logo

cPanelSniper – PoC Exploit Disclosed for cPanel Vulnerability, 44,000 Servers Compromised

ID: 050b2362-3f44-5a5a-82a2-6acbbca58afd

STIX ID: report--050b2362-3f44-5a5a-82a2-6acbbca58afd

Feed Name: cybersecurityNews.com

Threat Score
92/100

Date Published: 2026-05-02

Date Updated: 2026-05-02

Author: Guru Baran

...
...

A critical pre-authentication vulnerability in cPanel & WHM (CVE-2026-41940, CVSS 9.8) permits attackers to inject CRLF payloads into session files and forge root WHM sessions; a public Python PoC tool named "cPanelSniper" automates exploitation in a four-stage chain. Exploitation was observed in the wild as early as February 2026, with tens of thousands of attacking IPs and widespread compromise outcomes (ransomware, defacements, botnet recruitment); vendors released emergency patches and guidance to update and mitigate.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.