VORANT. Threat Intelligence Sign in Get the full feed

cPanel/WHM auth bypass flaw mass exploited

critical threat government-nationaldefensetechnology

Unauthenticated attackers are exploiting a cPanel/WHM/WP Squared auth bypass (CVE-2026-41940) for root RCE, deploying ransomware, Mirai, and espionage tools.

CVE-2026-41940 is an authentication bypass in the WHM/cPanel login flow affecting versions after 11.40, allowing unauthenticated remote attackers to gain administrative access and achieve root-level remote code execution via legitimate WHM API functionality. The flaw requires only a handful of HTTP requests and no credentials, making it trivial to weaponize. watchTowr Labs published technical analysis and PoC code, and the vulnerability has been added to CISA's KEV catalog following confirmed in-the-wild exploitation.

According to KnownHost's CEO, exploitation began as early as February 23, 2026 — roughly two months before cPanel's emergency patch on April 28, 2026 — indicating attackers had a significant head start before public disclosure. Since disclosure, exploitation has accelerated sharply, with Shadowserver tracking 44,000 IP addresses associated with active scanning and exploit attempts against internet-exposed cPanel/WHM instances.

Post-compromise activity is varied and includes deployment of a Go-based Linux encryptor tied to the "Sorry" ransomware operation, Mirai botnet installation, credential harvesting, and espionage operations targeting government and military entities in Southeast Asia. Given the scale of internet-exposed cPanel/WHM installations, the ease of exploitation, and the diversity of malicious follow-on activity, organizations running affected versions should patch immediately.

Mentioned in this report

Vulnerabilities CVE-2026-41940KEV
Malware MiraiSorry

Source reporting: https://www.cisecurity.org/advisory/a-vulnerability-in-whm-cpanel-and-wp-squared-could-allow-for-remote-code-execution_2026-042

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free