GitHub Actions Exploited to Attack cPanel and WHM Servers

GitHub Actions Exploited to Attack cPanel and WHM Servers

First seen 23 Jul 2026, 14:24 UTC GbhackersThehackernewsFeeds.4SysopsCybersecuritynews 81% similarity 69.9

Article Content

Browse articles
ThreatCluster

A large-scale cyber campaign has compromised multiple GitHub repositories to deploy malicious workflows targeting cPanel and WHM servers. Attackers are using GitHub Actions to automate the scanning of the internet for vulnerable installations, specifically exploiting the authentication-bypass flaw CVE-2026-41940. The malicious workflows leverage GitHub's compute resources to run scans and potentially steal cloud credentials. This operation has turned trusted open-source projects into tools for widespread attacks, affecting numerous web hosting environments. The campaign has been linked to the discovery of malicious development versions across multiple Packagist PHP packages. As of now, the exploitation of this vulnerability is active, and organizations using cPanel and WHM are at significant risk.

Key Points: • Attackers are leveraging compromised GitHub repositories to exploit cPanel and WHM servers. • The campaign utilizes CVE-2026-41940, an authentication-bypass vulnerability, for attacks. • Malicious GitHub Actions workflows are being used to scan for vulnerable systems globally.

ThreatCluster AI

Timeline

2026-04-29
CVE-2026-41940 published
An authentication-bypass vulnerability in cPanel and WHM was disclosed, affecting various versions.
Feeds.4Sysops
2026-04-30
CVE-2026-41940 added to CISA KEV
CISA listed CVE-2026-41940 for active exploitation, indicating its critical nature.
Feeds.4Sysops
2026-04-30
First public PoC released
A proof of concept for CVE-2026-41940 was made public, increasing the risk of exploitation.
Feeds.4Sysops
Recent
Malicious workflows discovered
Malicious GitHub Actions workflows were found in compromised repositories, targeting web hosting servers.
Cybersecuritynews
Recent
Global botnet formation reported
Hackers are building a global botnet using GitHub Actions to scan and exploit vulnerable servers.
Gbhackers

Community

Browse all →