« Volver al listado

Cpanel

Cpanel WP Squared: vulnerabilidades y CVE

Cpanel WP Squared tiene 3 vulnerabilidades publicadas, 3 de ellas en los últimos 12 meses. 1 son críticas y 1 figuran en el catálogo de explotación activa de CISA.

CVE3
Últimos 12 meses3
Críticas1
Explotadas activamente1

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

🔴 Explotadas activamente (CISA KEV)

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-41940Crítica (9.3)99%⚠ Explotación activa29 abr 2026
cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-32992Alta (8.2)0.32%—13 may 2026
SSL verification is disabled in the DNS Cluster system. This could allow for a malicious server to man-in-the-middle the request and capture credentials.
CVE-2026-29205Alta (8.6)0.38%—13 may 2026
Incorrect privileges management and insufficient path filtering allow to read arbitrary file on the server via the cpdavd attachment download endpoints.
CVE-2026-41940Crítica (9.3)99%⚠ Explotación activa29 abr 2026
cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1078 Valid Accounts1
  2. T1190 Exploit Public-Facing Application1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Cpanel