cPanelSniper PoC Exploit Disclosed as 44,000 Servers Reportedly Compromised
ID: 40d654e7-f3fd-5d6b-b8b6-a929d9cf41d1
STIX ID: report--40d654e7-f3fd-5d6b-b8b6-a929d9cf41d1
Feed Name: GBHackers
Threat Score
A critical zero-day (CVE-2026-41940) in cPanel/WHM enables unauthenticated CRLF-based session injection to escalate to root; an open-source Python framework named "cPanelSniper" automates the multi-stage exploit, Shadowserver reports ~44,000 compromised hosts being weaponized into a botnet, and operators are urged to apply emergency patches and hunt for malformed multi-line session artifacts.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
