Attackers exploit cPanel CVE-2026-41940 to deploy Filemanager Backdoor
ID: 8620db5b-ecab-5fcb-ac06-e2e550fa525f
STIX ID: report--8620db5b-ecab-5fcb-ac06-e2e550fa525f
Feed Name: Security Affairs
Attackers are actively exploiting the critical cPanel authentication-bypass vulnerability CVE-2026-41940 (CVSS 9.3) to deploy a Go-based 'Payload' infector and a Filemanager backdoor that install SSH keys, inject PHP/JS webshells, steal credentials, and exfiltrate data (including a reported 4.37 GB theft from targeted Southeast Asian government/military entities). Researchers link the activity to the long-running group Mr_Rot13, report thousands of malicious IPs and multi-platform support, and have published detection tools, indicators, and mitigation guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
