CISA's list that day
30 April 2026
On CISA added 1 vulnerability to its list of exploited vulnerabilities: CVE-2026-41940 in WebPros cPanel & WHM and WP2 (WordPress Squared). US federal agencies must fix it by .
Added that day
| Vulnerability | Product | Our group | Listed | Deadline | EPSS |
|---|---|---|---|---|---|
| CVE-2026-41940Missing Authentication for Critical Function | WebPros cPanel & WHM and WP2 (WordPress Squared) | Patch nowRansomware use, listed within a year; Metasploit module | 0.99 |