cPanel and WHM Servers Targeted in Attacks Exploiting CVE-2026-41940
ID: b929465a-8af7-5c28-9117-41ea78843a01
STIX ID: report--b929465a-8af7-5c28-9117-41ea78843a01
Feed Name: GBHackers
A critical CVE-2026-41940 authentication bypass in cPanel/WHM is being actively exploited by a sophisticated actor called Mr_Rot13 to gain full administrator access, deploy Go-based payload injectors and a persistent cross-platform 'filemanager' remote control Trojan, harvest credentials via injected JavaScript, implant SSH keys and webshells, and exfiltrate sensitive data (reported 4 GB from Southeast Asian government/military networks); the report provides technical TTPs and IOCs including MD5 hashes and a defanged C2 domain.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
