QiAnXin CERT

2 exploits Active since Mar 2026
CVE-2026-41940 GITHUB CRITICAL python WRITEUP
cPanel and WHM Authentication Bypass via Login Flow
cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.
1 stars
CVSS 9.8
CVE-2026-34714 GITHUB CRITICAL python WRITEUP
Vim < 9.2.0272 - Remote Code Execution via %{expr} Injection in Tabpanel
Vim before 9.2.0272 allows code execution that happens immediately upon opening a crafted file in the default configuration, because %{expr} injection occurs with tabpanel lacking P_MLE.
1 stars
CVSS 9.2