logo

cPanelSniper PoC Exploit Disclosed as 44,000 Servers Reportedly Compromised

ID: 40d654e7-f3fd-5d6b-b8b6-a929d9cf41d1

STIX ID: report--40d654e7-f3fd-5d6b-b8b6-a929d9cf41d1

Feed Name: GBHackers

Threat Score
90/100

Date Published: 2026-05-02

Date Updated: 2026-05-02

Author: Divya

...
...

A critical zero-day (CVE-2026-41940) in cPanel/WHM enables unauthenticated CRLF-based session injection to escalate to root; an open-source Python framework named "cPanelSniper" automates the multi-stage exploit, Shadowserver reports ~44,000 compromised hosts being weaponized into a botnet, and operators are urged to apply emergency patches and hunt for malformed multi-line session artifacts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.