Attackers are actively exploiting a critical authentication bypass bug in cPanel (CVE-2026-41940) that gives them full server control,…