logo

Hackers Exploit CVE-2026-41940 to Take Over cPanel and WHM Servers

ID: 0484afa5-23b8-5673-aa4f-30dc4569339d

STIX ID: report--0484afa5-23b8-5673-aa4f-30dc4569339d

Feed Name: Cyber Press

Threat Score
92/100

Date Published: 2026-05-11

Date Updated: 2026-05-22

Author: AnuPriya

...
...

A critical CVE-2026-41940 authentication bypass affecting cPanel/WHM is being actively exploited by an actor known as Mr_Rot13 to gain full administrator privileges, deploy a Go-based infector, Python webshell, injected JavaScript credential harvesters and a cross-platform "filemanager" RAT; exploitation has been observed from over 2,000 IPs with reported exfiltration of more than 4 GB from Southeast Asian government and military networks and multiple IOCs provided (MD5 hashes and a defanged C2 domain).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.