Is my server vulnerable to CVE-2026-41940?
If your cPanel/WHM build is older than the patched versions released on April 28, 2026 (11.86.0.41, 11.110.0.97, 11.118.0.63, 11.126.0.54, 11.130.0.19, 11.132.0.29, 11.134.0.20, 11.136.0.5; WP Squared 136.1.7), yes. The vulnerability affects all cPanel/WHM versions after 11.40 and is exploitable over the public network with no authentication. Even if WHM ports 2086/2087 are firewalled, the proxy-subdomain rewrites used by default cPanel installs (whm.example.com, webmail.example.com) expose the vulnerable login flow through the public web. We verify the patch level and the proxy-subdomain attack surface as the first step of every engagement.
Can you fix the token_denied cPanel issue?
Yes — when caused by malicious or injected session files. We remove the affected files, patch cPanel/WHM, and check for related compromise indicators.
Will you update cPanel/WHM as part of the cleanup?
Yes. Patching is a critical part of cleanup. Removing malicious files without patching leads to reinfection.
Is root SSH access required?
Yes. Proper cleanup and verification require root-level access. WHM access is helpful, but SSH is usually required for a complete incident response.
What stops the same attack from succeeding tomorrow?
Patching the underlying vulnerability (CVE-2026-41940 and any others discovered during triage), closing the proxy-subdomain attack surface, rotating every credential, tuning cPHulk and CSF to detect repeat probes, and giving you a checklist of what to monitor going forward. No honest security firm guarantees the future — what we deliver is a patched, hardened, documented server that is dramatically harder to reinfect through the same path.
Should I take a backup first?
Yes, strongly recommended. We can help you create one before cleanup begins if you don't already have one.
Do you support CloudLinux, Imunify360, and CSF?
Yes — plus LiteSpeed, Apache, Exim, and standard WHM stacks.
Do you work with EU and US clients?
Yes. Engagements are billed in EUR or USD; invoicing supports VAT and US W-9.