cPanel CVE-2026-41940 Under Active Exploitation to Deploy Filemanager Backdoor
ID: b65b1550-753d-51c8-84f2-f97c566bce4e
STIX ID: report--b65b1550-753d-51c8-84f2-f97c566bce4e
Feed Name: The Hacker News
**Executive summary:** The report attributes widespread, active exploitation of cPanel/WHM vulnerability CVE-2026-41940 to a threat actor dubbed Mr_Rot13, who uses automated attacks (over 2,000 source IPs) to deploy a Go-based infector and the Filemanager backdoor that implants SSH keys, drops PHP web shells for credential theft (ROT13-encoded exfiltration to Telegram), and delivers a cross-platform backdoor used for data collection, cryptomining, botnet propagation, and ransomware.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
