Stealthy hackers exploit cPanel flaw in active backdoor campaign (CVE-2026-41940)
ID: be47309f-3ea4-5201-9f6b-87dd932b7902
STIX ID: report--be47309f-3ea4-5201-9f6b-87dd932b7902
Feed Name: Help Net Security
Security researchers at XLab warn of an active campaign exploiting CVE-2026-41940 in cPanel & WHM that allows unauthenticated administrator access; attackers dubbed "Mr_Rot13" gain control of vulnerable hosts, change root passwords, plant SSH keys, drop PHP web shells, inject credential-harvesting code into the cPanel login page, install a cross-platform "Filemanager" trojan, and exfiltrate database passwords, SSH keys, and command history to attacker servers and a private Telegram group. The campaign is widespread (over 2,000 attacker-controlled IPs observed), has been linked to ransomware (including Sorry) and Mirai activity, and XLab has published indicators of compromise while cPanel has released patches and detection updates.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
