logo

Critical cPanel Vulnerability Weaponized to Target Government and MSP Networks

ID: 4458bd74-d899-5f34-9ded-e67565feebbe

STIX ID: report--4458bd74-d899-5f34-9ded-e67565feebbe

Feed Name: The Hacker News

Threat Score
85/100

Date Published: 2026-05-04

Date Updated: 2026-05-05

Author: [email protected] (The Hacker News)

...
...

A previously unknown threat actor actively exploited CVE-2026-41940 in cPanel/WHM to target government and military domains in Southeast Asia and a cluster of MSPs and hosting providers globally. The campaign used public PoCs and a custom exploit chain (authenticated SQL injection + RCE) against an Indonesian defense portal, employed AdaptixC2 plus OpenVPN and Ligolo for persistent access and pivoting, and resulted in exfiltration of Chinese railway-sector documents; Shadowserver observed up to ~44,000 likely compromised IPs scanning honeypots, and third parties rapidly weaponized the vulnerability with Mirai variants and the Sorry ransomware.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.