Critical cPanel Vulnerability Exploited for Hosting Server Compromise
Article Content
- •CVE-2026-41940 allows unauthenticated access to cPanel and WHM.
- •Exploitation activity surged immediately after public disclosure on April 30, 2026.
- •Compromised servers can lead to significant data exposure and malware deployment.
Threat actors exploited CVE-2026-41940, a critical authentication bypass in cPanel and WHM, allowing remote, unauthenticated access to hosting servers. The vulnerability, with a CVSS score of 9.8, affects cPanel versions released after 11.40. Following the public disclosure on April 29, 2026, exploitation activity surged starting April 30, particularly targeting Telnet services. JPCERT/CC reported a significant increase in Mirai-like scanning traffic, with many malicious hosts identified as running cPanel. The exploitation led to deployment of Mirai-family malware and ransomware attacks. cPanel issued patches on April 28, 2026, but many systems remained vulnerable post-disclosure. The campaign represents a shift in Mirai's operational scope, now targeting hosting servers for greater bandwidth and processing power.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Mirai and CVE-2026-41940 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
DDoS Attacks Surge 178% in MENA Region Amid Rising Threats DDoS attacks in the Middle East and North Africa surged by 178% year-on-year in the first half of 2026, with average attack bandwidth increasing by 300%. The UAE, Saudi Arabia, and Iran were the most targeted countries, with the UAE absorbing 27% of all attacks. StormWall's report attributes the rise to expanding…
KATARU IoT Malware Exploits Linux Vulnerabilities for DDoS Attacks The KATARU malware targets internet-exposed IoT devices using Telnet credential brute-forcing. Once access is gained, it attempts to escalate privileges using public Linux exploits, including CVE-2026-46300, CVE-2026-43284, and CVE-2026-31431. The malware combines Mirai-style DDoS capabilities with encrypted…