Critical cPanel and WHM bug exploited as a zero-day, PoC now available

2026-04-30T13:23:34Z709f8d8b4e13d3a0f8f5dd9c4a6c4fdb7e213f8a8709ec09425e5066d38c51f1
active-exploitationauthentication-bypassbackdoorcisacpanelcryptominingcve-2026-3854cve-2026-41940cve-2026-42208githublitellmnpmproof-of-conceptqinglongquick-page-post-redirectransomware-vecT-2.0rcesapsupply-chainteampcpvulnerability-patchwhmwindows-zero-daywordpresszero-day

What happened

Multiple high-impact incidents reported: a critical authentication-bypass zero-day (CVE-2026-41940) in cPanel, WHM and WP Squared is being actively exploited in the wild with a public PoC and prompted an emergency cPanel/WHM update. Other notable incidents include official SAP npm packages compromised in a suspected TeamPCP supply-chain attack to steal credentials, a dormant backdoor in the Quick Page/Post Redirect WordPress plugin, exploitation of Qinglong RCE/auth-bypass for cryptomining, and active exploitation of LiteLLM pre-auth SQLi (CVE-2026-42208). GitHub patched a critical RCE (CVE-‑_

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
709f8d8b4e13d3a0f8f5dd9c4a6c4fdb7e213f8a8709ec09425e5066d38c51f1
Enrichment time
2026-04-30T13:23:34Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Critical cPanel and WHM bug exploited as a zero-day, PoC now available · Baitaphish