CVE-2026-41940: cPanel & WHM - Authentication Bypass via Session-File CRLF Injection

HoneyLabs honeypots recorded 54 probes matching CVE-2026-41940 from 27 distinct source IP addresses in the last 7 days. Severity is rated CRITICAL.

This CVE is on CISA's Known Exploited Vulnerabilities list.

Request paths that identify it

  • /login/?login_only=1
  • /json-api/version

Addresses probing it

Source IPProbesNetworkCountry
103.252.221.1579Hostpalace Datacenters LtdItaly
47.251.42.66Alibaba (US) Technology Co., Ltd.United States
45.198.224.266Vpsvault.host LtdUnited States
50.116.72.423Network Solutions, LLCUnited States
68.178.167.2143GoDaddy.com, LLCUnited States
20.193.146.1593Microsoft CorporationIndia
57.159.30.222Microsoft CorporationIndia
40.81.230.772Microsoft CorporationIndia

Networks it comes from

ASNOrganisationProbesSource IPs
AS8075Microsoft Corporation1914
AS60064Hostpalace Datacenters Ltd91
AS45102Alibaba (US) Technology Co., Ltd.61
AS215925Vpsvault.host Ltd61
AS19871Network Solutions, LLC31
AS26496GoDaddy.com, LLC31

Captured requests

  • /login/?login_only=1

HTTP client fingerprints (JA4H)

  • po11nn0600_f8bf768a441b
  • po11nn0500_b4ba55311b46
  • po11nn0700_fb204b7f5765

CVE report

CVE report

Open a specific CVE from the CVE tracker.