thumbnail" src="https://discourse.ifin.network/uploads/default/original/1X/148e5141595577395d1517fe16cd2f6f40f0e76e.jpeg" alt="Link Preview Image" /><img class="img-thumbnail" src="https://discourse.ifin.network/uploads/default/original/1X/7f937c7d377dbe814f59e8216828de5bc9558309.png" alt="Link Preview Image" /><img class="img-thumbnail" src="https://discourse.ifin.network/uploads/default/original/1X/6d68704fcaf01b6162419ea172346d5a42604d39.png" alt="Link Preview Image" /></div></div>]]></description><link>https://board.circlewithadot.net/topic/696b206f-4393-408c-b45e-f4546eea4656/cve-2026-41960-cpanel-auth-bypass-eitw</link><generator>RSS for Node</generator><lastBuildDate>Fri, 01 May 2026 18:54:00 GMT</lastBuildDate><atom:link href="https://board.circlewithadot.net/topic/696b206f-4393-408c-b45e-f4546eea4656.rss" rel="self" type="application/rss+xml"/><pubDate>Wed, 29 Apr 2026 18:38:31 GMT</pubDate><ttl>60</ttl></channel></rss>