Post #2026547
2026-05-01 19:39 UTC
With all of the excitement around the copy.fail vulnerability, do NOT miss CVE-2026-41940 for cPanel and WHM auth bypass (CVSS 9.8). It is being actively exploited in the wild and if you had it on some server, assume that machine is now p0wned and you need to go into remediation and rebuild.
While the impact footprint of copy.fail is massive (eg, most things running Linux) the local privilege escalation nature of it makes it relatively less urgent for most environments, whereas cPanel has a far smaller footprint but the active attack surface and impact is far worse.
(I was blissfully unaware of cPanel, preferring static site generators myself.)
#hugops to all of the people dealing with these, although I have a creeping fear that 2026 could be thsi non-stop.
#infosec #cPanel #copyfail
Replies (2)
-
@jtk@infosec.exchange 2026-05-02 12:17
@nygren@hachyderm.io There are a lot of small to medium #hosting providers using cpanel/whm. We (dataplane) use dozens of them. I will be shocked if none of those we use get owned. I fully expect some of our data to be exposed or stolen.
-
@Earl@mast.john1126.com 2026-05-04 20:58
More details.... If you use cPanel, you could look at the bottom for your current version. I think if you have 134.0.20 or higher, your cPanel has been patched. @nygren@hachyderm.io @jtk@infosec.exchange #cpanel #security #server