1 of 1
Story summary
- cPanel released patches for CVE-2026-41940, updating cPanel and WHM versions to releases such as 11.86.0.41 and 11.134.0.20.
- The 9.8-rated flaw, which lets unauthenticated attackers gain admin access via CRLF injection, has been exploited for 30 days, according to KnownHost CEO Daniel Pearson.
- cPanel advises running “/scripts/upcp --force”, verifying the build, restarting the service, and blocking ports 2083-2096, while Namecheap blocked ports 2083 and 2087 and applied patch on April 29 2026 02:42 UTC.
