Skip to main content

Critical cPanel/WHM Security Vulnerability: Access Restrictions in Place

CVE-2026-41940

Written by Les Barton

Summary

cPanel has disclosed a critical authentication bypass vulnerability (CVE-2026-41940) in their cPanel and WHM software. The flaw affects all currently supported versions and allows unauthenticated remote attackers to gain unauthorized access to the control panel.
​

cPanel has released patches for currently supported versions, but older operating system versions have not received a patch. Servers running those older OS versions remain exposed, and that is what BigScoots is actively mitigating.


This is a vulnerability in cPanel's software. It is not an issue with BigScoots infrastructure or configuration.

Need access right now? Contact us for an IP whitelist

If your server is affected and you need cPanel or WHM access, open a support ticket and request an IP whitelist. On request, we can whitelist your individual IP address so you can connect to cPanel or WHM directly while standard access remains restricted for everyone else.
​


When you submit your ticket, please include the public IP address you'd like whitelisted. If you don't know your IP, you can find it at https://www.bigscoots.com/whatsmyip/.

Is my server affected?

Access restrictions have been applied selectively to servers running older OS versions that cPanel has not patched. Not all servers are impacted. If you attempt to log in to cPanel or WHM and find access is unavailable, your server is among those we've temporarily restricted.
​

If you're unsure whether your server is affected, open a support ticket and we'll confirm.

What we've done

On affected servers:

  • Closed TCP ports 2083 (cPanel) and 2087 (WHM)

  • Disabled Service/Proxy Subdomains as recommended by cPanel

What this means for you

Your websites, applications, databases, and email continue to function normally. Only direct cPanel and WHM logins are affected on impacted servers. We've reviewed our server logs and found no evidence of unauthorized access.

When will normal access be restored?

Restrictions will remain in place on affected servers until cPanel releases a patch for the older OS versions involved, or until those servers are migrated to a supported OS where a patch is available. We'll update this article as the situation changes.

Reference

Did this answer your question?