logo

cPanel and WHM Servers Targeted in Attacks Exploiting CVE-2026-41940

ID: b929465a-8af7-5c28-9117-41ea78843a01

STIX ID: report--b929465a-8af7-5c28-9117-41ea78843a01

Feed Name: GBHackers

Threat Score
90/100

Date Published: 2026-05-11

Date Updated: 2026-05-11

Author: Divya

...
...

A critical CVE-2026-41940 authentication bypass in cPanel/WHM is being actively exploited by a sophisticated actor called Mr_Rot13 to gain full administrator access, deploy Go-based payload injectors and a persistent cross-platform 'filemanager' remote control Trojan, harvest credentials via injected JavaScript, implant SSH keys and webshells, and exfiltrate sensitive data (reported 4 GB from Southeast Asian government/military networks); the report provides technical TTPs and IOCs including MD5 hashes and a defanged C2 domain.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.