CVE-2026-41940: cPanel Auth Bypass Exploited 65 Days as 0-Day, 1.5M Servers Exposed
Critical authentication bypass (CVSS 9.8) in cPanel & WHM via CRLF injection in cpsrvd. Exploited in the wild since February 23, patched April 28. Full technical breakdown, detection rules, mitigation, and post-compromise checklist for hosting provid


