cPanelSniper – PoC Exploit Disclosed for cPanel Vulnerability, 44,000 Servers Compromised
ID: 050b2362-3f44-5a5a-82a2-6acbbca58afd
STIX ID: report--050b2362-3f44-5a5a-82a2-6acbbca58afd
Feed Name: cybersecurityNews.com
A critical pre-authentication vulnerability in cPanel & WHM (CVE-2026-41940, CVSS 9.8) permits attackers to inject CRLF payloads into session files and forge root WHM sessions; a public Python PoC tool named "cPanelSniper" automates exploitation in a four-stage chain. Exploitation was observed in the wild as early as February 2026, with tens of thousands of attacking IPs and widespread compromise outcomes (ransomware, defacements, botnet recruitment); vendors released emergency patches and guidance to update and mitigate.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
