cPanel Patch Fixes Critical Authentication Flaw Across Supported Versions

TL;DR
cPanel released security updates to fix a critical authentication vulnerability across all supported versions, listing patched builds (11.110.0.97, 11.118.0.63, 11.126.0.54, 11.132.0.29, 11.134.0.20, 11.136.0.5); Namecheap temporarily blocked cPanel/WHM ports 2083 and 2087 as a precaution, with patches rolling out and some servers already updated as of April 29, 2026.
- Critical cPanel Authentication Vulnerability Identified — Update Your Server Immediately The Hacker News
- The Internet Is Falling Down, Falling Down, Falling Down (cPanel & WHM Authentication Bypass CVE-2026-41940) watchTowr Labs
- cPanel Releases Emergency Patch for Critical Authentication Flaw gbhackers.com
- All supported cPanel versions hit by critical auth bug, now patched Security Affairs
- cPanel Authentication Bypass Was Already Being Exploited Before the Patch Even Dropped cyberkendra.com
Want the full story? Read the original reporting
Read on The Hacker News