cPanel Under Pressure: Mirai Botnets Exploited CVE-2026-41940 Auth Bypass in the Wild as cPanel and WebPros Ship Root Code-Execution and Tenant-Isolation Patches · ZeroHour
cPanel Under Pressure: Mirai Botnets Exploited CVE-2026-41940 Auth Bypass in the Wild as cPanel and WebPros Ship Root Code-Execution and Tenant-Isolation Patches
What's new: No new reports or facts since the previous summary — all six sources predate it, with the latest being Canada's AV26-961 advisory (2026-09-24T14:43:22Z). This merge re-surfaces specifics under-emphasized previously: CVE-2026-41940's CVSS 9.8 rating, its April 28, 2026 patch date and fixed builds (11.110.0.97, 11.132.0.29, 11.136.0.5), Censys's finding that roughly 80 percent of hosts newly…
Merged summary · glm-5.3 · rewritten as coverage arrives
Attackers exploited CVE-2026-41940, a CVSS 9.8 unauthenticated cPanel/WHM authentication bypass, to turn hosting servers into Mirai botnet nodes (with '.sorry'-extension ransomware also observed); cPanel's September 22, 2026 release fixed three…
This story spans two converging cPanel/WHM storylines. First, threat actors exploited CVE-2026-41940, a CVSS 9.8 unauthenticated authentication bypass in cPanel/WHM session handling, against internet-facing hosting servers. cPanel shipped fixes on April 28, 2026 (builds 11.110.0.97, 11.132.0.29, and 11.136.0.5), but exploitation surged from April 30. JPCERT/CC, using Censys and NICTER intelligence, linked a sharp rise in Mirai or Mirai-variant packets targeting Telnet (TCP port 23) to the flaw: many source addresses belonged to hosting providers exposing cPanel/WHM admin interfaces, Japanese-origin Telnet traffic rose to roughly 15 times prior levels, the US accounted for the largest traffic share, and sharp increases appeared around May 1 in Germany, France, and Canada. Censys found roughly 80 percent of hosts newly classified as malicious on May 1 were running cPanel or WHM. The bypass lets unauthenticated attackers gain administrative access, alter settings, add malicious files, and pivot to other systems; post-exploitation payloads included Mirai-family malware and ransomware that encrypts files with a '.sorry' extension. Recommended defenses include patching cPanel, disabling Telnet, enforcing strong credentials, and reviewing admin logs. Second, on September 22, 2026, cPanel disclosed and fixed three tenant-isolation flaws affecting cPanel & WHM version 120 and later: CVE-2026-87899 (any authenticated cPanel user can execute code as root; The Hacker News and Canada's advisory place it in CalDAV/CardDAV), CVE-2026-87900 (WP Toolkit through 6.11.2-10794; a user can alter other accounts' databases), and CVE-2026-68490 (CWE-732 incorrect CalDAV/CardDAV permissions; a local user on a shared server can read, but not modify, other accounts' calendars and contacts; NVD had assigned no CVSS score at publication). Fixed builds are 11.134.0.57, 11.136.0.41, and 11.138.0.8 (covering cPanel lines 134, 136, and 138) plus WP Squared 11.138.1.11 or later, with WP Toolkit requiring a separate upgrade to 6.11.3 or later; the updates also repair existing storage permissions. cPanel reports no exploitation of these flaws, they were not in CISA's KEV catalog, and no temporary workaround is offered. On September 24, 2026, Canada's Cyber Centre issued advisory AV26-961 covering WebPros products (Plesk, its extensions, WP Toolkit, and cPanel/WHM), adding CVE-2026-68492 (arbitrary code execution as root via the Plesk RESTful API extension) and CVE-2026-87898 (root code…
Attackers are exploiting CVE-2026-41940, a critical unauthenticated cPanel/WHM auth bypass, to compromise hosting servers and recruit them into Mirai botnets.
Missing-Authentication Bypass in WebPros cPanel & WHM (AuthBypass to RCE)
published · WebPros cPanel KEV ransomware PoC ×7
CVE-2026-41940 is a CVSS 9.8 unauthenticated authentication bypass in cPanel/WHM session handling; fixes shipped April 28, 2026 (builds 11.110.0.97, 11.132.0.29, 11.136.0.5), and exploitation surged from April 30, 2026.
JPCERT/CC observed a sharp rise in Mirai or Mirai-variant packets targeting TCP port 23 (Telnet) beginning April 30, with many source addresses at hosting providers exposing cPanel/WHM admin interfaces.
Japanese-origin Telnet traffic rose to roughly 15 times pre-surge levels; the US accounted for the largest traffic share, with sharp increases around May 1 in Germany, France, and Canada.
Censys found roughly 80 percent of hosts newly classified as malicious on May 1, 2026 were running cPanel or WHM.
Post-exploitation of CVE-2026-41940 included Mirai-family malware and ransomware encrypting files with a '.sorry' extension.
On September 22, 2026, cPanel disclosed and fixed three tenant-isolation flaws affecting cPanel & WHM version 120 and later: CVE-2026-87899 (any authenticated cPanel user can execute code as root), CVE-2026-87900 (WP Toolkit through…
Fixed builds for the September 22 flaws: 11.134.0.57, 11.136.0.41, 11.138.0.8, WP Squared 11.138.1.11 or later, and WP Toolkit 6.11.3 or later; the updates also repair existing storage permissions.
cPanel reports no exploitation of the September 22 flaws, which were not in CISA's KEV catalog; no temporary workaround is offered.
Missing-Authentication Bypass in WebPros cPanel & WHM (AuthBypass to RCE)
CVE-2026-41940 is a critical missing-authentication flaw (CWE-306) in the login flow of WebPros cPanel & WHM (versions after 11.40) and WP2 (WordPress Squared) that lets unauthenticated remote attackers bypass authentication and gain unauthorized access to the control panel. Because no privileges, user interaction, or special conditions are required, any attacker who can reach the login endpoint over the network can attempt it. Beyond control-panel account takeover, public proofs of concept — including watchTowr's 'AuthBypass to RCE' exploit — show the flaw can be chained to remote code execution, and reporting indicates a single hosting customer could obtain root control of an entire shared server. Any hosting provider, MSP, reseller, or organization running cPanel/WHM or WP Squared is affected; cPanel is the dominant commercial hosting control panel, implying a very large installed base of shared-hosting servers and hosted domains. Exploitation is confirmed in the wild: CISA added it to the KEV on 2026-04-30 with known ransomware use, EPSS assigns a 98.5% probability of exploitation within 30 days (100th percentile), and multiple threat actors are actively exploiting it, including against government and MSP networks.
Do: Patch immediately per WebPros' advisory — the source data does not specify fixed version numbers, so follow vendor instructions for exact patched releases; CISA KEV/BOD 22-01 requires federal agencies to apply mitigations or discontinue use by the stated deadline (reported as Sunday). Until patched, restrict access to the cPanel/WHM login interface (IP allowlisting, VPN, or limiting management-interface exposure) and hunt for indicators of compromise such as unexpected control-panel logins, new admin accounts, webshells, or ransomware artifacts. The referenced public PoCs can be used to validate whether your instances are exploitable.
9.3
99%
KEV ransomware PoC ×7
WebPros cPanel versions after 11.40 (per CISA description)
WebPros WHM versions after 11.40 (per CISA description)
WebPros WP2 (WordPress Squared)
mass≈100,000+ internet-exposed cPanel/WHM servers, spanning tens of millions of hosted domains and millions of end users
Unauthenticated shell command injection in ConfigServer Security & Firewall (CSF)
CVE-2026-65638 is an unauthenticated shell command injection flaw (CWE-78) in ConfigServer Security & Firewall (CSF), caused by improper escaping of a request URL. An attacker who sends a crafted request URL containing shell metacharacters to the affected web-facing component can have arbitrary commands executed under the CSF service account. Successful exploitation therefore yields command execution on the server in the context of the CSF service account, with a critical CVSS 4.0 score of 9.2 reflecting high confidentiality, integrity, and availability impact on the vulnerable system. The flaw affects versions originally distributed by ConfigServer as well as versions of the WebPros-maintained fork that contain the vulnerable code; WebPros has fixed it in version 16.30, and other independently maintained CSF forks should be evaluated separately. There is no public proof of concept, the issue is not in CISA's Known Exploited Vulnerabilities catalog, and no exploitation has been reported to date.
Do: Upgrade the WebPros-maintained CSF fork to version 16.30 or later and verify which fork and version your deployment actually uses. If you run the original ConfigServer distribution or a third-party fork, monitor the respective maintainer for a patched release and assess your version independently. Until patched, restrict unauthenticated access to the CSF web interface (e.g., limit it to trusted management networks or localhost/VPN) and watch for unexpected command execution by the CSF service account.
9.2
—
ConfigServer Security & Firewall (CSF)
WebPros ConfigServer Security & Firewall (WebPros-maintained fork) Versions containing the vulnerable code; fixed in version 16.30
Other independently maintained CSF forks May also be affected; should be evaluated independently (no version ranges or fixes provided)
Authenticated eval injection in cPanel enables root code execution
cPanel 11.138.0.0 and earlier contains an eval injection flaw (CWE-95) in which attacker-controlled input reaches dynamic code evaluation without proper neutralization. A remote attacker holding any authenticated account on a cPanel server, such as an ordinary hosting customer, can trigger the flaw with crafted input and no user interaction. Successful exploitation yields arbitrary code execution as root, meaning a single low-privilege tenant can compromise the entire server and every site hosted on it. All deployments running version 11.138.0.0 or earlier are affected, which at disclosure covers essentially all active cPanel servers given that this was the current release. No public proof-of-concept or confirmed in-the-wild exploitation is known; the issue is not in CISA KEV and EPSS assigns only a 0.9% probability of exploitation within 30 days.
Do: Upgrade cPanel/WHM to a fixed release above 11.138.0.0 published under WebPros advisory AV26-861, prioritizing multi-tenant shared servers where any customer account can reach the vulnerable code. Until patched, restrict shell and feature access for untrusted accounts and review authentication logs and unexpected root-owned processes. No workaround is documented in the available data, so updating is the primary action.
Authenticated SQL Injection in cPanel EmailTrack Leads to Root RCE
CVE-2026-67401 is a critical SQL injection (CWE-89) in the EmailTrack component of cPanel, the widely used hosting control panel. An attacker holding any mail-enabled account on the server can reach the vulnerable component over the network with low privileges and no user interaction (CVSS: AV:N/AC:L/PR:L/UI:N), and the injection crosses a privilege boundary (Scope: Changed) to achieve remote code execution as root. Successful exploitation yields full compromise of the host — arbitrary commands as root with complete access to all hosted data — so every site, mailbox and account on an affected server is exposed. All cPanel deployments with mail enabled are potentially affected; the available data does not specify exact vulnerable version ranges, which are provided in WebPros security advisory AV26-908. Exploitation has not been confirmed in the wild (not in CISA KEV), but two public proof-of-concept exploits are already on GitHub, making near-term exploitation likely.
Do: Upgrade cPanel to the patched release identified in WebPros advisory AV26-908 (exact fixed version numbers are not given in the available data), prioritizing internet-facing servers that host mail-enabled accounts. Until patched, restrict access to the EmailTrack component and audit mail-enabled accounts and logs for suspicious database queries or unexpected root-level processes, since public PoC exploits are already available.
CalDAV/CardDAV Permission Flaw in cPanel Lets Local Users Read Other Accounts' Data
CVE-2026-68490 is an incorrect permission assignment (CWE-732) affecting the CalDAV/CardDAV calendar and address book service in cPanel & WHM, based on the related reporting naming cPanel. Any user who already has an account on the same server (for example, another shared-hosting tenant or a low-privilege local user) can access other accounts' calendar and contact data, because the service fails to enforce per-account boundaries on those resources. The attack is local, requires only low privileges, and no user interaction, yielding high confidentiality impact — including exposure of data in connected/subsequent systems per the CVSS 4.0 vector — but no integrity or availability impact. Practically, an attacker gains other tenants' calendars and address books, which frequently contain sensitive personal, corporate, and credential-adjacent information (meeting details, contacts, reset addresses). There is no CISA KEV entry and no public proof of concept, so exploitation status is currently none known.
Do: Update cPanel & WHM to the latest release in your supported tier (Current or LTS) and check the vendor changelog for the CalDAV/CardDAV permission fix once the exact fixed build is published. Audit calendar/contact (CalDAV/CardDAV) data directories and service logs for cross-account access by non-owner accounts, since a successful abuse leaves read traces. If the calendar and contacts service is not needed on your server, disable it to eliminate this attack surface, and treat any compromised address books as potential pivot data for phishing against your tenants.
Authenticated Root Code Execution via Untrusted Search Path in Plesk RESTful API
Plesk Obsidian versions 18.0.34 through 18.0.80.7 and 18.0.81.0 contain an untrusted search path flaw (CWE-426) that is exploitable when the Plesk RESTful API extension (versions 2.4.2 through 2.4.6) is installed. A remote attacker with any valid Plesk account (low-privilege, authenticated access is sufficient) can trigger the flaw through the extension's API, causing Plesk to load and execute a malicious component from an attacker-influenced path. Successful exploitation yields arbitrary code execution as root, giving full compromise of the host and every website and customer account it serves. This affects Plesk-powered hosting servers, VPS instances, and dedicated servers where the RESTful API extension is enabled; exploitation status is currently none known (not in CISA KEV, no public PoC).
Do: Update Plesk to 18.0.80.8 or 18.0.81.1 (or later) and update the RESTful API extension to 2.4.7 or later. If the RESTful API extension is not required, remove or disable it as the simplest mitigation. Audit Plesk authentication and extension logs for unexpected API activity by low-privileged accounts, and restrict access to the Plesk panel and API to trusted networks or VPNs.
8.7
—
Plesk Obsidian 18.0.34 to before 18.0.80.8; 18.0.81 to before 18.0.81.1
Plesk RESTful API extension 2.4.2 to before 2.4.7
largeTens of thousands of exposed servers (subset of ~100k+ Plesk servers running the RESTful API extension)
Authenticated OS Command Injection in Plesk Yields Root Code Execution
Plesk, a widely deployed hosting control panel, contains an OS command injection flaw (CWE-78) that lets a remote authenticated user run arbitrary operating-system commands with root privileges. An attacker with any valid Plesk account (including low-privileged reseller or customer logins, depending on the affected component) could submit crafted input that Plesk passes unsafely to a shell, escalating from panel access to full control of the underlying server. Because Plesk servers host customer websites, email, and databases, successful exploitation means complete compromise of every tenant and service on the box, with cross-system impact reflected in the CVSS 4.0 score of 9.4 (critical). The attack requires network access and an authenticated session, but no user interaction. There is currently no known public proof of concept and the flaw is not on the CISA KEV catalog, so exploitation status is none known.
Do: Apply the vendor's fix immediately via Plesk Updates as soon as the patched release is available, and check the Plesk security advisory for the exact fixed version. Because exploitation requires a valid login, audit Plesk user and reseller accounts for unknown or dormant credentials, enforce MFA, and restrict access to the control panel port (8443) to trusted IPs via firewall rules. Review server logs and the Plesk panel log for unexpected command execution or new cron jobs/SUID binaries, and inspect hosted sites for webshells if compromise is suspected.
9.4
—
Plesk (WebPros) Plesk hosting control panel
mass≈300,000–600,000 internet-exposed Plesk servers (order of magnitude ~10^5)
Authenticated Privilege Escalation to Root RCE in cPanel & WHM
CVE-2026-87899 is an execution-with-unnecessary-privileges flaw (CWE-250) in cPanel that lets any remote authenticated user — for example an ordinary hosting account on a shared server, or an attacker who has compromised one — execute arbitrary code with root privileges. The attack requires only low-privilege credentials and no user interaction, and a successful exploit yields complete control of the underlying server, including every other tenant's accounts, websites, databases, and email, which is consistent with reporting that the flaw enables cross-account access. This primarily threatens multi-tenant shared hosting environments where cPanel & WHM is the dominant control panel. The bug is rated critical (CVSS 4.0: 9.4) and a vendor fix has been released, but it is not on the CISA KEV list and no public proof-of-concept is known. No exploitation in the wild has been reported so far, though the pool of potentially affected servers is very large.
Do: Update all cPanel & WHM servers to the latest vendor release (via the CURRENT/RELEASE/LTS tier you track) as soon as the fix reaches your update tier, and confirm the update applied in WHM's update log. Because exploitation needs only a low-privileged hosting account, audit tenant accounts for weak or compromised credentials, enforce least privilege, and review for post-exploitation indicators such as unexpected root-owned processes, new SUID binaries, added cron jobs, modified SSH authorized_keys, and anomalous outbound traffic from the server.
9.4
—
cPanel, L.L.C. cPanel & WHM
mass≈1M+ internet-exposed cPanel/WHM servers, potentially tens of millions of hosted sites
Argument Injection in WP Toolkit for cPanel Allows Cross-Account File Read and RCE
CVE-2026-87900 is an argument injection flaw (CWE-88) in the WP Toolkit add-on for cPanel servers, affecting version 6.11.2-10794 and earlier. A remote attacker needs only a low-privileged, authenticated hosting account on an affected server and sends specially crafted arguments to WP Toolkit operations, with no user interaction required. Successful exploitation lets the attacker read arbitrary files and execute arbitrary code across other customer accounts on the same server, and press reports indicate the issue can escalate to running code as root and taking full control of the hosting server. The affected population is hosting providers running cPanel with WP Toolkit installed, along with all of their hosted customers. The flaw is rated critical (CVSS 4.0: 9.4), but it is not on the CISA KEV list, no public proof of concept exists, and no exploitation in the wild has been reported so far.
Do: Hosting providers should immediately update WP Toolkit for cPanel to any build newer than 6.11.2-10794 via WHM and verify the installed version. Because exploitation only requires an ordinary authenticated hosting account, review server logs for unusual WP Toolkit activity, cross-account file access, or unexpected processes/cron jobs, and rotate credentials if compromise is suspected. Customers on shared hosts that have not patched should treat files and credentials in their accounts as potentially exposed until the provider confirms remediation.
9.4
—
Plesk / WebPros (WP Toolkit) WP Toolkit for cPanel 6.11.2-10794 and earlier
massRoughly hundreds of thousands of servers and millions of hosted customer sites (order-of-magnitude estimate; exact count unknown)
mass
likely on the order of 100,000+ hosting server installations (order-of-magnitude estimate; exact published counts not available)
roughly hundreds of thousands of cPanel/WHM servers (millions of hosted sites on multi-tenant shared hosting)
mass
tens of millions of hosted accounts across hundreds of thousands of cPanel servers
Order of hundreds of thousands of cPanel/WHM servers, collectively hosting millions of accounts and sites