logo

Hackers target governments and MSPs via critical cPanel flaw CVE-2026-41940

ID: 6101a2c5-297d-5d15-aed7-51dd09ba23a4

STIX ID: report--6101a2c5-297d-5d15-aed7-51dd09ba23a4

Feed Name: Security Affairs

Threat Score
80/100

Date Published: 2026-05-04

Date Updated: 2026-05-05

Author: Pierluigi Paganini

...
...

Attackers are actively exploiting CVE-2026-41940, an authentication-bypass in cPanel/WHM, to compromise government, military, MSP and hosting provider systems across Southeast Asia and other countries. Observed activity includes exploitation via public PoCs (notably linked to IP 95.111.250.175), a custom exploit chain against an Indonesian defense training portal, deployment of AdaptixC2 and PowerShell reverse shells, persistent pivoting using OpenVPN and Ligolo, and exfiltration of approximately 4.37 GB of sensitive technical and personal data.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.