logo

Stealthy hackers exploit cPanel flaw in active backdoor campaign (CVE-2026-41940)

ID: be47309f-3ea4-5201-9f6b-87dd932b7902

STIX ID: report--be47309f-3ea4-5201-9f6b-87dd932b7902

Feed Name: Help Net Security

Threat Score
88/100

Date Published: 2026-05-12

Date Updated: 2026-05-12

Author: Zeljka Zorz

...
...

Security researchers at XLab warn of an active campaign exploiting CVE-2026-41940 in cPanel & WHM that allows unauthenticated administrator access; attackers dubbed "Mr_Rot13" gain control of vulnerable hosts, change root passwords, plant SSH keys, drop PHP web shells, inject credential-harvesting code into the cPanel login page, install a cross-platform "Filemanager" trojan, and exfiltrate database passwords, SSH keys, and command history to attacker servers and a private Telegram group. The campaign is widespread (over 2,000 attacker-controlled IPs observed), has been linked to ransomware (including Sorry) and Mirai activity, and XLab has published indicators of compromise while cPanel has released patches and detection updates.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.