‘Internet Crashes’: Critical cPanel CRLF Injection Vulnerability Puts Tens of Thousands of Websites at Risk of Total Compromise – Hosting Providers Urged to Apply CVE-2026-41940 Patch Immediately


  • New critical severity vulnerability allows authentication bypass
  • The vulnerability affects cPanel and WebHost Manager
  • Attackers can gain full root administrator rights over any server

Researchers at watchTowr Labs have dissected a critical authentication bypass in cPanel and Web Host Manager (WHM) that allows remote attackers to gain full admin access over servers that much of the Internet depends on.

The vulnerability, tracked as CVE-2026-41940 and given a severity of nearly 9.8, has been exploited in the wild, as confirmed by KnownHost.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top