<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Major authentication bypass disclosed in cPanel]]></title><description><![CDATA[<p>Major authentication bypass disclosed in cPanel</p><p><div class="card col-md-9 col-lg-6 position-relative link-preview p-0">

<div class="card-body">
<h5 class="card-title">
<a href="https://support.cpanel.net/hc/en-us/articles/40073787579671-Security-CVE-2026-41940-cPanel-WHM-WP2-Security-Update-04-28-2026">
Just a moment...
</a>
</h5>
<p class="card-text line-clamp-3"></p>
</div>
<a href="https://support.cpanel.net/hc/en-us/articles/40073787579671-Security-CVE-2026-41940-cPanel-WHM-WP2-Security-Update-04-28-2026" class="card-footer text-body-secondary small d-flex gap-2 align-items-center lh-2">



<img src="https://support.cpanel.net/favicon.ico" alt="favicon" class="not-responsive overflow-hiddden" style="max-width: 21px; max-height: 21px;" />



<p class="d-inline-block text-truncate mb-0"> <span class="text-secondary">(support.cpanel.net)</span></p>
</a>
</div></p>]]></description><link>https://board.circlewithadot.net/topic/772fd196-4c26-4976-b85f-77a58b21c614/major-authentication-bypass-disclosed-in-cpanel</link><generator>RSS for Node</generator><lastBuildDate>Fri, 15 May 2026 05:06:10 GMT</lastBuildDate><atom:link href="https://board.circlewithadot.net/topic/772fd196-4c26-4976-b85f-77a58b21c614.rss" rel="self" type="application/rss+xml"/><pubDate>Thu, 30 Apr 2026 00:20:04 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Major authentication bypass disclosed in cPanel on Thu, 30 Apr 2026 22:55:23 GMT]]></title><description><![CDATA[<p><span><a href="/user/campuscodi%40mastodon.social">@<span>campuscodi</span></a></span> The only way to ever get cPanel to work the way you wanted was to was bypass its controls. Without that it's nothing.</p>]]></description><link>https://board.circlewithadot.net/post/https://mastodon.me.uk/users/geoffl/statuses/116496120091294675</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://mastodon.me.uk/users/geoffl/statuses/116496120091294675</guid><dc:creator><![CDATA[geoffl@mastodon.me.uk]]></dc:creator><pubDate>Thu, 30 Apr 2026 22:55:23 GMT</pubDate></item><item><title><![CDATA[Reply to Major authentication bypass disclosed in cPanel on Thu, 30 Apr 2026 19:10:16 GMT]]></title><description><![CDATA[<p><span><a href="/user/campuscodi%40mastodon.social">@<span>campuscodi</span></a></span> Saw a ~6 Tbps attack this morning with about 5k hosting sources, which had one thing in common: cPanel</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/jmeyer/statuses/116495234947616160</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/jmeyer/statuses/116495234947616160</guid><dc:creator><![CDATA[jmeyer@infosec.exchange]]></dc:creator><pubDate>Thu, 30 Apr 2026 19:10:16 GMT</pubDate></item><item><title><![CDATA[Reply to Major authentication bypass disclosed in cPanel on Thu, 30 Apr 2026 09:22:07 GMT]]></title><description><![CDATA[<p><span><a href="/user/briankrebs%40infosec.exchange">@<span>briankrebs</span></a></span> good thing I borked the wife's website before it could get hacked then <img class="not-responsive emoji" src="https://files.mastodon.social/custom_emojis/images/000/010/444/original/ad0f730111fcec86.png" title=":thinkerguns:" /> <img class="not-responsive emoji" src="https://files.mastodon.social/custom_emojis/images/000/275/356/original/bc4b4fc774be017c.png" title=":KEKW:" /></p>]]></description><link>https://board.circlewithadot.net/post/https://mastodon.social/users/campuscodi/statuses/116492922216064170</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://mastodon.social/users/campuscodi/statuses/116492922216064170</guid><dc:creator><![CDATA[campuscodi@mastodon.social]]></dc:creator><pubDate>Thu, 30 Apr 2026 09:22:07 GMT</pubDate></item><item><title><![CDATA[Reply to Major authentication bypass disclosed in cPanel on Thu, 30 Apr 2026 02:14:42 GMT]]></title><description><![CDATA[<p><span><a href="/user/campuscodi%40mastodon.social">@<span>campuscodi</span></a></span> Probably a lot of sites are going to get pwned before this patch is fully deployed.</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/briankrebs/statuses/116491241531705323</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/briankrebs/statuses/116491241531705323</guid><dc:creator><![CDATA[briankrebs@infosec.exchange]]></dc:creator><pubDate>Thu, 30 Apr 2026 02:14:42 GMT</pubDate></item><item><title><![CDATA[Reply to Major authentication bypass disclosed in cPanel on Thu, 30 Apr 2026 00:43:02 GMT]]></title><description><![CDATA[<p><span><a href="/user/campuscodi%40mastodon.social">@<span>campuscodi</span></a></span> cPanel has authentication!? Next you will suggest phpBB does as well. <a href="https://securitycafe.ca/tags/snark" rel="tag">#<span>snark</span></a></p>]]></description><link>https://board.circlewithadot.net/post/https://securitycafe.ca/users/chetwisniewski/statuses/116490881127305710</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://securitycafe.ca/users/chetwisniewski/statuses/116490881127305710</guid><dc:creator><![CDATA[chetwisniewski@securitycafe.ca]]></dc:creator><pubDate>Thu, 30 Apr 2026 00:43:02 GMT</pubDate></item></channel></rss>