CVE-2026-41940: How a Misplaced CRLF Hands Attackers the Keys to Millions of Hosted Websites
What Is CVE-2026-41940? CVE-2026-41940 is a critical pre-authentication remote authentication bypass affecting cPanel & WHM and WP Squared — the control panel software that quietly powers an estimated 70 million domains and 94% of the web hosting control panel market. The root cause is a CRLF injection flaw in the way cPanel’s service daemon (cpsrvd)