logo

Attackers exploit cPanel CVE-2026-41940 to deploy Filemanager Backdoor

ID: 8620db5b-ecab-5fcb-ac06-e2e550fa525f

STIX ID: report--8620db5b-ecab-5fcb-ac06-e2e550fa525f

Feed Name: Security Affairs

Threat Score
88/100

Date Published: 2026-05-12

Date Updated: 2026-05-12

Author: Pierluigi Paganini

...
...

Attackers are actively exploiting the critical cPanel authentication-bypass vulnerability CVE-2026-41940 (CVSS 9.3) to deploy a Go-based 'Payload' infector and a Filemanager backdoor that install SSH keys, inject PHP/JS webshells, steal credentials, and exfiltrate data (including a reported 4.37 GB theft from targeted Southeast Asian government/military entities). Researchers link the activity to the long-running group Mr_Rot13, report thousands of malicious IPs and multi-platform support, and have published detection tools, indicators, and mitigation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.