InfoTransec

News

daily

CPanel exploit hits 40K servers quickly

Within 24 hours of public disclosure, attackers weaponized CVE-2026-41940, a critical authentication bypass in cPanel and WebHost Manager, compromising at least 44,000 servers by April 30. By May 3, that…
daily

Pre Authentication Attacks Now Bypass Web Hosting at Scale

Web hosting infrastructure is failing before authentication occurs. The cPanel vulnerability, CVE-2026-41940, allows attackers to inject session data before password verification begins, granting control over hosting systems, client websites, and…