type: vulnerability ยท created: 2026-08-30 ยท updated: 2026-08-30 ยท tags: [cve, cpanel, whm, auth-bypass, actively-exploited, acsc, australia, critical] ยท confidence: high ยท severity: critical ยท affected_sectors: [Global (Macro)] ยท au_impact: true
CVE-2026-41940
CVE-2026-41940 is a critical authentication-bypass vulnerability in cPanel/WebHost Manager (WHM) that was flagged by the Australian Cyber Security Centre (ACSC) for active exploitation in Australia in May 2026. It is the first of two critical cPanel issues disclosed this year, preceding the domain-parking root-code-execution flaw CVE-2026-65643.
The ACSC alert on active exploitation within Australia makes this directly relevant to local hosting providers and the shared-hosting market. Organisations running affected cPanel/WHM builds should confirm they are patched and review hosting accounts for signs of unauthorised administrative access, consistent with ACSC Essential Eight rapid-patching expectations.