logo

Critical cPanel Auth Bypass CVE-2026-41940 Exploited by Thousands

ID: 79101151-8d3e-573f-b176-56d544895831

STIX ID: report--79101151-8d3e-573f-b176-56d544895831

Feed Name: securityonline.info

Threat Score
92/100

Date Published: 2026-05-12

Date Updated: 2026-05-12

Author: Ddos

...
...

**Executive summary:** A critical authentication-bypass vulnerability (CVE-2026-41940, CVSS 9.8) in cPanel & WHM is being actively and widely exploited worldwide, with thousands of automated attackers observed, confirmed breaches (including theft of ~4.37 GB from Southeast Asian government/military targets), and deployment of PHP backdoors (notably by actor "Mr_Rot13") used to support mining, ransomware, botnets and other malicious activity; administrators are urged to patch immediately and audit logs for unauthorized access.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.