CVE-2026-41940 CVSS9.8 cPanel&WHM身份认证绕过漏洞

nvd.nist.gov NVD - CVE-2026-41940 watchTowr Labs – 29 Apr 26 The Internet Is Falling Down, Falling Down, Falling Down (cPanel & WHM... Hello! Yes, it'...
CVE-2026-41940 CVSS9.8 cPanel&WHM身份认证绕过漏洞
CVE-2026-41940 CVSS9.8 cPanel&WHM身份认证绕过漏洞
nvd.nist.gov

NVD - CVE-2026-41940

watchTowr Labs – 29 Apr 26

The Internet Is Falling Down, Falling Down, Falling Down (cPanel & WHM...

Hello! Yes, it's all a disaster again! Let's get this party started: 0:00 /0:12 1× No comments today, so imagine this: * We wrote something that we find very funny, * Nobody else gets it, * But...

[!quote]+
根据 cPanel 提供的信息,该漏洞会影响当前支持的所有 cPanel 和 WHM 版本。而不是某些版本、少数版本或特定发行轨道。
然后情况变得更糟,KnownHost 证实野外漏洞利用一直在进行,而且这个漏洞被用作零日漏洞,攻击我们提到的互联网重要部分的管理平面。

The Hacker News

Critical cPanel Authentication Vulnerability Identified — Update Your Server...

cPanel patches authentication flaw across supported versions, prompting Namecheap port blocks and temporary access limits.

theregister.com

Critical cPanel, WHM flaw probs exploited as 0-day, pros say

: Emergency patches out now for those managing the millions of domains assumed to be affected

2 个帖子 - 2 位参与者

阅读完整话题

来源: linux.do查看原文