Hackers Exploit cPanel CVE-2026-41940 Auth Bypass to Deploy Mirai Malware
Attackers are exploiting CVE-2026-41940, a critical unauthenticated cPanel/WHM auth bypass, to compromise hosting servers and recruit them into Mirai botnets.
JPCERT/CC observed a sharp rise in Mirai-like packets targeting TCP port 23 beginning April 30, with many source addresses at hosting providers exposing cPanel/WHM admin interfaces. CVE-2026-41940 lets unauthenticated attackers bypass login on vulnerable cPanel and WHM systems to gain administrative access, alter settings, add malicious files, and pivot to other systems. Exploitation was likely tied to Mirai or a Mirai variant, converting hosting servers into botnet nodes; Japanese-origin Telnet traffic rose to roughly 15 times prior levels. The US accounted for the largest traffic share, with sharp increases around May 1 in Germany, France, and Canada.