cPanel
WebPros
Actively exploited vulnerabilities
The US cybersecurity agency CISA lists this vulnerability in its catalog of Known Exploited Vulnerabilities. Check your version and patch or mitigate promptly.
- CVE-2026-41940WebPros cPanel & WHM and WP2 (WordPress Squared) Missing Authentication for Critical Function VulnerabilityRansomware
9.8 critical · over the network, without login · CISA deadline was 3 May
Source: CISA KEV. The CVE is matched to the product automatically — when in doubt, the linked NVD entry applies.
Version history & changelog · as detected by patchletter
No releases recorded yet — the source was just added.
Never miss a cPanel update
We check the source daily and email you — instantly or as a digest. Free, one-click unsubscribe.
Watch cPanelEmbed this badge
Shows the current cPanel version and updates itself. Free to use, no account needed.
[](https://patchletter.com/en/software/cpanel)https://patchletter.com/badge/cpanel.svgAlso available: ?v=eol (end of support) and ?v=cve (actively exploited).