← Homepage Orderbox Status Page

Security Advisory: Critical Authentication Vulnerability in cPanel & WHM Affecting All Supported Versions – Immediate Update/Patch Required

Posted on 30th April, 2026

A critical security vulnerability affecting cPanel & WHM login authentication has recently been identified by the vendor. This issue impacts all currently supported versions of cPanel and may expose servers to unauthorized access if left unpatched.

Ref : https://support.cpanel.net/hc/en-us/articles/40073787579671-Security-CVE-2026-41940-cPanel-WHM-WP2-Security-Update-04-28-2026

The good news is that cPanel has now released the official security patch for supported versions. We strongly recommend that all customers using VPS and Dedicated Servers; update to the latest cPanel version at the earliest to avoid any potential impact from this vulnerability.

Action Required: Please update cPanel to the latest version via WHM or from the server using the standard update process.

For guidance, please refer to the official documentation: https://docs.cpanel.net/whm/cpanel/upgrade-to-latest-version/

Important Notes

  1. Servers with auto-updates enabled may already receive the patch automatically.

  2. Customers running older / unsupported cPanel versions are strongly advised to upgrade to a supported build immediately, as the vulnerability may also affect those versions.

We recommend applying this update as soon as possible as a precautionary security measure.

Please contact our Support team if you need any further assistance.