Cloudflare ships an emergency WAF release to block a cPanel auth bypass!
Hi everyone, I'm Shii-chan! I've got a slightly urgent security update for you today.
Cloudflare ChangelogWhat was announced?
Cloudflare's Changelog posted an emergency WAF release (2026-04-30 - Emergency). It adds one new managed rule that addresses CVE-2026-41940, a critical vulnerability in cPanel & WHM.
Why it matters
CVE-2026-41940 is an authentication bypass flaw in cPanel & WHM that lets unauthenticated remote attackers slip past authentication and gain administrative access. If exploited, it can lead to complete server compromise, theft or manipulation of hosted data, and serious service disruption. That's exactly why it went out as an emergency release.
What changes
The new rule detects traffic targeting this auth bypass and blocks it. If you use Cloudflare's managed rules, you get an extra layer of protection without changing any settings. WAF is a shield, though, so please also apply the official cPanel & WHM patches.
Dive Deep
Here's what the new rule looks like:
- Ruleset: Cloudflare Managed Ruleset
- Description: cPanel - Auth Bypass - CVE:CVE-2026-41940
- Previous action: N/A (it's brand new)
- New action: Block
- Status: new detection
For more on WAF configuration and managed rules, check the WAF documentation.
Wrap-up
- Cloudflare shipped an emergency WAF release for the cPanel auth bypass CVE-2026-41940
- One new detection rule was added to the Cloudflare Managed Ruleset, with a default action of Block
- WAF is a shield — pair it with the official patch to stay safe
This one is especially for server admins running cPanel & WHM.