logo

The cPanel Situation Is…

ID: c5055386-8d8d-57e5-995d-04c8a4a1efca

STIX ID: report--c5055386-8d8d-57e5-995d-04c8a4a1efca

Feed Name: Censys Blog

Threat Score
85/100

Date Published: 2026-05-01

Date Updated: 2026-05-02

...
...

CVE-2026-41940, a critical pre-authentication bypass in cPanel/WHM disclosed April 29, 2026, was rapidly weaponized: Censys observed a May 1 surge where ~80% of newly malicious hosts were running cPanel, and two clearly distinct campaigns emerged—one deploying Mirai-like malware post-compromise and another ransomware campaign that encrypted files and appended a ".sorry" extension, with thousands of affected cPanel hosts exposing encrypted files via open directories.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.