‘The Internet is going down’: Critical cPanel CRLF injection vulnerability puts tens of millions of websites at risk of total compromise; Hosting providers urged to apply CVE-2026-41940 patch immediately



  • New Critical Vulnerability Allows Authentication Bypass
  • The vulnerability affects cPanel and WebHost Manager
  • Attackers can gain full root administrator privileges on any server

watchTowr Labs researchers have analyzed a critical authentication bypass in cPanel and Web Host Manager (WHM) that allows remote attackers to gain full administrative access to the servers on which much of the Internet depends.

The vulnerability, tracked as CVE-2026-41940 and with a severity score close to 9.8, has been exploited in the wild, as confirmed by KnownHost.

Leave a Comment

Your email address will not be published. Required fields are marked *