Security: CVE-2026-41940 - cPanel & WHM / WP2 Security Update - Nabtech
Security: CVE-2026-41940 - cPanel & WHM / WP2 Security Update
Critical Security Update: CVE-2026-41940
Essential Steps to Secure Your Servers and Accounts | Updated 8 hours ago
Dear Valued Clients,
We are writing to inform you about a critical security vulnerability recently identified in the cPanel & WHM platform, documented under the identifier CVE-2026-41940. Immediate action is necessary to protect your systems and data.
Urgent
A significant authentication bypass vulnerability has been discovered, impacting multiple versions of cPanel. Systems that are not updated are at risk of exploitation.
Impacted Versions
The identified vulnerability affects all versions released after 11.40. Immediate updates are crucial for the following cPanel & WHM versions:
- 11.86.0.41
- 11.110.0.97
- 11.118.0.63
- 11.126.0.54
- 11.130.0.19
- 11.132.0.29
- 11.134.0.20
- 11.136.0.5
The security patch also extends to WP Squared, with version 136.1.7 receiving updates.
Steps for Server Administrators
Follow these steps immediately to secure your server:
- Execute the update script:
/scripts/upcp --force - Verify the updated build version:
/usr/local/cpanel/cpanel -V - Restart the cPanel service to apply changes:
/scripts/restartsrv_cpsrvd --hard - For CentOS 6 / CloudLinux 6 (using version 110.0.50), update directly:
whmapi1 set_tier tier=11.110.0.103 - Ensure cPanel update preferences are correctly configured. Manual updates may be necessary for specific custom configurations.
Additional Recommendations
To enhance security, consider the following:
- Block inbound traffic on ports 2083, 2087, 2095, and 2096.
- If unable to update, stop services temporarily:
whmapi1 configureservice...
Actions for Hosting Account Clients
Our systems are reset to the most stable backup available. We urge you to change your account passwords immediately to strengthen security.
Detection & Mitigation
Utilize the provided script to scan for potential security breaches:
#!/bin/bash
# Scan for compromised session files
SESSIONS_DIR="/var/cpanel/sessions"
...
Run the script to identify any indicators of compromise and take appropriate action.
Full Article & Additional Resources
Detailed information and command references are available in the full cPanel Security Notice.
Need Assistance?
If you require further assistance or have questions, please don't hesitate to reach out to our technical support team. Your security remains our priority.
Related articles
- How to Protect Website Images From Being Displayed at an External Website
- How to Password Protect a Directory in cPanel
- How to Restrict Access to Directories by IP Address
- How to Block an IP Address to Deny Access to Your Website
- How to Disable the Two-Factor Authentication on Your cPanel Account
- Lost Password Reset - Nabtech
- SiteLock Website Security - Nabtech
- NordVPN - Nabtech
Was this article helpful?
Discussion
Loading the discussion…
Sign in to join the discussion.
