logo

44,000 IPs Hijacked: cPanel’s 9.8 CVSS Authentication Bypass Triggers Global Ransomware Surge

ID: a01afdae-79b0-521f-83bc-8b9032a2d11f

STIX ID: report--a01afdae-79b0-521f-83bc-8b9032a2d11f

Feed Name: securityonline.info

Threat Score
88/100

Date Published: 2026-05-02

Date Updated: 2026-05-02

Author: Ddos

...
...

The report warns of CVE-2026-41940 — a CRLF injection in cPanel & WHM allowing passwordless admin access — which CISA added to its KEV catalog; evidence shows active exploitation at scale (tens of thousands of compromised IPs, a May 1 spike of ~19,000 malicious hosts with ~15,000 cPanel systems affected, ~7,000 servers showing ".sorry" ransomware renames), and recommends immediate forced updates and patch verification.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.