Skip to content
Critical cPanel Vulnerability Exploited for Hosting Server Compromise

Critical cPanel Vulnerability Exploited for Hosting Server Compromise

First seen 22 Sep 2026, 01:39 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 22, 2026 at 02:10 UTC
  • CVE-2026-41940 allows unauthenticated access to cPanel and WHM.
  • Exploitation activity surged immediately after public disclosure on April 30, 2026.
  • Compromised servers can lead to significant data exposure and malware deployment.

Threat actors exploited CVE-2026-41940, a critical authentication bypass in cPanel and WHM, allowing remote, unauthenticated access to hosting servers. The vulnerability, with a CVSS score of 9.8, affects cPanel versions released after 11.40. Following the public disclosure on April 29, 2026, exploitation activity surged starting April 30, particularly targeting Telnet services. JPCERT/CC reported a significant increase in Mirai-like scanning traffic, with many malicious hosts identified as running cPanel. The exploitation led to deployment of Mirai-family malware and ransomware attacks. cPanel issued patches on April 28, 2026, but many systems remained vulnerable post-disclosure. The campaign represents a shift in Mirai's operational scope, now targeting hosting servers for greater bandwidth and processing power.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-04-28
cPanel releases patches for CVE-2026-41940
cPanel issued fixes for the critical authentication bypass vulnerability affecting versions after 11.40.
Gbhackers
2026-04-29
CVE-2026-41940 published
The vulnerability was officially published, detailing its critical nature and potential impact.
Gbhackers
2026-04-30
CISA adds CVE-2026-41940 to KEV list
CISA recognized the vulnerability as actively exploited in the wild, prompting urgent attention.
Gbhackers
2026-04-30
Surge in Mirai-like traffic observed
JPCERT/CC reported a sharp increase in packets targeting TCP port 23, linked to the cPanel vulnerability.
blogs.jpcert.or.jp
2026-05-01
Malicious hosts identified
Censys reported that 80% of newly classified malicious hosts were running cPanel or WHM during the surge.
Gbhackers

More articles in this cluster (2)

Following this threat?

Track Mirai and CVE-2026-41940 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed