Hackers Exploit cPanel CVE-2026-41940 Auth Bypass to Deploy Mirai Malware
Attackers are exploiting CVE-2026-41940, a critical unauthenticated cPanel/WHM auth bypass, to compromise hosting servers and recruit them into Mirai botnets.
JPCERT/CC observed a sharp rise in Mirai-like packets targeting TCP port 23 beginning April 30, with many source addresses at hosting providers exposing cPanel/WHM admin interfaces. CVE-2026-41940 lets unauthenticated attackers bypass login on vulnerable cPanel and WHM systems to gain administrative access, alter settings, add malicious files, and pivot to other systems. Exploitation was likely tied to Mirai or a Mirai variant, converting hosting servers into botnet nodes; Japanese-origin Telnet traffic rose to roughly 15 times prior levels. The US accounted for the largest traffic share, with sharp increases around May 1 in Germany, France, and Canada.
- JPCERT/CC saw Mirai-like traffic to TCP port 23 surge starting April 30
- Many source addresses belonged to hosting providers exposing cPanel/WHM admin interfaces
- CVE-2026-41940 allows unauthenticated attackers to bypass login and gain administrative access
- Japanese-source Telnet traffic rose to roughly 15 times pre-surge levels; US had the largest share
- Defenders should patch cPanel, disable Telnet, enforce strong credentials, and review admin logs
Vulnerabilities mentionedAll →
- CVE-2026-419409.399%Missing-Authentication Bypass in WebPros cPanel & WHM (AuthBypass to RCE)published · WebPros cPanel KEV ransomware PoC ×7
Full article718 words · extracted from cybersecuritynews.com · click to collapse
Hackers are exploiting a critical cPanel and WHM flaw to place Mirai malware on exposed servers, extending a botnet threat normally associated with connected devices.
The activity produced a sharp rise in suspicious Telnet traffic and exposed a wider Internet security problem. Its use directly against servers creates concern for organizations that may not associate conventional hosting infrastructure with Mirai-driven botnet operations.
The issue, CVE-2026-41940, lets an unauthenticated attacker bypass the login process on vulnerable cPanel and WHM systems. With administrative access, an intruder can alter settings, add malicious files, and attack other systems.
The campaign shows why unpatched management interfaces remain targets. Analysts at JPCERT/CC identified a sudden increase in Mirai-like packets aimed at TCP port 23 in early May.
The surge began on April 30 and then gradually declined, but connected compromised hosting infrastructure to a botnet ecosystem.
Many observed source addresses belonged to hosting providers, and researchers found cPanel administration interfaces when they visited those addresses.
JPCERT/CC said in a report shared with Cyber Security News (CSN) that the monitoring cannot prove the infection path alone. Still, separate reporting indicated exploitation was likely tied to Mirai or Mirai-variant activity.
Hackers Exploit cPanel CVE-2026-41940 Auth Bypass
CVE-2026-41940 is a severe authentication-bypass flaw affecting cPanel and WHM deployments. It enables access to administrative functions without a valid account, creating a route to complete compromise.
Earlier coverage of active cPanel zero-day exploitation detailed how the weakness was exploited before organizations had time to apply emergency fixes.
Once inside, attackers can turn a web-hosting server into an operational foothold instead of simply stealing hosted data.
Mirai-derived code can use that foothold to probe exposed services, spread through additional targets, or supply traffic for denial-of-service operations. This broadens the impact beyond one breached control panel, especially where providers manage many sites.
.webp)
The observed traffic focused on port 23, commonly used by Telnet, a legacy remote-access protocol that should not be exposed.
Mirai families have repeatedly abused weak credentials and reachable remote services; the evolving Mirai botnet threat shows why attackers seek fast ways to add systems to their networks.
The activity may have involved Mirai infections exploiting CVE-2026-41940. The organization also noted reports of other harm unrelated to Mirai, showing that authentication bypass enables other abuse.
Worldwide Signals and Defensive Steps
The United States accounted for the largest source-traffic share. Sharp increases also appeared around May 1 in Germany, France, and Canada.
Changing regional patterns suggested that infections were distributed across the Internet rather than limited to a single country, provider, or cluster of servers.
Japan reflected the same trend. Mirai-like traffic from Japanese addresses targeting port 23 rose to roughly 15 times the level seen before the increase.
At the peak, many packets came from addresses assigned to several hosting providers. The server takeover campaign analysis provides useful context on the risk created by exposed cPanel and WHM installations.
For defenders, the first priority is to install the vendor fixes for CVE-2026-41940 on every affected server and verify that no outdated instance remains reachable.
Administrators should also restrict remote administration to trusted networks, disable Telnet where it is not essential, and replace weak or reused passwords with strong unique credentials.
Organizations that suspect compromise should inspect active processes and outbound network connections, checking whether each service has a clear operational purpose.
They should also review cPanel and system logs for unexpected administrative sessions, new accounts, configuration changes, or unexplained files.
The new cPanel flaw disclosures reinforce the need to treat hosting panels as high-value systems requiring regular patching and monitoring. The incident is a reminder that Mirai is not confined to cameras, routers, and other Internet of Things devices.
A compromised server can become another botnet node, exposing its operator and customers to disruption and further abuse. Prompt patching, limited remote access, and continuous review of unusual traffic remain the most practical safeguards.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.