Critical cPanel Auth Bypass CVE-2026-41940 Exploited by Thousands
ID: 79101151-8d3e-573f-b176-56d544895831
STIX ID: report--79101151-8d3e-573f-b176-56d544895831
Feed Name: securityonline.info
**Executive summary:** A critical authentication-bypass vulnerability (CVE-2026-41940, CVSS 9.8) in cPanel & WHM is being actively and widely exploited worldwide, with thousands of automated attackers observed, confirmed breaches (including theft of ~4.37 GB from Southeast Asian government/military targets), and deployment of PHP backdoors (notably by actor "Mr_Rot13") used to support mining, ransomware, botnets and other malicious activity; administrators are urged to patch immediately and audit logs for unauthorized access.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
