<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>devtake.dev — #watchtowr</title><description>Articles tagged watchtowr on devtake.dev.</description><link>https://devtake.dev/</link><language>en-us</language><item><title>70 million domains had a no-password root bypass. cPanel rushed an emergency patch.</title><link>https://devtake.dev/article/cpanel-whm-auth-bypass-cve-2026-41940/</link><guid isPermaLink="true">https://devtake.dev/article/cpanel-whm-auth-bypass-cve-2026-41940/</guid><description>cPanel shipped fixes April 28 for a CVSS 9.8 auth bypass that walks attackers into shared-hosting panels with no password. WatchTowr says exploitation started before the patch.</description><pubDate>Fri, 01 May 2026 11:25:00 GMT</pubDate><category>security</category><category>security</category><category>cpanel</category><category>web-hosting</category><category>cve-2026-41940</category><category>auth-bypass</category><category>watchtowr</category><category>credential-theft</category><category>supply-chain</category><author>luca-reinhardt</author></item></channel></rss>