Incident Report — Security Update: CVE-2026-41940 (cPanel & WHM / WP2)
2026-05-05

Summary
On April 28, 2026, a security vulnerability affecting cPanel & WHM environments was disclosed and assigned CVE-2026-41940. The vulnerability impacts the WP Toolkit (WP2) component and, under certain conditions, could allow unauthorized actions. Proservice immediately initiated an impact assessment across its managed infrastructure.
Technical Details
The vulnerability involves improper access control within the WP Toolkit (WP2) component in cPanel & WHM environments.
- WP Toolkit (WP2)
- cPanel & WHM installations running unpatched versions
Severity: High (Vendor Assessment)
- Attack Vector: Authenticated / Restricted Access (context-dependent)
- Impact: Potential unauthorized operations within WordPress environments
Risk Assessment
- Spread: Limited to affected cPanel & WHM instances
- Impact: Privilege abuse / Unauthorized actions
- Exploitation: Context-dependent (often requires authentication)
- Customer Risk: Medium → High, especially in shared hosting environments
Proservice Response Action Plan
- Conducted a full infrastructure audit to identify affected systems.
- Applied vendor-issued patches and security updates.
- Updated WP Toolkit (WP2) to the latest secure version.
- Verified the integrity of managed WordPress installations.
- Strengthened access controls and continuous monitoring.
- Reviewed system logs for any indicators of compromise.
Customer Impact
✓ Status: No exploitation attempts were detected.
No unauthorized access to customer data was identified, and all services continued operating normally without interruption.
Mitigation & Recommendations
- Regularly update cPanel & WHM.
- Keep WP Toolkit and WordPress installations fully updated.
- Enable strong authentication, including Two-Factor Authentication (2FA).
- Restrict administrative access to trusted personnel only.
- Continuously monitor account logs and user activity.
Status
Remediation Guide
/scripts/upcp --force
Update WP Toolkit from the WHM interface
systemctl restart cpanel
Enable Two-Factor Authentication (2FA)
Audit all WordPress installations
Other Incidents

Incident Report — Security Update: CVE-2026-41940 (cPanel & WHM / WP2)
Company: Proservice
Publication Date: May 5, 2026
Identification Date: April 28, 2026
Status: Resolved


Incident Report — Linux Kernel Privilege Escalation Vulnerability (CVE-2022-0847)
Company: Proservice
Publication Date: May 5, 2026
Identification Date: May 4, 2026
Status: Resolved
