GitHub Repositories Exploited to Target cPanel and WHM Servers

GitHub Repositories Exploited to Target cPanel and WHM Servers

First seen 23 Jul 2026, 14:24 UTC ThehackernewsFeeds.4Sysops 75% similarity 69.8

Article Content

Browse articles
ThreatCluster

Attackers have compromised multiple GitHub repositories to deploy malicious GitHub Actions workflows, creating a distributed attack platform. These workflows utilize GitHub-hosted runners to download Linux payloads from a command-and-control server. The primary target of this attack is cPanel and WHM installations that are vulnerable to the authentication-bypass flaw CVE-2026-41940. This vulnerability was published on April 29, 2026, and was added to CISA's Known Exploited Vulnerabilities catalog on April 30, 2026. The exploitation of this flaw poses significant risks to affected systems, as it allows unauthorized access to server functionalities. Security professionals are urged to monitor their systems for signs of compromise and apply necessary mitigations.

Key Points: • Attackers are exploiting compromised GitHub repositories to target cPanel and WHM servers. • The attack leverages GitHub Actions workflows to deploy malicious payloads. • CVE-2026-41940 is a critical vulnerability being actively exploited in this campaign.

ThreatCluster AI

Timeline

2026-04-29
CVE-2026-41940 published
A critical authentication-bypass vulnerability affecting cPanel and WHM was disclosed.
Feeds.4Sysops
2026-04-30
CVE-2026-41940 added to CISA KEV
CISA included CVE-2026-41940 in its Known Exploited Vulnerabilities catalog due to active exploitation.
Feeds.4Sysops
2026-04-30
First public PoC released
A proof-of-concept for CVE-2026-41940 was made publicly available, increasing the risk of exploitation.
Feeds.4Sysops
2026-07-23
Attack methods reported
Reports emerged detailing how attackers are using GitHub Actions to deploy attacks against vulnerable servers.
Thehackernews

Community

Browse all →