Hackers Abuse Critical cPanel Authentication Bypass to Compromise Hosting Servers
Attackers exploited critical cPanel CVE-2026-41940 on hosting servers, deploying Mirai variants and ransomware.
Threat actors exploited CVE-2026-41940, a CVSS 9.8 authentication bypass in cPanel and WHM session handling, to access internet-facing hosting servers. cPanel patched the issue on April 28, 2026, but activity surged from April 30, and JPCERT/CC linked a sharp rise in Mirai-like Telnet traffic in Japan to the flaw using Censys and NICTER intelligence. Censys found roughly 80 percent of hosts newly classified as malicious on May 1 were running cPanel or WHM. Researchers observed Mirai-family malware and separate ransomware that encrypts files with a ".sorry" extension.