Hackers Abuse CVE-2026-41940 to Take Over cPanel and WHM Servers
ID: 3df2282b-e84e-5449-a69f-9fb8ceb34dd1
STIX ID: report--3df2282b-e84e-5449-a69f-9fb8ceb34dd1
Feed Name: cybersecurityNews.com
## Executive Summary A critical CVE-2026-41940 authentication bypass in cPanel/WHM (CVSS 9.8) is being actively exploited worldwide to gain unauthenticated administrator access; the actor tracked as “Mr_Rot13” deploys an AI-like Go injector, SSH backdoors, a PHP webshell (“Cpanel-Python”), injected JavaScript credential-stealers, and a cross-platform Filemanager RAT to enable ransomware, cryptomining, and data exfiltration (including reported thefts of sensitive archives). Defanged domains and MD5 hashes are listed as IOCs; large-scale automated scanning and exploitation have been observed.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
