Back Gbhackers Hackers Abuse Critical cPanel Authentication Bypass to Compromise Hosting Servers
Threat actors rapidly exploited a critical authentication bypass in cPanel and WHM to compromise internet-facing hosting servers, with Japanese telemetry data linking the campaign to a sharp rise in Mirai-like scanning and attack traffic targeting Telnet services.
The activity centers on CVE-2026-41940, a critical vulnerability in cPanel and WHM’s session-management layer that enables a remote, unauthenticated attacker to obtain access to vulnerable control-panel environments.
The vulnerability, assigned a CVSS score of 9.8, affects cPanel and WHM versions released after 11.40, as well as impacted WP Squared deployments. cPanel released fixes on April 28, 2026, but exploitation activity followed almost immediately.
The surge began on April 30 and gradually declined afterward, closely overlapping with public disclosure and active exploitation of the cPanel vulnerability .
While sensor data alone cannot establish causation, JPCERT/CC said intelligence published by Censys and Japan’s NICTER Analysis Team indicates that the increase was likely associated with Mirai or Mirai-variant infections exploiting CVE-2026-41940.
The campaign highlights an important shift in the Mirai ecosystem. Mirai is generally associated with compromised routers, cameras, DVRs, and other embedded devices using weak or default credentials.
However, compromised hosting servers can offer attackers considerably more bandwidth, processing capacity, stable connectivity, and access to tenant data than conventional IoT bots.
A breached cPanel server may also expose hosted websites, databases, mailboxes, backup archives, customer credentials, and downstream administrative accounts.
JPCERT/CC Researchers said that , TSUBAME internet monitoring system recorded a dramatic increase in packets with Mirai-like characteristics aimed at TCP port 23 in early May.
cPanel Authentication Exploited
Censys observed that roughly 80% of hosts newly classified as malicious during the May 1 surge were running cPanel or WHM, a major deviation from normal patterns.
Researchers identified at least two distinct post-exploitation paths: one involving Mirai-family malware deployment and another involving ransomware that encrypts files and appends a “.sorry” extension.
The vulnerable code resides in the cPanel and WHM authentication flow. According to cPanel, two paths can write session files to disk, but only one implemented input sanitization.
The missing sanitization in the Basic Authentication-handling path could allow specially crafted requests to cause an unauthenticated session to be treated as authenticated.
This potentially grants access without valid credentials and may enable attackers to reach highly privileged WHM administration functions.
TSUBAME analysis found that many source IP addresses generating the Mirai-like traffic belonged to hosting providers.
Researchers were able to identify cPanel administration interfaces on numerous systems by visiting those addresses, strengthening the connection between the observed botnet activity and exposed hosting infrastructure.
The United States accounted for the largest of sources, but major increases were also recorded around May 1 in Germany, France, Canada, and Japan, suggesting broad global exploitation rather than a geographically concentrated campaign.
Traffic from Japanese addresses alone climbed to approximately 15 times its pre-surge level at its peak. Across domestic and international TSUBAME sensors, TCP/23 was the most frequently observed destination port in most locations.
Other consistently targeted services included HTTPS on port 443, HTTP on ports 80 and 8080, SSH on port 22, Remote Desktop Protocol on port 3389, and alternative administration services on ports 8443 and 8728.
Administrators should urgently identify every exposed cPanel and WHM instance and upgrade to vendor-fixed releases. Patched builds include 11.110.0.97, 11.118.0.63, 11.126.0.54, 11.130.0.18, 11.132.0.29, 11.134.0.20, and 11.136.0.5.
Until systems are patched, organizations should restrict access to cPanel, WHM, and Webmail management ports 2082, 2083, 2086, 2087, 2095, and 2096 using firewall allowlists or VPN-only administration.
Incident responders should also investigate potentially affected servers for anomalous session files, unexpected privileged logins, unauthorized account creation, altered web content, unfamiliar cron jobs, suspicious running processes, and outbound scanning or Telnet traffic.
As this campaign demonstrates, a hosting control-panel compromise can rapidly become botnet infrastructure and a wider customer-impact incident.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
Artificial Intelligence
Cyber security Course
Cyber Security Resources
Cybersecurity
Information Gathering
Information Security Risks
NightEagle Uses BlueKeep and DCSync to Move Toward Active Directory Domain Controllers
10 Malicious npm Packages Linked to Runtime Malware Campaign With Millions of Downloads
PAYLOAD Ransomware Abuses Active Directory Group Policy to Disrupt Entire Windows Domain
New Rapuncel Infostealer Abuses Microsoft-Signed Driver to Disable 145 Security Tools
BigDiskBuster Windows Defender DoS Vulnerability Blocks Platform and Signature Updates
North Korea’s Hangro VPN Certificate Exposes Internal Network and Russia-Linked Infrastructure
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
