Brand
cPanel (WebPros): actively exploited vulnerabilities
1 vulnerability in a cPanel (WebPros) product (cPanel & WHM (WP Squared)) is in CISA’s catalog of exploited vulnerabilities. It was added on April 30, 2026.
-
1 vulnerability added in the last 12 months
-
1 exploited vulnerability in the catalog, in total
-
0 added in the last 30 days
By category
Add just one cPanel (WebPros) category to your radar, or open its page.
- Web and application servers 1 vulnerability
A high count also reflects how widely a product is deployed and how much attackers care about it: it is not a security rating.
Affected products
- cPanel & WHM (WP Squared)1 vulnerability, Web servers
Name used by CISA: WebPros. Product families: indicative classification by this site.
Patch first
In the order of the main list (Patch first): recent additions first, then the most severe. The number is the rank within this cPanel (WebPros) list.
- Rank 1
cPanel (WebPros) cPanel & WHM (WP Squared)CVE-2026-41940
WebPros cPanel & WHM and WP2 (WordPress Squared) Missing Authentication for Critical Function Vulnerability
Ransomware
CVSS severity 9.8critical
Added Apr 30, 2026
Follow and verify
Indicative classification, based on the vendor and product names given by CISA. How products are classified.