CVE-2026-41940: cPanel & WHM - Authentication Bypass via Session-File CRLF Injection
HoneyLabs honeypots recorded 23 probes matching CVE-2026-41940 from 10 distinct source IP addresses in the last 7 days. Severity is rated CRITICAL.
This CVE is on CISA's Known Exploited Vulnerabilities list.
Request paths that identify it
- /login/?login_only=1
- /json-api/version
Addresses probing it
| Source IP | Probes | Network | Country |
|---|---|---|---|
| 148.66.142.9 | 6 | GoDaddy.com, LLC | Singapore |
| 13.72.110.24 | 5 | Microsoft Corporation | United States |
| 47.251.42.6 | 4 | Alibaba (US) Technology Co., Ltd. | United States |
| 45.142.193.149 | 2 | Iic Rail Limited | Romania |
| 103.230.85.236 | 1 | NxtGen Datacenter & Cloud Technologies Pvt. Ltd. | India |
| 93.123.109.214 | 1 | Techoff Srv Limited | Bulgaria |
| 62.60.130.247 | 1 | Cipher Operations Doo Beograd - Novi Beograd | Iran |
| 78.173.87.76 | 1 | Turk Telekom | Türkiye |
Networks it comes from
| ASN | Organisation | Probes | Source IPs |
|---|---|---|---|
| AS26496 | GoDaddy.com, LLC | 7 | 2 |
| AS8075 | Microsoft Corporation | 5 | 1 |
| AS45102 | Alibaba (US) Technology Co., Ltd. | 4 | 1 |
| AS213388 | Iic Rail Limited | 2 | 1 |
| AS9121 | Turk Telekom | 1 | 1 |
| AS215930 | Cipher Operations Doo Beograd - Novi Beograd | 1 | 1 |
Captured requests
- /login/?login_only=1
CVE report
CVE report
Open a specific CVE from the CVE tracker.