GITHUB-ACTIONS · JULY 2026 · EARLY WARNING

GitHub Actions Abused to Exploit CVE-2026-41940 in cPanel and WHM

EARLY WARNING · UNCONFIRMED. This page describes a developing threat that 0Day surfaced from early signals and has not yet independently confirmed. Details may change. Always verify against the primary sources before acting.
CVE-2026-41940Severity: HIGH

An early warning indicates that GitHub Actions in compromised repositories are being abused to exploit CVE-2026-41940 in cPanel and WHM, potentially leading to credential theft.

What happened

Reportedly, a large-scale campaign has been leveraging compromised GitHub repositories to target cPanel and WHM instances. Malicious GitHub Actions workflows have been added to these repositories, which, when triggered, download a Linux payload from attacker-controlled infrastructure. This payload scans for and exploits CVE-2026-41940, an authentication bypass vulnerability, to gain elevated control over the control panel and harvest various sensitive data including credentials and configuration files.

The campaign appears to involve malicious development versions of PHP packages associated with a legitimate developer, which were compromised between July 12 and 13, 2026. The PHP libraries themselves were not the execution path; instead, the malicious GitHub Actions workflows were the primary mechanism for launching the attack.

Professional software engineers are advised to investigate and monitor their GitHub Actions for any suspicious activity. Additionally, reviewing cPanel and WHM configurations for potential compromises is recommended. Primary sources should be consulted for the most accurate and up-to-date information on this ongoing investigation.

How 0Day mitigates this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If cpanel is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Join the 0Day waitlist →

← Back to all threats