
Emergency patch seals critical cPanel/WHM auth-bypass flaw (CVE-2026-41940)
An authentication-bypass vulnerability in cPanel/WHM (CVE-2026-41940, severity 9.8) affects nearly all supported versions. An emergency patch has been released and admins must run /scripts/upcp --force to install patched builds (11.110.0.97, 11.118.0.63, 11.126.0.54, 11.132.0.29, 11.136.0.5, 11.134.0.20). Unsupported versions will not receive updates; upgrade to a supported version ASAP. If exploited, attackers could gain full control of hosting accounts and servers, enabling backdoors, data theft, spam or malware deployment. Namecheap temporarily blocked ports 2083/2087 to mitigate risk.





