logo

Critrical cPanel flaw mass-exploited in "Sorry" ransomware attacks

ID: e7d97a51-0142-5d4d-8822-1cc74b711a24

STIX ID: report--e7d97a51-0142-5d4d-8822-1cc74b711a24

Feed Name: Bleeping Computer

Threat Score
90/100

Date Published: 2026-05-02

Date Updated: 2026-05-02

Author: Lawrence Abrams

...
...

A critical cPanel/WHM authentication bypass (CVE-2026-41940) has been patched but is being actively exploited in the wild to breach servers and deploy a Linux-specific 'Sorry' ransomware encryptor that appends .sorry to files; Shadowserver reports around 44,000 compromised IPs and victims receive README.md ransom notes pointing to a Tox contact.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.