CVE-2026-41940: cPanel & WHM - Authentication Bypass via Session-File CRLF Injection

HoneyLabs honeypots recorded 23 probes matching CVE-2026-41940 from 10 distinct source IP addresses in the last 7 days. Severity is rated CRITICAL.

This CVE is on CISA's Known Exploited Vulnerabilities list.

Request paths that identify it

  • /login/?login_only=1
  • /json-api/version

Addresses probing it

Source IPProbesNetworkCountry
148.66.142.96GoDaddy.com, LLCSingapore
13.72.110.245Microsoft CorporationUnited States
47.251.42.64Alibaba (US) Technology Co., Ltd.United States
45.142.193.1492Iic Rail LimitedRomania
103.230.85.2361NxtGen Datacenter & Cloud Technologies Pvt. Ltd.India
93.123.109.2141Techoff Srv LimitedBulgaria
62.60.130.2471Cipher Operations Doo Beograd - Novi BeogradIran
78.173.87.761Turk TelekomTürkiye

Networks it comes from

ASNOrganisationProbesSource IPs
AS26496GoDaddy.com, LLC72
AS8075Microsoft Corporation51
AS45102Alibaba (US) Technology Co., Ltd.41
AS213388Iic Rail Limited21
AS9121Turk Telekom11
AS215930Cipher Operations Doo Beograd - Novi Beograd11

Captured requests

  • /login/?login_only=1

CVE report

CVE report

Open a specific CVE from the CVE tracker.