PoC Exploit for cPanelSniper Raises Alarm Over Mass Server Compromise
ID: 04275d19-ea59-5711-8316-6cfbe9884b88
STIX ID: report--04275d19-ea59-5711-8316-6cfbe9884b88
Feed Name: Cyber Press
A weaponized public exploit framework called cPanelSniper leverages a critical authentication bypass in cPanel/WHM (CVE-2026-41940) that allows attackers to inject CRLF-crafted data into session files and gain root-level access without credentials; the Python PoC requires no external dependencies and has been rapidly weaponized with reports of at least 44,000 compromised IPs scanning honeypots. Administrators are urged to apply vendor patches immediately, search session directories for indicators of compromise, rotate administrative credentials, and monitor for unauthorized accounts and persistence.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
