← All Advisories

WebPros cPanel and WHM's Login Flow Authentication Bypass Gives Unauthenticated Attackers Unauthorized Access to the Control Panel; CISA's May 3rd KEV Deadline Has Passed

Last refreshed2026-09-27

Status: KEV  |  Advisory ID: CVE-2026-41940

Key Details

CVECVE-2026-41940
Vulnerability NameWebPros cPanel & WHM and WP2 (WordPress Squared) Missing Authentication for Critical Function Vulnerability
Affected productsWebPros cPanel & WHM and WP2 (WordPress Squared)
Exploitation statusListed in CISA's Known Exploited Vulnerabilities (KEV) catalog, indicating confirmed active exploitation.
Classified asCWE-306 (Missing Authentication for Critical Function)
KEV listingAdded to CISA's Known Exploited Vulnerabilities (KEV) catalog on 2026-04-30.
Exploitation prediction (EPSS)98.53% probability of exploitation in the next 30 days (100% percentile) -- FIRST.org's EPSS model.
Federal remediation deadline2026-05-03 (CISA KEV, Binding Operational Directive).

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
WebProscPanel & WHM and WP2 (WordPress Squared)
SubsystemsGeneral OT
SectorsMultiple

What to Know

WebPros cPanel & WHM (WebHost Manager) and WP2 (WordPress Squared) contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.

What to Do

Monitor WebPros's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-41940
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-41940

KEV Required Action

FieldValue
KEV Linkhttps://www.cisa.gov/known-exploited-vulnerabilities-catalog
Date Added to KEV2026-04-30
Required Action Due Date2026-05-03
Required ActionApply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.