CVE-2026-41940
cPanel & WHM Authentication Bypass
Research Framing
| Field | Value | |||||||||||||||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Decision Question | What must hosting providers, MSPs, and exposed cPanel & WHM or WP Squared operators patch, validate, preserve, and investigate now that CVE-2026-41940 has public exploit material, KEV status, and reported ransomware use? | |||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Interpreted Questions | What is the vulnerability, who is exposed, how is it exploited, what evidence supports active exploitation, how urgent is remediation, and what should hosting providers, MSPs, SMBs, and client-facing advisors do first? | |||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Initial Observations | The vendor, CVE authorities, and CISA establish a critical unauthenticated session-management bypass affecting cPanel & WHM and WP Squared, with fixed builds available and the vulnerability listed in KEV. Public technical analysis and reporting document reproducible exploitation, while incident reporting connects some exploitation to Sorry ransomware and broader hosting-control-plane impact. Patching is therefore necessary but not sufficient: exposed operators must also preserve evidence, run the vendor detection workflow, and review control-panel, hosted-account, persistence, and ransomware activity. 1 2 3 4 6 7 | |||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Source Coverage |
|
Expansion Research Add
Expansion research clarifies the website-software relationship: cPanel & WHM is a hosting control panel that can manage many hosted workloads, including WordPress, other CMS platforms, custom websites, email, databases, files, and customer accounts. CVE-2026-41940 is not a WordPress core, theme, or plugin vulnerability; WordPress is a common example of downstream impact, not the vulnerable product.17 18
1-Topic
This CVE Watch Brief covers CVE-2026-41940, a critical authentication bypass in cPanel & WHM and WP Squared. The brief is focused on practical exposure validation, exploitation status, public PoC availability, KEV urgency, downstream hosting-control-plane impact, and the evidence responders should preserve before cleanup. 1 2 3 6 13
| Focus | Source-Backed Answer |
|---|---|
| What is the issue? | An unauthenticated attacker may abuse session-management behavior in cPanel & WHM / WP Squared to reach authenticated control-panel state. |
| Who is exposed? | Hosting providers, MSPs, resellers, agencies, and SMBs whose web, mail, database, CMS, or customer-hosting workflows depend on exposed cPanel/WHM or WP Squared infrastructure. |
| Why now? | The CVE is KEV-listed, public exploit material exists, public reporting describes active exploitation and ransomware linkage, and remediation must be paired with compromise scoping. |
2-Persona / Audience Lens
This CVE / Exploit Watch Brief is written for vulnerability-management teams, hosting providers, MSPs, SOC and incident-response teams, cyber insurers, breach counsel, and SMB-facing advisors. It emphasizes immediate exposure validation, patch status, exploitation evidence, detection steps, and plain-language client communication for organizations that may not operate cPanel directly but rely on a hosting provider that does. 3 6 7
3-BLUF
- CVE-2026-41940 is a critical cPanel & WHM / WP Squared authentication bypass with CVSS 9.8 severity and no required credentials or user interaction. 1 3 6 13
- Target discovery can happen before formal reconnaissance through commodity exposure enumeration: common cPanel/WHM hostnames, ports, service fingerprints, provider patterns, passive attack-surface data, and scanning. 3 6 10 17
- This is not a WordPress vulnerability and is not limited to WordPress. It affects the hosting control panel layer used to manage websites, CMS platforms, databases, mail, domains, files, and customer accounts; WordPress sites are one common downstream exposure path. 3 13 17 18
- 28-Jun-2026 · Newly retained (>24h) CISA's official KEV feed records April 30, 2026 as the catalog-addition date, with a May 3 due date and known ransomware-campaign-use flag; cPanel's response separately references May 1 confirmation. Public reporting describes active exploitation, including Sorry ransomware follow-on activity. 2 4 7
- The vulnerability affects cPanel & WHM versions after 11.40 before the applicable fixed builds; WP Squared is fixed at 136.1.7 and later. 3 13
- watchTowr published technical analysis and PoC after vendor patches became available, materially increasing exploit reproducibility. 5 6
- 28-Jun-2026 · Newly retained (>24h) Newly retained defense-side evidence adds Cloudflare emergency WAF rule coverage and Shadowserver compromised-website report tags for sorry-ransomware, whmstealer, and mr-rot13 patterns. 23 24
- 29-Jul-2026 · Newly retained (>24h) Imperva adds bounded WAF/customer-telemetry evidence: nearly 4,000 attack requests observed across 15 industries and 17 countries, with US sites accounting for almost 70% of observed attacks. 40
- 13-Jul-2026 · Newly retained (>24h) Proofpoint adds network-telemetry context that CVE-2026-41940 exploitation followed a multi-actor mass-exploitation pattern and appeared in compromised-website web-inject chains such as TA569/SocGholish. 29
- 22-Jul-2026 · Newly retained (>24h) Coalition Security Labs adds insurer/policyholder coordination evidence: impacted policyholders were notified, provider patch progress should be tracked, and on-premises cPanel/WHM remediation needs direct evidence. 37
- 24-Jul-2026 · Newly retained (>24h) Socket adds a new activity-cluster lens: compromised GitHub repositories and GitHub-hosted Actions runners were abused as distributed CVE-2026-41940 scanning/exploitation and credential-harvesting infrastructure, while Packagist development versions were exposure artifacts rather than the execution path. 38
- 27-Jul-2026 · Newly retained (>24h) ASD's ACSC adds national-CERT scoping evidence: active exploitation was observed in Australia, and several MSP-managed products were reportedly impacted with customer compromise, but no named victim organization list was published. 39
- 18-Aug-2026 · Newly retained (>24h) Government of Guam/BSP remains the retained named public victim/disclosure row tied to the cPanel-hosted CVE-2026-41940 compromise path; DysruptionHub's August 16 update now treats the incident as presumed resolved after BSP's restoration warning disappeared and reports/data pages were repopulated, while still preserving no government-wide all-clear, exact final restoration date, confirmed data theft, ransomware finding, or actor attribution. 42 43 44
- 13-Aug-2026 · Newly retained; undated Shadowserver's current dashboard row still shows bounded CVE-2026-41940 exploit pressure: 98 last-day unique IPs, 134 seven-day average, 164 thirty-day average, 259 ninety-day average, and known ransomware-campaign-use flag. Freshness: Newly retained (publication date not visible). 41
- 11-Aug-2026 · Newly retained (>24h) China Daily / CCTV News Client reporting attributed to the National Computer Virus Emergency Response Center adds China-focused Sorry ransomware activity detail: multiple domestic attacks against internet-exposed Linux web servers, cPanel/CVE-2026-41940 initial access, sshd process masquerading, data theft, AES/RSA encryption, and weak-password SSH lateral-movement risk. 45
- For exposed systems, patching is necessary but not sufficient: run the vendor detection script, review session/access logs, scope administrator activity, and check for ransomware or web-host compromise. 3 4 7
4-Executive Summary
CVE-2026-41940 is a critical authentication bypass in cPanel & WHM and WP Squared. The vendor describes it as a session-management vulnerability in which one code path that writes session files lacked the sanitization applied elsewhere; under a specially crafted request, an unauthenticated session could be treated as authenticated. The public risk is severe because cPanel & WHM commonly sits on internet-facing hosting infrastructure and can control hosted websites, databases, email, reseller accounts, and server configuration. 3 4 6
The attacker story is straightforward enough for non-technical stakeholders: find an exposed cPanel/WHM service, send a crafted pre-authentication request that manipulates session state, reach privileged control panel functionality, and then use that access to change hosting accounts, alter sites, access databases or files, plant webshells, or deploy ransomware. This is why the brief treats the CVE as a hosting control-plane compromise risk rather than a narrow website bug. 4 5 6 7 11
The “find an exposed service” step is not magic. Threat actors can discover candidate targets through internet-wide scanning, common cPanel/WHM hostnames, common management ports, HTTP and TLS fingerprints, hosting-provider patterns, passive attack-surface data, or target lists when those are present in a particular investigation. WP Squared, also referenced as WP2 in vendor materials, is a WebPros/cPanel product in the affected product family and should be scoped as hosting-control-plane exposure rather than as a WordPress core, plugin, or theme issue. 3 6 10 17
The WordPress connection needs to be stated carefully. cPanel & WHM is a widely used web-hosting control panel for managing websites, CMS platforms, databases, email, domains, files, customer accounts, and server administration. WordPress is a common workload managed through cPanel, but CVE-2026-41940 is not a WordPress vulnerability and not limited to WordPress. Successful exploitation can endanger any hosted assets managed through the same control plane. 6 11 17 18
The exploitation picture is mature enough for emergency handling. cPanel released fixes on April 28, watchTowr published root-cause analysis and PoC on April 29, 28-Jun-2026 · Newly retained (>24h) CISA's official KEV feed records an April 30 catalog addition, May 3 due date, and known ransomware-campaign-use flag, while cPanel's response references May 1 confirmation. BleepingComputer reported exploitation tied to Sorry ransomware on May 2. Shadowserver also reported at least 44,000 likely compromised IPs seen scanning honeypots. 2 5 7 8
26-Jun-2026 · Newly retained (>24h) AI Monitoring Agent run at June 26, 2026 10:02 AM ET retained three older-but-new-to-this-brief deltas: NVD's June 17 official metadata update, Censys activity-cluster telemetry for Mirai-pattern and .sorry ransomware activity, and Ctrl-Alt-Intel's named public targeting report involving CVE-2026-41940 PoC use.1 20 21
27-Jun-2026 · Newly retained (>24h) AI Monitoring Agent run at June 27, 2026 10:02 AM ET retained QiAnXin XLab's May 11 Mr_Rot13/Filemanager reporting as a source-backed activity-cluster delta. The update adds backdoor, credential-theft, webshell, and persistence hunting guidance without publishing raw attacker payload infrastructure and without converting aggregate compromise activity into a named-victim list.22
28-Jun-2026 · Newly retained (>24h) AI Monitoring Agent run at June 28, 2026 10:02 AM ET retained older defense-side deltas: Cloudflare's April 30 emergency WAF release for CVE-2026-41940 and Shadowserver's compromised-website report tags for sorry-ransomware, whmstealer, and mr-rot13 patterns. These add mitigation/reporting workflow guidance and do not create a named-victim list. Freshness: Newly retained (>24h).23 24
01-Jul-2026 · Newly retained (>24h) AI Monitoring Agent run at July 1, 2026 10:02 AM ET retained older hosting-provider disclosure evidence: Liquid Web's public status incident for CVE-2026-41940 remediation and InMotion Hosting's fleet-response report. These sources improve provider-notice, customer-scoping, and remediation-pattern guidance, while preserving the boundary that they are not a raw named end-customer victim list. Freshness: Newly retained (>24h).25 26
30-Jul-2026 · Newly retained (>24h) AI Monitoring Agent run at July 30, 2026 10:04 AM ET retained Liquid Web's later status-incident updates as older-but-useful provider-remediation evidence: the incident moved to monitoring on July 21 after all known affected systems had been addressed or were actively being addressed, then was marked resolved on July 23. Freshness: Newly retained (>24h).25
03-Jul-2026 · Newly retained (>24h) AI Monitoring Agent run at July 3, 2026 10:03 AM ET retained ThreatLocker's May 15 Sorry ransomware analysis as an older-but-useful detection and recovery delta. The update strengthens bounded ransomware hunting for host-level markers, service/process disruption, SSH propagation attempts, and recovery scoping, without adding exploit instructions, raw victim lists, or a universal compromise assumption. Freshness: Newly retained (>24h).27
08-Jul-2026 · Newly retained (>24h) AI Monitoring Agent run at July 8, 2026 10:03 AM ET retained Unfold Security's May 6 detection research as an older-but-useful detection-engineering delta. The update adds behavior-based session and access-log correlation guidance while avoiding raw exploit payloads, raw rule bodies, and brittle PoC-string-only detection framing. Freshness: Newly retained (>24h).28
13-Jul-2026 · Newly retained (>24h) AI Monitoring Agent run at July 13, 2026 10:03 AM ET retained Proofpoint's May 27 network-telemetry report as an older-but-useful activity-cluster delta. Proofpoint frames CVE-2026-41940 as multi-actor mass exploitation and reports that the vulnerability is increasingly observed in compromised-website web-inject chains such as TA569/SocGholish. Freshness: Newly retained (>24h).29
17-Jul-2026 · Newly retained (>24h) AI Monitoring Agent run at July 17, 2026 10:11 AM ET retained Bluehost's July 9 provider guidance and May 6 compromise-check guide as older-but-useful provider/customer-notice deltas. The update adds Bluehost to the named provider response pattern, strengthens VPS/Dedicated and CentOS 6 scoping, and captures provider-published compromise-review categories without republishing raw command bodies or hashes. Freshness: Newly retained (>24h).30 31
19-Jul-2026 · Newly retained (>24h) AI Monitoring Agent run at July 19, 2026 10:04 AM ET retained InMotion Hosting's May 20 direct customer follow-up and BinaryLane's May 5 provider advisory as older-but-useful provider-response deltas. The update strengthens port-blocking, patch exception, customer outreach, unmanaged-VPS, detection-script, credential/log/account review, and provider-attestation scoping without adding a new named end-customer victim list, actor, ransomware family, or exploit instructions. Freshness: Newly retained (>24h).32 33
20-Jul-2026 · Newly retained (>24h) AI Monitoring Agent run at July 20, 2026 10:02 AM ET retained CrowdSec's May 4 telemetry/detection report, Beazley Security's insurer-adjacent advisory, and KnownHost's April 28-30 provider response thread as older-but-useful deltas. The update adds bounded reconnaissance telemetry, WAF virtual-patching and detection-control evidence, insurer/MDR scoping language, and direct provider port-blocking/log-review detail without adding a named end-customer victim list or raw exploit/log examples. Freshness: Newly retained (>24h).34 35 36
22-Jul-2026 · Newly retained (>24h) AI Monitoring Agent run at July 22, 2026 10:03 AM ET retained Coalition Security Labs' May 1 insurer/security advisory as an older-but-useful policyholder coordination delta. Coalition says it notified impacted policyholders, worked with them to track hosting-provider patch progress, and helped on-premises cPanel/WHM policyholders remediate. Freshness: Newly retained (>24h).37
24-Jul-2026 · Newly retained (>24h) AI Monitoring Agent run at July 24, 2026 10:02 AM ET retained Socket's July 22 GitHub Actions abuse research as an older-but-useful activity-cluster delta. Socket reports compromised repositories and GitHub-hosted runners used to scan for and attempt CVE-2026-41940 exploitation against cPanel/WHM targets and harvest server-side credentials; this adds CI/CD and software-supply-chain scoping without treating Packagist installation as the execution path. Freshness: Newly retained (>24h).38
27-Jul-2026 · Newly retained (>24h) AI Monitoring Agent run at July 27, 2026 10:03 AM ET retained ASD's ACSC May 1 alert as older-but-useful national-CERT evidence. ACSC reported active exploitation in Australia and warned that several MSP-managed products had been impacted with customer compromise; this strengthens provider/MSP scoping and third-party assurance questions without naming public victim organizations or changing product version/fixed-build guidance. Freshness: Newly retained (>24h).39
29-Jul-2026 · Newly retained (>24h) AI Monitoring Agent run at July 29, 2026 10:02 AM ET retained Imperva's April 30 threat-research note as older-but-useful telemetry and compensating-control evidence. Imperva reported nearly 4,000 attack requests against customer environments across 15 industries and 17 countries, with US sites accounting for almost 70% of observed attacks, while still directing defenders to patch and review cPanel session/access evidence. Freshness: Newly retained (>24h).40
03-Aug-2026 · Newly retained (>24h) AI Monitoring Agent run at August 3, 2026 10:03 AM ET retained Government of Guam and Guam Bureau of Statistics and Plans public disclosure evidence, plus DysruptionHub's reconciled incident profile, as a named victim/disclosure delta. The evidence supports cPanel-hosted government website disruption, bsp.guam.gov compromise, and ongoing BSP file/content restoration; it does not confirm sensitive personal-information breach, ransomware encryption, ransom demand, leak threat, named actor attribution, or a public raw victim/customer list. Freshness: Newly retained (>24h) for the May 2 official statement and DysruptionHub profile; Newly retained (publication date not visible) for the BSP restoration notice.42 43 44
09-Aug-2026 · Newly retained; undated AI Monitoring Agent run at August 9, 2026 10:01 AM ET retained Shadowserver's embedded August 8 exploited-vulnerabilities dashboard row as a bounded current exploit-pressure update. The row shows CVE-2026-41940 at rank 14 with 151 last-day unique IPs, 190 seven-day average, 167 thirty-day average, 266 ninety-day average, 1,099 connections, KEV status, and known ransomware-campaign-use flag. Freshness: Newly retained (publication date not visible). This does not add a named victim organization, new actor, new ransomware family, intrusion set, botnet, exploit wave, public PoC-driven campaign name, or successful-compromise count.41
11-Aug-2026 · Newly retained (>24h) AI Monitoring Agent run at August 11, 2026 10:02 AM ET retained China Daily / CCTV News Client reporting attributed to the National Computer Virus Emergency Response Center and National Engineering Laboratory. The warning says multiple domestic Sorry ransomware attacks in China targeted internet-exposed Linux web servers and used the WebPros cPanel authorization-bypass vulnerability CNNVD-202604-5641 / CVE-2026-41940 for initial access before process masquerading, victim/environment profiling, service and backup disruption, data theft, AES/RSA file encryption, and weak-password SSH lateral movement. Freshness: Newly retained (>24h). This adds a China-focused activity-cluster and defensive-scoping delta, not a named victim list, new ransomware family, or universal payload path.45
13-Aug-2026 · Newly retained (>24h) AI Monitoring Agent run at August 13, 2026 10:03 AM ET retained DysruptionHub's August 10 Government of Guam/BSP status update as a named victim/disclosure revision. The update keeps the incident active, says BSP downloads and embedded content were still unavailable while the agency re-uploaded files and datasets, and preserves the boundary that no government-wide all-clear, confirmed data theft, ransomware finding, or actor attribution had been published. Freshness: Newly retained (>24h).42 43 44
18-Aug-2026 · Newly retained (>24h) AI Monitoring Agent run at August 18, 2026 10:01 AM ET retained DysruptionHub's August 16 Government of Guam/BSP recovery-status revision as an older-than-24-hour victim/disclosure update. DysruptionHub now treats the incident as presumed resolved because BSP's restoration warning was no longer visible on core BSP pages and reports/data pages were repopulated, while preserving that no government-wide all-clear, exact final restoration date, confirmed data theft, ransomware finding, or actor attribution had been published. Freshness: Newly retained (>24h).44
13-Aug-2026 · Newly retained; undated The same August 13 run retained Shadowserver's current exploited-vulnerabilities dashboard row as bounded current exploit-pressure telemetry: 98 last-day unique IPs, 134 seven-day average, 164 thirty-day average, 259 ninety-day average, and known ransomware-campaign-use flag. Freshness: Newly retained (publication date not visible). This does not add a named victim organization, new actor, new ransomware family, intrusion set, botnet, exploit wave, public PoC-driven campaign name, or successful-compromise count.41
For US SMBs, the risk is often indirect but still urgent. Many small businesses do not administer WHM themselves; they rely on a web host, MSP, reseller, or agency. 27-Jul-2026 · Newly retained (>24h) ACSC's Australia-facing alert reinforces this indirect-risk pattern by warning that several MSP-managed products were impacted and customers should confirm provider patching and monitoring. Those stakeholders should validate whether any cPanel/WHM or WP Squared environment is internet-facing, patched to a fixed build, scanned with the vendor detection script, and reviewed for post-exploitation activity including Sorry ransomware, data theft, backup/service disruption, and SSH lateral-movement evidence where relevant. 3 6 10 25 26 30 31 35 36 37 39 45
For insurers, brokers, breach counsel, and MSPs, the practical question is not only “does the policyholder run WordPress?” or “what CMS does the site use?” It is “does the policyholder, host, reseller, MSP, or web agency use cPanel/WHM or WP Squared to operate the insured web, mail, database, or customer-hosting environment?” External attack-surface checks can identify probable cPanel exposure, but they cannot prove patch status or absence of compromise; that requires provider attestation, version evidence, vendor detection-script output, retained logs, hosted-asset review, and where applicable insurer or broker tracking of provider remediation progress. 3 6 10 17 18 35 37
Decision-makers should avoid treating this as a routine patch notice. KEV status, public exploit details, ransomware reporting, and exposed-hosting blast radius make this an exposure-validation and incident-scoping problem. Patching closes the known flaw, but response should also preserve logs, inspect session artifacts, rotate affected administrative credentials where warranted, and confirm hosted-site integrity. 3 4 7
Expansion Research Add
Practical summary: CVE-2026-41940 is a critical authentication bypass in the cPanel & WHM hosting control panel. It is not a WordPress vulnerability and is not limited to WordPress. Successful exploitation can give attackers administrative access to hosted websites, databases, files, mail, and customer environments managed through the affected control plane.3 6 13 17 18
CVE-2026-41940 Exploit Watch Snapshot
KEV Status
Added
28-Jun-2026 · Newly retained (>24h) CISA KEV feed records April 30, 2026 addition, May 3 due date, and known ransomware-campaign-use flag; cPanel response references May 1 confirmation. 2 4
Telemetry
Ongoing
25-Aug-2026 · Newly retained; undated HoneyLabs' live CVE telemetry listed CVE-2026-41940 activity last seen August 25, 2026, with 5 events from 4 unique IPs in the 24-hour window and 46 events from 15 unique IPs in the seven-day window. Freshness: Newly retained (publication date not visible). Shadowserver previously reported 44K+ likely compromised IPs and an August 13 current-activity dashboard row. 7 8 41 47
5-AI Agent Delta Updates
| Field | Value |
|---|---|
| AI Agent Status | 25-Jun-2026 · Added AI Agent #3 - CVE-2026-41940 cPanel & WHM Watch Monitor is scheduled for daily review at 2:00 PM ET for six months. |
| Baseline State | Initial static product created June 23, 2026 from public sources and source reconciliation. |
| Last AI Agent Run | Run completed August 25, 2026 at 10:01 AM ET. AI Monitoring Agent retained updated HoneyLabs live CVE scanning telemetry as a source-backed delta. Brief version updated to v1.31. |
| Sources Added / Newly Used | August 25 run newly used updated HoneyLabs live CVE telemetry page/API values in source 47. Freshly reported (<24h): none. Newly retained (>24h): none. Newly retained (publication date not visible): HoneyLabs live CVE telemetry, retrieved August 25, 2026 at 10:01 AM ET, showing CVE-2026-41940 actively exploited, 5 events from 4 unique IPs in the 24-hour window, 46 events from 15 unique IPs in the seven-day window, and last_seen August 25. CISA KEV catalog release timestamp advanced to 2026-08-24T18:00:04.7056Z with no material CVE-2026-41940 row change; CVE.org API dateUpdated remained 2026-08-11T03:55:30.673Z; NVD lastModified remained 2026-06-17T10:47:13.957. |
| Named Victim / Disclosure Search Outcome | August 25 named-victim/provider-disclosure search found no additional reliable public organization or company newly tied to confirmed CVE-2026-41940 exploitation, ransomware impact, hosted-site compromise, provider notice, or customer notice beyond the retained Government of Guam/BSP row. HoneyLabs telemetry was retained as aggregate scanning telemetry only; no raw victim/customer list, exposed-instance count, provider-wide aggregate, forum anecdote, or unverifiable claim was retained. |
| Associated Campaign / Activity Search Outcome | August 25 associated-campaign/activity-cluster search retained updated HoneyLabs live CVE scanning telemetry as a bounded current exploit-pressure signal. No new actor, ransomware family, intrusion set, botnet, named campaign, exploit wave, provider advisory pattern, successful-compromise count, data-theft finding, ransomware confirmation, or actor attribution was identified. Existing Sorry ransomware, Mr_Rot13/Filemanager, Shadowserver telemetry/tag, Proofpoint web-inject, Socket GitHub Actions abuse, China warning, HoneyLabs early-reconnaissance, malicious-PoC source-deconfliction, and provider-remediation clusters otherwise remain unchanged. |
| Previous AI Agent Delta | August 25, 2026 run retained updated HoneyLabs live CVE telemetry as bounded current scanning evidence. August 24 run retained updated HoneyLabs live CVE telemetry and VulnCheck malicious-PoC source-deconfliction research. August 23, August 22, and August 21 runs retained earlier HoneyLabs live CVE telemetry deltas. August 20 and August 19 runs found no source-backed content delta. August 18 run retained DysruptionHub's Government of Guam/BSP presumed-resolved revision. 41 42 43 44 45 46 47 48 |
| Checked But Not Retained | August 25 run checked CISA KEV/feed status, NVD detail/API, CVE.org/CVE API, VulnCheck advisory and public-PoC research, cPanel advisory/response pages, cPanel/WP Squared release-note references, WP Squared references, Rapid7, watchTowr, BleepingComputer, Shadowserver compromised-website report/dashboard/search results, HoneyLabs CVE telemetry/API, Censys, Ctrl-Alt-Intel, QiAnXin XLab, Cloudflare, ThreatLocker, Unfold Security, Proofpoint, CrowdSec, Beazley Security, Coalition Security Labs, Chubb cyber alert, ASD ACSC, Cyber Security Agency of Singapore, Canadian Centre for Cyber Security, CERT-In, Socket/Corgea Packagist/GitHub Actions coverage, The Hacker News, Help Net Security, BankInfoSecurity, TechCrunch, TechRadar, The Register, SecurityWeek, Cybersecurity Dive, Cato Networks, Dataminr, Center for Internet Security, Qualys, Picus, CyCognito, CybelAngel, SecPod, Imperva, Liquid Web, KnownHost, Namecheap, Bluehost, InMotion, BinaryLane, NFOrce, SimplicityHosting, Bitsight, Trend Micro, Arctic Wolf, eSentire, Malwarebytes, Broadcom, Barracuda, Pentest-Tools scanner page, China Daily/CCTV/CVERC warning coverage, Government of Guam, Guam BSP, DysruptionHub incident profile/registry, Island Times/Pacific Island Times, SecurityAffairs, ColorTokens, Skynet Hosting, webhosting.today, Senserva ranking page, Cato rapid CVE mitigation page, Preciseley support-index noise, hosting-provider advisories, customer-notice searches, victim/disclosure searches, Reddit/forum/social reposts, LinkedIn/X/Instagram/social reposts, GitHub exploit-code and scanner repositories, exploit-index pages, scanner pages, and SEO/security-news rewrites for novelty. CISA KEV, NVD, CVE.org, and cPanel records had no material CVE-2026-41940 official-status, affected-version, detection, mitigation, victimology, or activity-cluster change. Duplicate media recaps, social reposts, exploit-code indexes, scanner pages, social anecdotes, rankings, and secondary/SEO rewrites were not retained. |
| Next Scheduled Run | Daily at 2:00 PM ET through December 25, 2026. |
| Email Report | No external email, Gmail, SMTP, Postmark, subscriber-delivery, retry workflow, or notification workflow sent for the August 25 run under the current non-negotiable no-email policy; run status is retained in Codex output and automation memory only. |
| Delta Rules | Always append the Change Log; distinguish Freshly reported (<24h) from Newly retained (>24h) sources; use dated pills and color coding for changed content; update PANDA index date; deploy after successful verification when the deployment path is available; do not send external email under the current no-email policy. |
| Future Delta Candidates | CISA KEV due-date changes, vendor advisory updates, new exploitation telemetry, ransomware linkage updates, associated campaigns or activity clusters, WP Squared/cPanel product guidance, named victim organizations, or new detection guidance. |
6-Why It Matters
cPanel & WHM is not just another web application on a host. In many environments, it is the management layer for websites, databases, email, DNS-adjacent workflows, reseller access, and server administration. An authentication bypass against that control plane can become a customer-impacting event quickly, especially for hosting providers, MSPs, agencies, and SMBs that share infrastructure or depend on a third party for web operations. 6 11 12
That distinction matters for scoping. A website owner may not have a flaw in WordPress, Joomla, Drupal, Magento, custom code, or another hosted application to patch, but still needs assurance from the hosting provider, MSP, reseller, or web agency that the cPanel/WHM control plane was patched and checked for exploitation. This is a hosting-control-plane risk with downstream website and hosted-service consequences.3 17 18
26-Jun-2026 · Newly retained (>24h) Newly retained telemetry adds that Censys observed a May 1 malicious-host surge overwhelmingly concentrated on cPanel/WHM, plus distinct Mirai-pattern and .sorry ransomware activity signals. This improves activity scoping but does not create a public named-victim list.20
01-Jul-2026 · Newly retained (>24h) Newly retained hosting-provider notices show why customers need provider-specific evidence instead of only generic CVE status: Liquid Web publicly described CVE-2026-41940-related remediation, support-volume impact, and restoration where compromise was evident, while InMotion reported network-edge blocking, fleet patching, and direct work with a small subset of customer environments. Freshness: Newly retained (>24h).25 26
30-Jul-2026 · Newly retained (>24h) Liquid Web's later status updates add provider-remediation closure context: normal support operations had resumed by the July 21 monitoring update, and the incident was marked resolved on July 23. Freshness: Newly retained (>24h).25
17-Jul-2026 · Newly retained (>24h) Bluehost adds another named provider-response example for VPS and Dedicated customers: temporary cPanel/WHM/Webmail/WebDisk port restrictions on affected servers, CentOS 6 migration guidance, backup and log-review advice, and compromise-review categories for ransomware markers, persistence, SSH keys, cPanel template tampering, shell history, credential rotation, and hosted-account review. Freshness: Newly retained (>24h).30 31
19-Jul-2026 · Newly retained (>24h) InMotion's direct follow-up and BinaryLane's advisory add provider-response detail that customers can request from hosts: port-blocking windows, patch exception handling, direct customer outreach, unmanaged VPS responsibilities, credential rotation, log/account review, and detection-script execution. Freshness: Newly retained (>24h).32 33
Business Risk
Hosting Control
Unauthorized WHM access can cascade into hosted sites, mail, databases, and customer data.
Response Risk
Patch + Scope
Updating closes the known flaw, but responders still need to inspect sessions, logs, and hosted content.
Client Risk
Indirect Exposure
SMBs may not know they use cPanel; their exposure may sit with a host, reseller, MSP, or agency.
Expansion Research Add
For client communications, do not call this a WordPress bug. Say: “This is a cPanel/WHM hosting control panel vulnerability that can put websites, databases, mail, files, and hosted customer environments at risk when they are managed through vulnerable hosting infrastructure. WordPress is one common downstream example, not the vulnerable product.”
7-Vulnerability Details
| Attribute | Assessment | Source Basis |
|---|---|---|
| CVE | CVE-2026-41940 | NVD and CVE.org provide the stable CVE identity. 1 14 |
| Affected products | cPanel & WHM, including DNSOnly per cPanel advisory; WP Squared also affected before fixed build. | Vendor and advisory sources identify the affected product family. 3 4 6 |
| Hosted workload relationship | Not a WordPress core, plugin, or theme vulnerability and not limited to WordPress; any websites, CMS platforms, databases, mail, files, or customer accounts managed by vulnerable cPanel/WHM infrastructure may be downstream affected. | cPanel product and WordPress-management documentation support the hosting-control-plane distinction. 3 17 18 |
| Vulnerability class | Authentication bypass in session-management / login flow, associated with CRLF injection and unsanitized session-file handling. | Vendor and practitioner analyses describe the session-management exploit path. 4 5 6 10 |
| Privileges required | None. Public sources frame this as unauthenticated remote access to administrative control paths. | NVD, Rapid7, and VulnCheck support the no-credential framing. 1 6 13 |
| Potential impact | Administrative control of cPanel host system, configurations, databases, websites, mail, files, customer accounts, and hosted services. | Practitioner sources support the hosting-control-plane impact assessment. 6 11 |
8-Affected Products & Fixed Versions
| Product | Affected | Fixed / Required Build |
|---|---|---|
| cPanel & WHM | All versions after 11.40 before fixed branch builds | 26-Jun-2026 · Newly retained (>24h) NVD's June 17 affected-record update corroborates the branch-specific fixed-build ranges. 11.86.0.41, 11.94.0.28, 11.102.0.39, 11.110.0.97, 11.118.0.63, 11.124.0.35, 11.126.0.54, 11.130.0.19, 11.132.0.29, 11.134.0.20, 11.136.0.5 and later 1 3 13 |
| WP Squared | WP Squared builds before fixed release | 136.1.7 and later 3 6 |
| CentOS 6 / CloudLinux 6 cPanel v110.0.50 path | Legacy environments called out by vendor | Vendor described v110.0.103 direct update path and tier-setting instructions 3 |
9-KEV, Exploitation & Public PoC Status
| Item | Status | What It Means |
|---|---|---|
| CISA KEV | Known Exploited | Treat as an urgent, externally validated exploitation risk rather than a theoretical vulnerability. 2 4 |
| Public PoC | Available | Technical exploitation became easier to reproduce after watchTowr publication. 5 6 |
| Ransomware reporting | Reported | BleepingComputer reports Sorry ransomware deployment after exploitation; scope for encryption and backup impact. 7 |
| Compromise telemetry | Large-scale signal | 26-Jun-2026 · Newly retained (>24h) Shadowserver and Censys reporting support broad exploitation, scanning, and post-compromise activity signals, not a victim list. 8 20 |
10-Technical Breakdown
Before exploitation, the attacker still has to find candidate cPanel/WHM or WP Squared endpoints. That is usually not luck. Publicly reachable hosting-control panels can be located through internet-wide scanning, common hostnames such as cpanel, whm, and webmail, common cPanel ports such as 2082/2083, 2086/2087, and 2095/2096, HTTP titles, TLS certificates, provider fingerprints, passive attack-surface datasets, and known hosting-provider or reseller patterns. Underground or shared target lists can also exist in real incidents, but this brief treats internet exposure discovery and attack-surface enumeration as the source-supported baseline unless a source proves a specific list-driven campaign. 3 6 10 17
At a defensive level, the public technical record points to a pre-authentication path in which attacker controlled input can influence cPanel session-file state. cPanel describes two code paths writing session files, one of which lacked sanitization during Basic authentication handling. Rapid7 and watchTowr describe the exploitability around CRLF injection, malformed session material, and the ability to insert privileged session properties before authentication is complete. 4 5 6
The attacker does not need to start with a WordPress login, another CMS login, a stolen cPanel password, or an installed website plugin. The exploit target is the exposed cPanel/WHM service itself. If successful, the attacker can arrive inside a trusted administration layer and then use normal control-panel functions to create or modify accounts, reach hosted files, inspect databases, change site content, add SSH keys, access mail-adjacent assets, or prepare follow-on ransomware. That means investigation should include the cPanel host, hosted websites, customer accounts, databases, mail, SSH keys, backups, and reseller or privileged account activity. 3 6 7 11
Expansion Research Add
In WordPress-heavy hosting environments, this means the attacker is not exploiting WordPress directly. More broadly, they are potentially bypassing authentication on the control panel that manages hosted website files, CMS installs, databases, domains, backups, email, customer accounts, and administrative workflows.
11-MITRE ATT&CK / Attack Flow
| Step | MITRE / Attack Phase | Likely Attacker Activity | Defensive Focus |
|---|---|---|---|
| 0 | Target acquisition / exposed-control discovery | Locate probable cPanel/WHM or WP Squared endpoints through internet-wide scanning, common cPanel hostnames, common management ports, HTTP/TLS fingerprints, passive attack-surface data, hosting-provider patterns, or shared target lists where locally evidenced. | Know whether the organization or provider exposes cPanel/WHM, restrict admin portals, monitor for scanning, and use attack-surface management to find shadow or third-party hosting dependencies. |
| 1 | Reconnaissance / version and service confirmation | Confirm internet-facing cPanel/WHM, DNSOnly, or WP Squared services and estimate version, patch state, or exploitability from reachable service behavior and fingerprints. | Maintain asset inventory, restrict cPanel/WHM access, and validate exposed versions before incidents. |
| 2 | T1190 - Exploit Public-Facing Application | Send a crafted unauthenticated request that abuses session-management behavior, CRLF/session-file handling, or login-flow weakness to obtain authenticated control-panel state. | Patch to fixed build, restart cpsrvd, run vendor detection script, and preserve session files and access logs. |
| 3 | Privileged control-panel access | Use WHM/cPanel administrative functions after bypassing authentication, rather than exploiting WordPress directly. | Review administrative actions, reseller accounts, new users, password changes, SSH keys, package changes, and privilege changes. |
| 4 | Collection / hosted asset access | Access hosted files, databases, website directories, backups, mail-adjacent assets, and customer or reseller environments managed by the control panel. | Scope hosted websites, databases, backups, webshells, malicious uploads, data access, and integrity of customer-facing sites. |
| 5 | T1486 - Data Encrypted for Impact | Deploy malware, alter hosted sites, steal data, or encrypt files as reported in Sorry ransomware cases. | Check ransomware notes, .sorry extensions, backup integrity, restoration paths, and whether compromise stayed at control-panel access or became business impact. |
Expansion Research Add
The key scoping distinction: the flaw can place an attacker above the websites and hosted services at the hosting-control layer. If a policyholder only checks WordPress plugins, website code, or CMS updates, they can miss the actual compromised plane of control.
12-TTPs
| Tactic | MITRE ATT&CK / Mapping | Source-Backed Detail | Caveat | Source Basis |
|---|---|---|---|---|
| Initial Access | T1190 - Exploit Public-Facing Application | Exploit exposed cPanel/WHM web service without valid credentials. | Map only where the affected service is internet-facing. | Exploit analysis and ATT&CK mapping support this behavior. 5 6 15 |
| Privilege / Control | Session-state abuse / control-panel administration | Injected session state can be treated as authenticated administrative access, after which the attacker may use normal cPanel/WHM functions. | Do not describe this as password theft unless logs prove credential access; the vulnerability is an authentication bypass. | Vendor and technical sources describe the session-state bypass path. 3 4 5 6 |
| Persistence | T1078 - Valid Accounts | If an attacker creates or changes WHM/cPanel, reseller, SSH, database, or hosted-site accounts after bypassing authentication, those accounts become post-exploitation persistence or re-entry paths. | Only map when local logs show account creation, password changes, SSH key additions, or similar administrative actions. | The control-plane impact described by Rapid7, Qualys, and cPanel makes account review a necessary local hunt. 3 6 11 |
| Persistence / Credential Access | Webshell, SSH-key, login-page tampering, and remote-control backdoor activity | 27-Jun-2026 · Newly retained (>24h) QiAnXin XLab reported Mr_Rot13 post-exploitation activity that implants access paths, modifies cPanel-facing assets, steals credentials, and deploys Filemanager remote-control tooling. | Map only when local artifacts support this activity; do not publish raw attacker infrastructure in broad stakeholder guidance. | Retained as source-backed activity-cluster evidence. 22 |
| Impact | T1486 - Data Encrypted for Impact | 03-Jul-2026 · Newly retained (>24h) Sorry ransomware reporting describes Linux-host encryption following exploitation, with newly retained ThreatLocker analysis adding host-level marker, process/service interruption, and SSH-propagation hunt detail. | Ransomware linkage is reported; not every exploitation case becomes ransomware or the same payload path. | Ransomware impact is reported as a real-world outcome, not a universal result. 7 16 27 |
| Resource Development / Execution / Collection | Compromised CI/CD workflows and GitHub-hosted runner abuse | 24-Jul-2026 · Newly retained (>24h) Socket reported malicious GitHub Actions workflows in compromised repositories launching runners to download payloads, scan for CVE-2026-41940-exposed cPanel/WHM systems, and collect credentials and secrets from successfully reached servers. | Map as a source-backed activity cluster and CI/CD abuse pattern; do not assume every affected Packagist user executed the workflow or that every matching repository is a confirmed victim. | Retained as newly incorporated Socket activity-cluster evidence. 38 |
13-IOCs / Observables
This brief does not publish a stable universal IP/domain/hash blocklist for CVE-2026-41940. Forensicators should prove compromise through a local evidence chain: vendor detection-script results, session-file artifacts, cPanel/WHM access logs, privileged administrative actions, hosted-asset changes, and ransomware or malware traces where present. 3 4 7
| Forensic Evidence | What It Can Prove | What To Collect / Preserve | Evidence Boundary |
|---|---|---|---|
| Public IOC status | No retained source publishes a reliable universal CVE-2026-41940 IP, domain, hash, JA3, user-agent, or exploit-client blocklist suitable for proving compromise by itself. | Use public exploitation status and telemetry for urgency; use local artifacts to prove or refute compromise. 2 3 4 7 8 | A host can be vulnerable or exposed without being proven compromised. |
| Vendor detection-script output | Positive or suspicious findings from the cPanel-provided detection script against relevant session files and log context. | Run the vendor script before session-file cleanup and preserve the script, version, runtime, output, and reviewed files. 3 4 | Treat script output as high-value local evidence; correlate with logs and administrative actions before final impact conclusions. |
| Session-file + access-log correlation | Suspicious session artifacts that line up with cPanel/WHM access-log activity, successful administrative responses, unusual source IPs, or abnormal request timing. | Preserve session directories, cPanel access logs, cpsrvd/error logs where available, web server logs, timestamps, source IPs, account names, and request/response context. 3 5 6 9 | A suspicious session file alone may show exploit attempt or artifact creation; correlated successful admin activity is stronger compromise evidence. |
| Control-panel administration after suspicious access | New or modified WHM/cPanel/reseller accounts, password resets, SSH key additions, package changes, domain changes, backup changes, mail/database access, or other privileged actions after the suspected exploit window. | Export WHM/cPanel account history, privileged user changes, SSH authorized keys, package/domain changes, database/mail access evidence, and backup activity. 6 11 | These artifacts prove post-access behavior; they may not by themselves prove CVE-2026-41940 unless tied to the exploit-window and session/access evidence. |
| Backdoor and persistence evidence 27-Jun-2026 · Newly retained (>24h) | Mr_Rot13/Filemanager-style artifacts can show post-exploitation persistence, credential theft, and remote-control activity after a cPanel compromise path. | Preserve SSH authorized-key changes, webshell evidence, modified login-page assets, suspicious credential-access scripts, remote-control service evidence, process listings, and clean-room malware triage notes. 22 | Use these as compromise and persistence indicators, not as universal proof that every exposed cPanel host was hit by Mr_Rot13. |
| Hosted-asset impact evidence | Webshells, unauthorized file changes, modified hosted sites, database dumps, suspicious uploads, new cron jobs, malware, encrypted files, ransom notes, or .sorry extensions. | 03-Jul-2026 · Newly retained (>24h) Preserve webroot diffs, file-integrity output, malware scan results, database access logs, backup status, ransom notes, encryption indicators, host-level marker files, service/process interruption evidence, SSH-propagation traces, and restoration evidence. 6 7 11 16 27 | Hosted-site compromise or ransomware impact can prove an incident occurred, but responders still need to determine whether CVE-2026-41940 was the entry path. |
Observable Hunt Leads
| Artifact | What To Look For | Why It Matters | Response Use |
|---|---|---|---|
| /var/cpanel/sessions | Suspicious session files, injected session attributes, anomalous auth markers, badpass-origin artifacts. | Vendor detection script centers on filesystem session indicators. 3 4 | Preserve before cleanup. |
| /usr/local/cpanel/logs/access_log | Requests tied to suspicious tokens, Basic auth abuse, anomalous WHM/cPanel access, follow-on 200 responses. | Access-log context helps determine whether suspicious session material was used. 3 | Correlate with session files. |
| Historical WHM login-path probes 15-Aug-2026 · Newly retained (>24h) | Focused pre-advisory probes against WHM login paths in April 2026, especially narrow-source activity that did not resemble broad commodity scanning. | HoneyLabs reported one focused pre-advisory cPanel/WHM probing case and emphasized that the traffic was not exploit-shaped. 46 | Freshness: Newly retained (>24h); use for retrospective triage only, not as proof of compromise. |
| Session and access-log correlation 08-Jul-2026 · Newly retained (>24h) | Authenticated cpsess activity without the expected preceding successful login path; suspicious session promotion or token use that lines up with access-log activity. | Unfold recommends behavior-based detection for exploit mechanics rather than brittle matching on public PoC strings. 28 | Freshness: Newly retained (>24h); adapt to local log retention and SIEM schemas. |
| WHM/cPanel accounts | New admin/reseller accounts, password changes, SSH key additions, unexpected package or domain changes. | Successful exploitation can grant administrative access to hosting control planes. 6 11 | Scope control-plane impact. |
| Hosted websites | Webshells, unauthorized file changes, malware uploads, mass defacement, encrypted files. | Compromised WHM access can cascade into hosted websites and customer data. 6 7 11 | Inspect hosted assets. |
| Backdoor / credential-theft traces 27-Jun-2026 · Newly retained (>24h) | Unexpected SSH keys, PHP webshells, cPanel login-page tampering, credential collection, and Filemanager-style remote-control tooling after suspected CVE-2026-41940 access. | QiAnXin XLab tied this post-exploitation pattern to Mr_Rot13 activity abusing CVE-2026-41940. 22 | Use as hunt leads; keep raw attacker infrastructure out of public guidance. |
| Ransomware traces 03-Jul-2026 · Newly retained (>24h) | .sorry file extension, ransom notes, backup deletion, Linux encryptor execution paths, host-level marker files, service/process disruption, and SSH propagation attempts. | BleepingComputer, Shadowserver, and ThreatLocker reporting tie CVE-2026-41940 compromise workflows to Sorry ransomware reporting/tags and bounded host-level hunting detail. 7 16 24 27 | Freshness: Newly retained (>24h); check reported impact path without treating it as universal exploitation behavior. |
| Shadowserver compromised-website report tags 28-Jun-2026 · Newly retained (>24h) | Check whether your network, ASN, or hosted domains appear in Shadowserver notifications tagged sorry-ransomware, whmstealer, or mr-rot13 for cPanel/Roundcube compromise patterns. | Shadowserver describes CVE-2026-41940-related report tagging for likely compromised cPanel/Roundcube assets. 24 | Freshness: Newly retained (>24h); use as notification workflow, not public victim evidence. |
| Provider compromise-review checklist 17-Jul-2026 · Newly retained (>24h) | Validate patched build, then review for ransomware-marker files, persistence or shell-startup anomalies, root SSH-key changes, cPanel template tampering, suspicious shell history, hosted-account changes, and evidence-preservation needs. | Bluehost published customer-facing CVE-2026-41940 compromise-review guidance for VPS/Dedicated environments. 31 | Freshness: Newly retained (>24h); use categories as hunt leads without republishing raw command bodies or hashes. |
| Provider response and exception records 20-Jul-2026 · Newly retained (>24h) | Port-blocking windows, patch exception lists, direct customer outreach, unmanaged-VPS responsibility statements, credential rotation guidance, log/account review prompts, detection-script execution records, and provider log-review outcomes. | InMotion, BinaryLane, Beazley Security, and KnownHost publish provider-side response, customer-action, or insurer-evidence details useful for scoping indirect hosting-control-plane exposure. 32 33 35 36 | Freshness: Newly retained (>24h); provider notices are not end-customer victim lists. |
| CrowdSec telemetry and virtual patching 20-Jul-2026 · Newly retained (>24h) | CrowdSec observed 282 distinct IPs tied to CVE-2026-41940 between April 27 and May 4 and published detection/WAF virtual-patching coverage for exposed setups. | Use as bounded reconnaissance/detection telemetry and compensating-control evidence. 34 | Freshness: Newly retained (>24h); telemetry and control status do not prove a named victim or clean state. |
| GitHub Actions abuse and server-side secret harvesting 24-Jul-2026 · Newly retained (>24h) | Compromised repository workflows launching GitHub-hosted runners, Linux scanner/payload execution, CVE-2026-41940 targeting of cPanel/WHM services, and collection of server-side credentials, tokens, environment files, database access, SSH material, and cloud/payment/email secrets. | Socket tied this CI/CD abuse campaign to CVE-2026-41940 exploitation attempts and credential harvesting against cPanel/WHM targets. 38 | Freshness: Newly retained (>24h); do not republish raw payload infrastructure or treat affected Packagist installation as automatic execution. |
14-Detection & Hunting
The vendor detection script is the highest-priority local check because it is tailored to session-file indicators for this vulnerability. Run it before deleting session artifacts, and preserve output for IR review. The script looks at session files and access-log context, and cPanel has refined it across multiple advisory updates to reduce false positives. 3 4 08-Jul-2026 · Newly retained (>24h) Unfold Security adds a detection-engineering layer: hunt for exploit-invariant behavior such as suspicious session promotion and authenticated cpsess activity without the normal preceding login path, instead of depending only on static PoC-string matches. Freshness: Newly retained (>24h).28 20-Jul-2026 · Newly retained (>24h) CrowdSec and KnownHost add older-but-newly-retained operational context: dedicated detection/WAF virtual-patching coverage, reconnaissance telemetry, and provider log-review outcomes should complement, not replace, vendor script output and local access/session correlation. Freshness: Newly retained (>24h).34 36
| Hunt | Detail | Owner |
|---|---|---|
| Version validation | Confirm fixed build on every cPanel, WHM, DNSOnly, and WP Squared deployment. | Vulnerability management / hosting admin |
| Session-file triage | Run the vendor script against cPanel session directories and inspect suspicious sessions. | Linux admin / IR |
| Access-log correlation | Review suspicious session tokens, anomalous Basic auth paths, successful administrative access, and cpsess activity that lacks a prior legitimate login event. | SOC / DFIR |
| Behavior-based exploit detection 08-Jul-2026 · Newly retained (>24h) | Build detections around session-file invariants and access-log sequence anomalies that should hold across exploit variants. Freshness: Newly retained (>24h). 28 | Detection engineering / SIEM |
| CrowdSec detection and virtual patching 20-Jul-2026 · Newly retained (>24h) | Where deployed, confirm CrowdSec detection-rule and WAF virtual-patching status, then correlate any hits with cPanel session/access logs, patch timing, and provider evidence. Freshness: Newly retained (>24h). 34 | SOC / platform engineering |
| Provider compromise-review checklist 17-Jul-2026 · Newly retained (>24h) | Use Bluehost's customer guidance as provider-scoped categories for review: ransomware markers, persistence changes, SSH keys, cPanel template tampering, shell history, hosted-account review, evidence preservation, and credential rotation. Freshness: Newly retained (>24h). 31 | Hosting provider / IR / Linux admin |
| Provider log-review attestation 20-Jul-2026 · Newly retained (>24h) | Ask hosts whether they reviewed cPanel access and session logs, how many systems showed access-attempt evidence, whether customers were contacted directly, and whether active-compromise signs were ruled in or out. Freshness: Newly retained (>24h). 35 36 | Provider management / breach counsel |
| Hosted impact | Check hosted sites, files, databases, mail, and backups for unauthorized change or encryption. | IR / web operations |
15-Incident Response Playbook Ideas
| # | Action | Likely Owner | Evidence |
|---|---|---|---|
| 1 | Update cPanel & WHM / WP Squared to a fixed build immediately and restart cpsrvd. 3 4 6 | Server admin / hosting provider | Stops the known authentication-bypass path. |
| 2 | Inventory internet-facing WHM/cPanel endpoints, reseller environments, DNSOnly hosts, and WP Squared deployments. 3 6 10 | IT / MSP / ASM | Finds direct and indirect hosting-control exposure. |
| 2A | 15-Aug-2026 · Newly retained (>24h) If logs still exist, review April 2026 WHM login-path probes and focused pre-advisory reconnaissance separately from confirmed exploit-session evidence. 46 | SOC / detection engineering / hosting provider | Freshness: Newly retained (>24h); adds historical reconnaissance scoping without treating probes as confirmed exploitation. |
| 3 | Run the vendor detection script against session files and preserve findings before cleanup. 3 4 | IR / Linux admin | Preserves vulnerability-specific evidence. |
| 4 | 08-Jul-2026 · Newly retained (>24h) Add behavior-based detections that correlate suspicious cPanel session-file markers with access-log usage and authenticated cpsess activity that lacks a preceding legitimate login path. 28 | SOC / detection engineering | Freshness: Newly retained (>24h); improves detection resilience without relying only on public PoC strings. |
| 5 | Review cPanel access logs, session directories, root/admin activity, account creation, SSH key additions, webshell indicators, hosted-site changes, database access, and backup deletion. 3 6 7 9 11 28 | IR / DFIR | Scopes whether control-panel access became hosted-site, data, or ransomware impact. |
| 6 | 11-Aug-2026 · Newly retained (>24h) Look for Sorry ransomware impact, .sorry file extensions, ransom notes, host-level marker files, sshd process masquerading, service/process disruption, data-theft staging, SSH propagation attempts, weak-password lateral movement, and web-host encryption impact. 7 16 24 27 45 | IR / recovery | Freshness: Newly retained (>24h); checks reported exploitation outcomes and newly retained malware-analysis/national-warning detail. |
| 7 | 27-Jun-2026 · Newly retained (>24h) For compromised hosts, hunt for Mr_Rot13/Filemanager-style post-exploitation signs: unexpected SSH keys, webshells, modified cPanel login assets, credential collection, and remote-control backdoors. 22 | DFIR / Linux admin | Checks a newly retained activity-cluster outcome without publishing raw payload infrastructure. |
| 8 | If patching cannot happen immediately, restrict cPanel service exposure and apply vendor-supported mitigations; then rotate privileged hosting credentials if compromise is suspected. 3 6 7 | Network / platform team | Reduces reachable attack surface while containment and impact review continue. |
| 9 | 28-Jun-2026 · Newly retained (>24h) Where Cloudflare WAF is in path, confirm the April 30 emergency managed rule is active and review block/log events, while still patching cPanel & WHM / WP Squared. 23 | Network / appsec / hosting provider | Freshness: Newly retained (>24h); adds compensating-control evidence and telemetry triage. |
| 10 | 17-Jul-2026 · Newly retained (>24h) For Bluehost-like VPS/Dedicated scenarios, combine fixed-build validation with compromise review for ransomware markers, persistence changes, SSH keys, cPanel template tampering, shell history, evidence preservation, credential rotation, and hosted-account impact. 30 31 | Hosting provider / IR / Linux admin | Freshness: Newly retained (>24h); adds provider-scoped customer guidance without republishing raw command bodies or hashes. |
| 11 | 27-Jul-2026 · Newly retained (>24h) Ask providers whether exposed ports were blocked, which systems could not receive patches, whether any customers received direct compromise outreach, whether logs were reviewed for access attempts, whether post-patch customer actions included credential rotation, log/account review, and detection-script execution, and whether any third-party-managed environments match ACSC's MSP/customer-compromise warning. 32 33 35 36 39 | Provider management / MSP / breach counsel | Freshness: Newly retained (>24h); strengthens provider-notice, unmanaged-VPS, insurer-evidence, national-CERT/MSP, and log-review scoping. |
| 12 | 20-Jul-2026 · Newly retained (>24h) Where CrowdSec coverage is deployed, review CVE-2026-41940 detection-rule and WAF virtual-patching status alongside vendor patch evidence and local cPanel session/access-log review. 34 | SOC / platform engineering | Freshness: Newly retained (>24h); adds third-party detection and virtual-patching evidence without treating controls as proof of clean state. |
| 13 | 24-Jul-2026 · Newly retained (>24h) For organizations with GitHub/Packagist exposure, review repository workflow changes, Actions logs, unusual runner activity, outbound payload downloads, secrets exfiltration, and affected development-version lockfile references while separately validating cPanel patch and compromise evidence. 38 | AppSec / DevSecOps / SOC | Freshness: Newly retained (>24h); adds CI/CD abuse and credential-harvesting scoping without treating package installation as the execution path. |
16-Decision Ready Actions
| Decision Owner | Decision / Action | Timeframe |
|---|---|---|
| Executives / business owners | Ask whether any hosted websites, customer portals, or business mail depend on cPanel/WHM and whether the host can attest to fixed builds and exploit checks. | Immediate |
| IT / MSP | Patch, restart cpsrvd, run vendor detection tooling, and inventory all exposed cPanel/WHM endpoints. | Immediate |
| SOC / IR | Preserve logs and session artifacts before cleanup; scope for admin abuse, website compromise, and Sorry ransomware traces. | 0-24 hours |
| Claims / breach counsel | Treat unpatched vulnerable hosting control planes as potential unauthorized-access events requiring evidence preservation and impact scoping. | 0-72 hours |
| Client-facing advisors | Prepare plain-language guidance for SMBs that may use hosted cPanel indirectly through a provider or agency. | Same day |
17-US SMB / Insurance Policyholder Scoping Lens
Many SMBs are not direct cPanel administrators. They may use cPanel indirectly through shared hosting, managed website providers, WordPress hosts, resellers, digital agencies, web developers, or MSP-managed hosting. Scoping should therefore ask both the organization and its providers whether affected cPanel/WHM or WP Squared infrastructure existed, whether it was patched to a fixed build, whether the vendor script was run, and whether hosted assets showed unauthorized access or encryption. The right question is not “was WordPress vulnerable?” or “was the site code vulnerable?” but “was the hosting control panel that manages the web environment vulnerable or compromised?” 3 6 7 17 18
| Question For Policyholder / Provider | Why It Matters | Evidence To Request |
|---|---|---|
| Who operates the cPanel/WHM or WP Squared environment: policyholder, hosting provider, MSP, reseller, web agency, or developer? | Determines who owns patching, logs, detection-script execution, and hosted-asset review. | Hosting agreement, provider name, control-panel URL, admin owner, MSP/web agency contact. |
| Was any cPanel/WHM, DNSOnly, or WP Squared instance exposed during the February-May 2026 risk window, and what exact version/build was running? | Determines whether the environment fell into the affected version range and whether historical exploitation needs to be scoped. | Version output, update logs, patch timestamp, cpsrvd restart evidence, fixed-build attestation. |
| Was the cPanel vendor detection script run before session files were deleted or rotated? | The vendor script is the most specific public check for this CVE’s session-file evidence. | Script output, retained session files, access-log excerpts, provider incident ticket. |
| Did the host, MSP, or reseller issue a CVE-2026-41940 customer notice, restrict ports, restore affected servers, keep unpatched exceptions blocked, review logs for access attempts, contact customers whose environments required direct remediation, or later mark the incident monitored/resolved? 30-Jul-2026 · Newly retained (>24h) | Provider notices from Liquid Web, InMotion, Bluehost, BinaryLane, and KnownHost show that customer impact can sit in provider remediation queues even when the policyholder did not operate WHM directly; Liquid Web adds later monitored/resolved provider-status evidence, and Beazley adds insurer-adjacent perimeter and MDR scoping language. Freshness: Newly retained (>24h). | Provider incident notice, ticket history, restore status, fixed-build evidence, exception list, customer outreach, outage notice, monitored/resolved status, OS-migration guidance, unmanaged-VPS responsibility statement, log-review attestation, and compromise-review notes. 25 26 30 31 32 33 35 36 |
| For insured environments, did the carrier, broker, or risk platform identify cPanel/WHM exposure and track remediation with the hosting provider? 22-Jul-2026 · Newly retained (>24h) | Coalition says it notified impacted policyholders on April 29, worked with policyholders to track hosting-provider patch progress, helped on-premises cPanel/WHM policyholders remediate, and advised businesses relying on hosting providers to confirm patching directly. Freshness: Newly retained (>24h). | Carrier/broker notice, Coalition Control or equivalent alert record, provider patch-progress tracking, on-premises remediation notes, and fixed-build attestation. 37 |
| Were cPanel access logs, session directories, privileged account changes, SSH keys, and hosted-site changes reviewed? | Confirms whether exposure remained theoretical or became unauthorized administration. | Access-log review, new account list, SSH key inventory, file-integrity results, database access review. |
| Were hosted websites, backups, mail-adjacent assets, databases, or customer-facing portals modified, encrypted, or exfiltrated? | Separates vulnerable-but-clean from suspected compromise, ransomware, or data-access impact. | Webroot diff, backup status, ransomware indicators, database audit, webshell scan, restoration notes. |
| Remote Check | What It Can Show | Boundary |
|---|---|---|
| DNS and hostnames | Probable cPanel/WHM use from names such as cpanel.example.com, whm.example.com, or webmail.example.com. | Shows likely control-panel exposure or provider pattern; does not prove vulnerability or compromise. |
| Common cPanel ports | Externally reachable services on 2082/2083, 2086/2087, 2095/2096, or related management endpoints. | Requires authorization and rate-limited, non-invasive checking; cannot prove fixed build without authenticated or provider evidence. |
| Passive attack-surface intelligence | Search-engine, certificate, HTTP-title, banner, ASN, nameserver, or hosting-provider fingerprints that suggest cPanel/WHM presence. | Useful for triage and outreach, but patch and compromise status must be validated by the operator. 6 10 |
| Provider / insurer attestation 22-Jul-2026 · Newly retained (>24h) | Whether the host patched all affected instances, ran the detection script, reviewed logs, applied exposure-management checks, identified or ruled out access attempts or active compromise, and whether carrier/broker workflows tracked provider remediation for impacted policyholders. Freshness: Newly retained (>24h). 35 36 37 | Ask for evidence, not a generic secure-state statement. |
Expansion Research Add
Insurance-facing language: remote checks can identify probable cPanel usage and exposed management surfaces, but they should trigger evidence requests rather than become proof of compromise. Ask for version/build, patch timestamp, cpsrvd restart evidence, detection-script results, access-log review, exposure-management findings, MDR hunt outcomes, customer-contact criteria, carrier or broker remediation tracking where present, and hosted-asset integrity checks. 35 37
18-Patch & Mitigation Guidance
The primary control is to update to a fixed version and restart cPanel services. Vendor-supported mitigations exist for environments that cannot update immediately, including service exposure restrictions and temporary service changes, but Rapid7 and cPanel both frame patching as the preferred long-term fix.3 6
28-Jun-2026 · Newly retained (>24h) Cloudflare's April 30 emergency WAF release adds a source-backed compensating-control check for environments fronted by Cloudflare: confirm the managed rule is active and review logs/blocks, but do not treat WAF coverage as a substitute for updating cPanel & WHM / WP Squared. Freshness: Newly retained (>24h).23
| Control | Guidance |
|---|---|
| Update | Run cPanel update to a fixed build and confirm version with the cPanel version command. 3 |
| Restart | Restart cpsrvd after update as vendor guidance requires. 3 |
| Legacy path | For CentOS 6 / CloudLinux 6 v110.0.50, follow the vendor-designated v110.0.103 update path. 3 |
| Temporary mitigation | If immediate patching is impossible, restrict inbound access to exposed cPanel/WHM services and apply vendor-supported mitigation steps. 3 6 |
| Cloudflare WAF managed rule 28-Jun-2026 · Newly retained (>24h) | For Cloudflare-fronted assets, validate the emergency managed WAF rule for CVE-2026-41940-related cPanel & WHM authentication-bypass traffic is enabled and review rule hits. Freshness: Newly retained (>24h). 23 |
| Imperva WAF and customer telemetry 29-Jul-2026 · Newly retained (>24h) | Where Imperva Cloud WAF or WAF Gateway is in path, confirm CVE-2026-41940 protection/guide status and review event telemetry; Imperva observed nearly 4,000 attack requests but still directs defenders to patch, inspect session files, and audit WHM access logs. Freshness: Newly retained (>24h). 40 |
| Provider port restrictions and OS migration 17-Jul-2026 · Newly retained (>24h) | Bluehost described temporary cPanel/WHM/Webmail/WebDisk port restrictions for affected VPS/Dedicated servers and framed migration off CentOS 6 as the durable remediation path for unsupported cPanel stacks. Freshness: Newly retained (>24h). 30 |
| Provider port blocking and patch exceptions 19-Jul-2026 · Newly retained (>24h) | InMotion and BinaryLane provider guidance reinforces that exposed cPanel/WHM/Webmail/WebDisk ports may be blocked while fleets are patched, and that systems unable to receive fixes need explicit exception handling, customer outreach, and owner-side patch validation. Freshness: Newly retained (>24h). 32 33 |
| Provider log review and exposure management 20-Jul-2026 · Newly retained (>24h) | KnownHost and Beazley Security reinforce that provider/client evidence should include port-blocking windows, patch rollout, cPanel access/session-log review, detection-script use, perimeter exposure checks, and MDR hunt outcomes. Freshness: Newly retained (>24h). 35 36 |
| CrowdSec detection and WAF virtual patching 20-Jul-2026 · Newly retained (>24h) | Where CrowdSec is in use, confirm CVE-2026-41940 detection and virtual-patching coverage, but keep fixed-build validation and local forensic review as the control of record. Freshness: Newly retained (>24h). 34 |
19-Timeline
| Date / Period | Event | Source-Backed Meaning |
|---|---|---|
| February 2026 (reported) | Public reporting and later summaries reference possible pre-disclosure exploitation activity beginning around late February. | Treat unpatched or recently patched servers as potentially exposed; do not assume risk began on public disclosure day. 6 7 9 19 |
| April 11-13, 2026 15-Aug-2026 · Newly retained (>24h) | HoneyLabs reported focused WHM login-path probing from one source address 17 days before cPanel's April 28 vendor advisory, then saw broader post-publication probing after April 30. 46 | Freshness: Newly retained (>24h); use as bounded early-reconnaissance and historical-log-review evidence. HoneyLabs says the observed pre-publication traffic was not exploit-shaped, so do not treat it as confirmed exploitation, actor attribution, or victim evidence. |
| April 27, 2026 | cPanel says the vulnerability was confirmed and classified, triggering incident response. | Vendor response window begins. 4 |
| April 28, 2026 | cPanel published the support advisory and released patched builds across supported tiers. | Emergency update window begins for exposed servers. 3 4 |
| April 28-30, 2026 20-Jul-2026 · Newly retained (>24h) | KnownHost published a provider response thread describing network-level cPanel/WHM/Webmail/WebDisk port blocking, managed-customer patch rollout, log review, access restoration, and a small number of access-attempt findings without active-compromise signs in reviewed cases. 36 | Freshness: Newly retained (>24h); use as provider-response and bounded telemetry evidence, not an end-customer victim list. |
| April 29, 2026 | watchTowr published technical analysis and public PoC; Rapid7 published an emergent-threat overview. | Exploitability became broadly reproducible for capable operators. 5 6 |
| April 27-May 4, 2026 20-Jul-2026 · Newly retained (>24h) | CrowdSec reported first observed CVE-2026-41940 activity on April 27, 282 distinct IPs tied to the issue through May 4, a significant reconnaissance campaign, dedicated detection coverage, and WAF virtual patching guidance. 34 | Freshness: Newly retained (>24h); use as bounded reconnaissance/detection telemetry, not a named-victim list. |
| April 30, 2026 | Shadowserver reported at least 44,000 likely compromised IPs seen scanning honeypots. | Exploitation moved beyond theoretical risk into large telemetry signal. 8 |
| April 30, 2026 28-Jun-2026 · Newly retained (>24h) | CISA added CVE-2026-41940 to the Known Exploited Vulnerabilities catalog; the KEV JSON records a May 3, 2026 due date and known ransomware-campaign-use flag. 2 | Freshness: Newly retained (>24h); use April 30 as the official KEV catalog date while noting cPanel's May 1 response reference separately. |
| April 30, 2026 28-Jun-2026 · Newly retained (>24h) | Cloudflare published an emergency WAF managed-rule release for cPanel & WHM authentication-bypass traffic related to CVE-2026-41940. 23 | Freshness: Newly retained (>24h); use as compensating-control evidence, not as a replacement for vendor patching. |
| April 30, 2026 29-Jul-2026 · Newly retained (>24h) | Imperva published customer-telemetry and WAF protection guidance, reporting nearly 4,000 CVE-2026-41940 attack requests across 15 industries and 17 countries. 40 | Freshness: Newly retained (>24h); use as bounded WAF/customer-telemetry and compensating-control evidence, not as a named-victim list. |
| May 1, 2026 26-Jun-2026 · Newly retained (>24h) | Censys reported a May 1 spike in GreyNoise-classified malicious hosts concentrated on cPanel/WHM and identified Mirai-pattern and .sorry ransomware activity. 20 | Use this as activity-cluster evidence, not as a named-victim list. |
| May 1, 2026 22-Jul-2026 · Newly retained (>24h) | Coalition Security Labs published insurer/policyholder guidance, stated it notified impacted policyholders on April 29, and described tracking hosting-provider patch progress plus on-premises cPanel/WHM remediation support. 37 | Freshness: Newly retained (>24h); use as insurer and policyholder coordination evidence, not as a named victim or public customer list. |
| May 1, 2026 27-Jul-2026 · Newly retained (>24h) | ASD's ACSC published an alert stating it was aware of active CVE-2026-41940 exploitation in Australia and that several MSP-managed products had been impacted, resulting in customer compromise. 39 | Freshness: Newly retained (>24h); use as national-CERT/MSP customer-impact scoping evidence, not as a named victim list. |
| May 2, 2026 | BleepingComputer reported mass exploitation in Sorry ransomware attacks. | IR scoping should include ransomware and web-host compromise checks. 7 |
| May 2, 2026 26-Jun-2026 · Newly retained (>24h) | Ctrl-Alt-Intel reported an unknown actor using public CVE-2026-41940 PoC tooling against South-East Asian government/military entities plus MSP/hosting-provider targets. 21 | Treat as reported targeting/attempted exploitation with no firm attribution and no automatic compromise conclusion. |
| May 5, 2026 19-Jul-2026 · Newly retained (>24h) | BinaryLane updated its CVE-2026-41940 advisory, describing active exploitation against cPanel servers on its network and provider/customer mitigation responsibilities. 33 | Freshness: Newly retained (>24h); use as provider advisory-pattern evidence, not as a named end-customer victim list. |
| May 6, 2026 08-Jul-2026 · Newly retained (>24h) | Unfold Security published CVE-2026-41940 detection research focused on behavior-based cPanel session and access-log correlation instead of PoC-string matching. 28 | Freshness: Newly retained (>24h); use as detection-engineering guidance while keeping raw rule and exploit material out of broad stakeholder summaries. |
| May 6, 2026 17-Jul-2026 · Newly retained (>24h) | Bluehost published a CVE-2026-41940 compromise-check guide for customers that covers version validation, ransomware-marker checks, persistence and SSH-key review, cPanel template tampering, shell-history review, evidence preservation, credential rotation, and hosted-account scoping. 31 | Freshness: Newly retained (>24h); use as provider-scoped IR checklist evidence while avoiding republication of raw command bodies and hashes. |
| May 10, 2026 | cPanel published response, actions, and next-steps post with root-cause summary and adoption status. | Vendor clarified session-management cause and response path. 4 |
| May 11, 2026 27-Jun-2026 · Newly retained (>24h) | QiAnXin XLab reported Mr_Rot13 exploitation of CVE-2026-41940 to deploy Filemanager backdoor tooling and credential-theft/webshell/persistence components. 22 | Use this as activity-cluster and hunt-priority evidence; do not publish raw payload details or convert it into a named-victim list. |
| May 15, 2026 03-Jul-2026 · Newly retained (>24h) | ThreatLocker published Sorry ransomware malware-analysis detail for CVE-2026-41940 follow-on activity, including Linux encryptor behavior, host markers, service/process disruption, SSH propagation attempts, and recovery implications. 27 | Freshness: Newly retained (>24h); use as bounded hunt and recovery guidance, not as a named-victim list or universal payload path. |
| May 4 and May 13, 2026 28-Jun-2026 · Newly retained (>24h) | Shadowserver added compromised-website report tags for CVE-2026-41940-related cPanel/Roundcube compromise patterns, including sorry-ransomware, whmstealer, and mr-rot13. 24 | Freshness: Newly retained (>24h); use for reporting workflow and activity tags, not as a raw victim list. |
| May 18, 2026 01-Jul-2026 · Newly retained (>24h) | Liquid Web's status incident recorded ongoing remediation following CVE-2026-41940, extended support impact, and restoration work where compromise was evident. 25 | Freshness: Newly retained (>24h); use as named hosting-provider disclosure evidence, not as a raw customer-victim list. |
| May 20, 2026 19-Jul-2026 · Newly retained (>24h) | InMotion Hosting published direct customer follow-up guidance describing fleet port blocking and patching, exceptions where ports stayed blocked, customer outreach, and post-patch review steps. 32 | Freshness: Newly retained (>24h); strengthens provider/customer-notice scoping while avoiding raw exploit-chain detail. |
| May 26, 2026 01-Jul-2026 · Newly retained (>24h) | InMotion Hosting reported fleet-level blocking and patching, 99% of potentially affected customers protected without service disruption, and hands-on remediation for a small subset of environments. 26 | Freshness: Newly retained (>24h); use as provider-response and exposure-scoping evidence, not confirmed compromise for every customer. |
| May 2026 20-Jul-2026 · Newly retained (>24h) | Beazley Security published insurer-adjacent CVE-2026-41940 guidance for exposed self-hosted cPanel review, vendor detection-script use, perimeter exposure management, and MDR threat hunts. 35 | Freshness: Newly retained (>24h); use for insurance and provider-evidence scoping while keeping raw exploit examples out of the public brief. |
| May 27, 2026 13-Jul-2026 · Newly retained (>24h) | Proofpoint published network-telemetry reporting that described CVE-2026-41940 as part of a multi-actor cPanel exploitation cluster and observed use in compromised-website web-inject chains such as TA569/SocGholish. 29 | Freshness: Newly retained (>24h); use as activity-cluster and prioritization evidence, not as a named-victim list or proof that every compromised website involved TA569. |
| June 17, 2026 26-Jun-2026 · Newly retained (>24h) | NVD shows CISA ADP SSVC metadata and VulnCheck affected-record changes added to the CVE record. 1 | Official metadata reinforces active exploitation, automatable exploitation, and total technical-impact framing. |
| July 9, 2026 17-Jul-2026 · Newly retained (>24h) | Bluehost updated customer-facing guidance for VPS and Dedicated customers, including active-exploitation language, temporary cPanel/WHM/Webmail/WebDisk port restrictions for affected servers, CentOS 6 migration as durable remediation, backup/log-review advice, and customer communication language for potentially affected servers. 30 | Freshness: Newly retained (>24h); use as named provider-response and customer-notice evidence, not as a named end-customer victim list. |
| July 22, 2026 24-Jul-2026 · Newly retained (>24h) | Socket published research on a campaign abusing compromised GitHub repositories and GitHub-hosted Actions runners as distributed scanning, CVE-2026-41940 exploitation, and credential-harvesting infrastructure against cPanel/WHM targets. 38 | Freshness: Newly retained (>24h); use as activity-cluster and software-supply-chain scoping evidence, not as a named organization/company victim list or proof that installing the affected Packagist packages executed the payload. |
| July 21-23, 2026 30-Jul-2026 · Newly retained (>24h) | Liquid Web updated the same cPanel/WHM status incident to monitoring on July 21, stating all known affected systems had been addressed or were being actively addressed and normal support operations had resumed, then marked the incident resolved on July 23. 25 | Freshness: Newly retained (>24h); use as provider-remediation status evidence, not as proof that every unnamed customer environment was clean or compromised. |
| July 30, 2026 31-Jul-2026 · Newly retained; undated | Shadowserver's embedded top exploited-vulnerabilities dashboard result showed CVE-2026-41940 ranked 18th, with 114 last-day unique IPs, 196 seven-day average unique IPs, KEV status, and known ransomware-campaign-use flag. 41 | Freshness: Newly retained (publication date not visible); use as bounded ongoing exploit-telemetry evidence, not as a named-victim list, compromise count, or new actor attribution. |
| August 13, 2026 13-Aug-2026 · Newly retained; undated | Shadowserver's embedded top exploited-vulnerabilities dashboard result still showed CVE-2026-41940 exploit pressure, with 98 last-day unique IPs, 134 seven-day average, 164 thirty-day average, 259 ninety-day average, and known ransomware-campaign-use flag. 41 | Freshness: Newly retained (publication date not visible); use as bounded current honeypot exploit telemetry, not as a named-victim list, successful-compromise count, new actor attribution, or proof of a new exploit wave. |
| August 25, 2026 25-Aug-2026 · Newly retained; undated | HoneyLabs' live CVE telemetry listed CVE-2026-41940 as actively exploited, with 5 events from 4 unique IPs in the 24-hour window and 46 events from 15 unique IPs in the seven-day window, last seen August 25. 47 | Freshness: Newly retained (publication date not visible); use as bounded current scanning telemetry and SOC/provider prioritization evidence, not as a named-victim list, successful-compromise count, actor attribution, or a new campaign name. |
| August 20, 2026 24-Aug-2026 · Newly retained (>24h) | VulnCheck published 2026 public-PoC curation research and used a malicious repository that claimed to exploit CVE-2026-41940 as an example of unsafe exploit-artifact handling. 48 | Freshness: Newly retained (>24h); use as source-deconfliction and safe-handling guidance. Do not republish raw malicious repository, payload, or execution details. |
| May 2-August 10, 2026 13-Aug-2026 · Newly retained (>24h) | Government of Guam and Guam BSP public notices, reconciled by DysruptionHub's August 10 update, tie disrupted guam.gov/BSP web properties and then-active BSP file/content restoration to the cPanel-hosted compromise path mapped to CVE-2026-41940. 42 43 44 | Freshness: Newly retained (>24h) for the May 2 official statement and August 10 DysruptionHub update; Newly retained (publication date not visible) for the BSP restoration notice. Use as named public victim/disclosure evidence with no government-wide all-clear, confirmed sensitive PII breach, ransomware, data-theft finding, or actor attribution. |
| August 16, 2026 18-Aug-2026 · Newly retained (>24h) | DysruptionHub updated the Government of Guam/BSP profile to Presumed Resolved after observing that BSP's restoration warning was removed from core BSP pages and reports/publications/data pages were repopulated. 44 | Freshness: Newly retained (>24h); use as bounded recovery-status evidence only. It does not establish a government-wide all-clear, exact final restoration date, complete affected-agency list, data-theft finding, ransomware confirmation, or actor attribution. |
| August 10, 2026 11-Aug-2026 · Newly retained (>24h) | China Daily / CCTV News Client reported that the National Computer Virus Emergency Response Center and National Engineering Laboratory found multiple domestic Sorry ransomware attacks against internet-exposed Linux web servers, explicitly tying initial access to CNNVD-202604-5641 / CVE-2026-41940. 45 | Freshness: Newly retained (>24h); use as China-focused Sorry ransomware activity-cluster and defensive-scoping evidence, not as a named victim list, new ransomware family, or universal payload path. |
20-Real World Examples
| Example | What It Shows | Boundary |
|---|---|---|
| Sorry ransomware reporting 03-Jul-2026 · Newly retained (>24h) | BleepingComputer reports attackers exploited CVE-2026-41940 to breach servers and deploy a Go-based Linux encryptor appending the .sorry extension; ThreatLocker adds bounded malware-analysis detail for host markers, service/process disruption, SSH propagation attempts, and recovery scoping. Freshness: Newly retained (>24h). 7 27 | Use as reported ransomware linkage and hunt guidance; not every exploitation case is ransomware or the same payload path. |
| China-focused Sorry ransomware warning 11-Aug-2026 · Newly retained (>24h) | China Daily / CCTV News Client reporting attributed to the National Computer Virus Emergency Response Center says multiple domestic Sorry ransomware attacks targeted internet-exposed Linux web servers and used CNNVD-202604-5641 / CVE-2026-41940 for initial access, followed by sshd masquerading, victim/environment profiling, service and backup disruption, data theft, AES/RSA encryption, and weak-password SSH lateral-movement attempts. Freshness: Newly retained (>24h). 45 | Use as national-warning and activity-cluster evidence; it names no victim organization and should not be treated as a new ransomware family, actor attribution, or universal exploitation path. |
| Censys .sorry exposure telemetry 26-Jun-2026 · Newly retained (>24h) | Censys reported thousands of cPanel/WHM hosts exposing open directories where filenames ended in .sorry, alongside Mirai-pattern activity in malicious-host classifications. 20 | Use as public telemetry and activity-cluster evidence; do not convert exposed directory counts into named victim organizations. |
| Ctrl-Alt-Intel public targeting report 26-Jun-2026 · Newly retained (>24h) | Ctrl-Alt-Intel reported an unknown actor using public CVE-2026-41940 PoC tooling against South-East Asian government/military entities and MSP/hosting-provider targets. 21 | Reported targeting/attempted exploitation is not the same as confirmed compromise, ransomware impact, or attribution to a named actor. |
| Mr_Rot13 / Filemanager activity 27-Jun-2026 · Newly retained (>24h) | QiAnXin XLab reported Mr_Rot13 exploitation of CVE-2026-41940 to deploy Filemanager remote-control tooling, webshells, SSH-key persistence, login-page tampering, and credential-theft components. 22 | Use as source-backed activity-cluster and hunt guidance; do not treat it as a named-victim disclosure or publish raw attacker infrastructure. |
| Shadowserver compromised-website report tags 28-Jun-2026 · Newly retained (>24h) | Shadowserver describes CVE-2026-41940-related cPanel/Roundcube compromise reporting with sorry-ransomware, whmstealer, and mr-rot13 tags. Freshness: Newly retained (>24h). 24 | Use as report-routing and activity-tag evidence; do not publish Shadowserver event data as a victim list. |
| Hosting-provider customer notices 30-Jul-2026 · Newly retained (>24h) | Liquid Web disclosed CVE-2026-41940 remediation, restoration work where compromise was evident, July 21 monitoring status after all known affected systems were addressed or actively being addressed, and July 23 incident resolution; InMotion disclosed network-edge blocking, fleet patching, direct remediation for a small subset of customer environments, blocked exceptions, customer outreach, and post-patch customer actions; Bluehost described active exploitation, temporary port restrictions, CentOS 6 migration pressure, backup/log-review guidance, and compromise-check categories for VPS/Dedicated customers; BinaryLane described active exploitation on its network and customer/provider mitigation responsibilities; KnownHost described network-wide port blocking, managed-customer patching, log review, and bounded access-attempt findings. Freshness: Newly retained (>24h). 25 26 30 31 32 33 36 | Use as provider-response and customer-scoping evidence; do not infer all customers were compromised or publish end-customer names. |
| Government of Guam / BSP disruption 18-Aug-2026 · Newly retained (>24h) | Government of Guam activated cyber incident response after a widespread incident linked to cPanel-hosted websites; BSP later stated bsp.guam.gov was among domains compromised during the cPanel-hosted server incident and that most downloads and embedded content could not be restored while files, datasets, reports, and media were securely re-uploaded. DysruptionHub's August 16 update now treats the incident as presumed resolved because BSP's restoration warning was removed from core pages and reports/data pages were repopulated. Freshness: Newly retained (>24h). 42 43 44 | Use as named public victim/disclosure, operational-impact, and bounded recovery-status evidence; do not infer sensitive PII breach, confirmed data theft, confirmed ransomware, ransom demand, leak threat, named actor attribution, government-wide all-clear, exact final restoration date, or a raw victim/customer list. |
| Coalition policyholder coordination 22-Jul-2026 · Newly retained (>24h) | Coalition Security Labs says it notified impacted policyholders, tracked hosting-provider patch progress with policyholders, supported on-premises cPanel/WHM remediation, and advised businesses relying on hosting providers to confirm patching directly. Freshness: Newly retained (>24h). 37 | Use as insurer/policyholder coordination evidence; do not infer named victims, claim details, or a public customer list. |
| ACSC Australia/MSP impact advisory 27-Jul-2026 · Newly retained (>24h) | ASD's ACSC said it was aware of active exploitation in Australia and that products managed by several MSPs had been impacted, resulting in customer compromise. Freshness: Newly retained (>24h). 39 | Use as official national-CERT and MSP/customer scoping evidence; ACSC did not name victim organizations, customers, providers, sectors, or a threat actor. |
| CrowdSec reconnaissance telemetry 20-Jul-2026 · Newly retained (>24h) | CrowdSec reported first observed activity on April 27, 282 distinct IPs tied to CVE-2026-41940 through May 4, a significant reconnaissance campaign, and dedicated detection/WAF virtual-patching coverage. Freshness: Newly retained (>24h). 34 | Use as bounded telemetry and control evidence; not as a named-victim list or proof that every observed IP achieved compromise. |
| Imperva WAF/customer telemetry 29-Jul-2026 · Newly retained (>24h) | Imperva reported nearly 4,000 CVE-2026-41940 attack requests targeting customer environments across 15 industries and 17 countries, with US sites accounting for almost 70% of observed attacks, plus WAF protection guidance. Freshness: Newly retained (>24h). 40 | Use as bounded customer-environment telemetry and control evidence; not as a named-victim disclosure or proof of successful compromise. |
| Proofpoint compromised-website web-inject telemetry 13-Jul-2026 · Newly retained (>24h) | Proofpoint described CVE-2026-41940 as part of a multi-actor cPanel exploitation cluster and increasingly observed it in compromised-website web-inject chains such as TA569/SocGholish. Freshness: Newly retained (>24h). 29 | Use as activity-cluster and hosted-site scoping evidence; not a named-victim disclosure and not universal attribution to TA569/SocGholish. |
| Socket GitHub Actions runner abuse campaign 24-Jul-2026 · Newly retained (>24h) | Socket reported compromised GitHub repositories and GitHub-hosted runners used as distributed infrastructure to scan for and attempt CVE-2026-41940 exploitation against cPanel/WHM targets, then harvest server-side credentials and secrets. Freshness: Newly retained (>24h). 38 | Use as activity-cluster and software-supply-chain scoping evidence; do not treat affected Packagist package installation as automatic payload execution or matching workflow-file counts as named victim companies. |
| HoneyLabs pre-advisory WHM probing 15-Aug-2026 · Newly retained (>24h) | HoneyLabs reported one focused source probing the cPanel/WHM login path 17 days before the April 28 cPanel advisory, followed by broader post-publication probing after April 30. Freshness: Newly retained (>24h). 46 | Use as early-reconnaissance and retrospective log-review evidence; HoneyLabs explicitly says the pre-publication traffic was not exploit-shaped and should not be treated as confirmed exploitation, actor attribution, or victim evidence. |
| Shadowserver 44K+ telemetry | Shadowserver reported at least 44,000 likely compromised IPs seen scanning honeypots. 8 | Telemetry is not a publishable named-victim list and should not be treated as unique customer count. |
| Hosting provider exposure | Rapid7 notes exposed cPanel/WHM instances may number around 1.5 million in simple internet-exposure queries. 6 | Exposure counts vary by scan method and do not equal confirmed compromise. |
| Policyholder / SMB web environment | The realistic real-world pattern is an SMB, hosted website customer, reseller customer, or agency-managed site whose exposure depends on a third-party cPanel/WHM control plane. That may include WordPress, another CMS, ecommerce software, custom sites, mail, databases, or customer portals. 3 6 17 18 | This is a scoping archetype, not a named confirmed victim. |
21-Public Victim / Disclosure Matrix
This card is intentionally reserved for named public victim organizations or companies tied to CVE-2026-41940 exploitation. 26-Jun-2026 · Newly retained (>24h) The June 26 monitor found named public organizations in Ctrl-Alt-Intel reporting, but only as reported targets of public PoC use / attempted exploitation. The retained source set still does not support a validated public list of organizations confirmed compromised by CVE-2026-41940.21 27-Jun-2026 · Newly retained (>24h) The June 27 monitor retained Mr_Rot13 activity-cluster reporting, but it did not add a reliable named public victim organization or company directly tied to confirmed CVE-2026-41940 compromise.22 28-Jun-2026 · Newly retained (>24h) The June 28 monitor retained Shadowserver report tags and Cloudflare WAF guidance, but found no new reliable named public victim organization or company. Freshness: Newly retained (>24h).23 24 01-Jul-2026 · Newly retained (>24h) The July 1 monitor retained named hosting-provider disclosure evidence from Liquid Web and InMotion Hosting. These sources improve provider/customer-notice scoping, but they do not publish a reliable named end-customer victim list. Freshness: Newly retained (>24h).25 26 03-Jul-2026 · Newly retained (>24h) The July 3 monitor retained ThreatLocker's Sorry ransomware malware-analysis detail, but found no new reliable named victim organization or company. Freshness: Newly retained (>24h).27 17-Jul-2026 · Newly retained (>24h) The July 17 monitor retained Bluehost as a named hosting-provider customer-notice source. The sources improve VPS/Dedicated, CentOS 6, outage, backup, log-review, and compromise-check scoping, but they do not publish a reliable named end-customer victim list. Freshness: Newly retained (>24h).30 31 19-Jul-2026 · Newly retained (>24h) The July 19 monitor retained InMotion Hosting's direct follow-up and BinaryLane's advisory as named provider/customer-notice sources. These sources strengthen provider-response and unmanaged-VPS scoping, but they do not publish a reliable named end-customer victim list. Freshness: Newly retained (>24h).32 33 20-Jul-2026 · Newly retained (>24h) The July 20 monitor retained KnownHost as an additional named provider/customer-notice source and retained CrowdSec/Beazley Security for telemetry, detection-control, and insurer-adjacent scoping. These sources improve provider-response and evidence-request language, but they do not publish a reliable named end-customer victim list. Freshness: Newly retained (>24h).34 35 36 22-Jul-2026 · Newly retained (>24h) The July 22 monitor retained Coalition Security Labs as insurer/policyholder coordination evidence. It strengthens carrier, broker, and provider-remediation tracking questions, but it does not publish a reliable named end-customer victim list. Freshness: Newly retained (>24h).37 24-Jul-2026 · Newly retained (>24h) The July 24 monitor retained Socket's GitHub Actions abuse research as a source-backed activity cluster. The source names compromised maintainer/package artifacts and broad workflow-file counts, but it does not publish a reliable named organization/company list confirmed compromised through CVE-2026-41940. Freshness: Newly retained (>24h).38 27-Jul-2026 · Newly retained (>24h) The July 27 monitor retained ASD's ACSC alert as national-CERT/MSP scoping evidence. ACSC reports active exploitation in Australia and unnamed MSP-managed customer compromise, but it does not name a reliable public victim organization, customer, provider, sector, or actor. Freshness: Newly retained (>24h).39 29-Jul-2026 · Newly retained (>24h) The July 29 monitor retained Imperva WAF/customer-environment telemetry. Imperva's industry, country, and customer-environment aggregation improves exposure and control scoping, but it does not name a reliable public victim organization or prove successful compromise. Freshness: Newly retained (>24h).40 03-Aug-2026 · Newly retained (>24h) The August 3 monitor retained Government of Guam/BSP as named public victim/disclosure evidence tied to the cPanel-hosted CVE-2026-41940 compromise path. Freshness: Newly retained (>24h) for the May 2 official statement and DysruptionHub profile; Newly retained (publication date not visible) for the BSP restoration notice.42 43 44 09-Aug-2026 · Newly retained; undated The August 9 monitor retained updated Shadowserver current exploit telemetry, but found no additional reliable named public organization or company tied to confirmed CVE-2026-41940 exploitation, ransomware impact, hosted-site compromise, provider notice, or customer notice. Freshness: Newly retained (publication date not visible).41 11-Aug-2026 · Newly retained (>24h) The August 11 monitor retained China Daily / CCTV News Client reporting of multiple domestic Sorry ransomware attacks in China, but the source does not name victim organizations or companies. Freshness: Newly retained (>24h).45 13-Aug-2026 · Newly retained (>24h) The August 13 monitor retained DysruptionHub's August 10 Guam/BSP status update: the response remained active, BSP downloads and embedded content were still unavailable while files and datasets were re-uploaded, and no government-wide all-clear, confirmed data theft, ransomware finding, or actor attribution had been published. Freshness: Newly retained (>24h).42 43 44 18-Aug-2026 · Newly retained (>24h) The August 18 monitor retained DysruptionHub's August 16 Guam/BSP presumed-resolved revision: BSP's restoration warning was no longer visible on core BSP pages and reports/data pages were repopulated, but no government-wide all-clear, exact final restoration date, confirmed data theft, ransomware finding, or actor attribution had been published. Freshness: Newly retained (>24h).44 15-Aug-2026 · Newly retained (>24h) The August 15 monitor retained HoneyLabs' July 23 pre-advisory WHM login-path probing analysis, but it did not name a victim organization or prove exploitation. Freshness: Newly retained (>24h).46 25-Aug-2026 · Newly retained; undated The August 25 monitor retained updated HoneyLabs live CVE telemetry, but found no additional reliable named public organization or company tied to confirmed CVE-2026-41940 exploitation, ransomware impact, hosted-site compromise, provider notice, or customer notice beyond the retained Government of Guam/BSP row. Freshness: Newly retained (publication date not visible) for HoneyLabs.47
| Organization / Entity | Public Status | Reported Impact | Evidence Boundary | How To Use It |
|---|---|---|---|---|
| Philippine Coast Guard; Philippine Air Force, 15th Strike Wing; Philippine Government Arsenal; Lao Ministry of National Defence; Lao Ministry of Natural Resources and Environment 26-Jun-2026 · Newly retained (>24h) | Reported by Ctrl-Alt-Intel on May 2, 2026 as targets of an unknown actor's CVE-2026-41940 public-PoC use. 21 | Reported targeting / attempted exploitation; no confirmed compromise, data theft, ransomware impact, or victim statement is established by this source. | Use as named public targeting evidence only. Do not describe these organizations as confirmed breached victims unless a reliable source later confirms compromise or impact. | Use for government/MSP scoping questions, targeted-exploitation caveats, and activity-cluster monitoring. |
| Unnamed MSPs and hosting providers in the Philippines, Laos, Canada, South Africa, and the United States 26-Jun-2026 · Newly retained (>24h) | Ctrl-Alt-Intel reported MSP/hosting-provider targeting alongside the named South-East Asian government/military targets. 21 | No public organization names, compromise confirmations, customer notices, or provider statements were retained for this group. | Do not populate unnamed providers as victims; use this as sector/victimology guidance only. | Prioritize hosting providers, MSPs, resellers, and web agencies for patch-evidence and detection-script follow-up. |
| Unnamed Australian MSP-managed customers 27-Jul-2026 · Newly retained (>24h) | ASD's ACSC reported active exploitation in Australia and stated that products managed by several MSPs had been impacted, resulting in compromise of their customers. 39 | Official national-CERT customer-compromise scoping signal; no named organization, provider, customer, sector, campaign, ransomware family, or victim statement was published. Freshness: Newly retained (>24h). | Do not treat this as a public named-victim list or raw customer notice. It supports provider/MSP assurance questions only. | Ask Australian and MSP-managed environments for patch evidence, monitoring confirmation, vendor detection-script results, and local impact review. |
| Government of Guam; Guam Bureau of Statistics and Plans 18-Aug-2026 · Newly retained (>24h) | Government of Guam official response statement dated May 2, 2026; Guam BSP restoration notice with no visible publication date; DysruptionHub reconciled incident profile published May 2 and last updated August 16, 2026. 42 43 44 | Government of Guam activated cyber incident response for a widespread incident linked to cPanel-hosted websites, with multiple guam.gov sites potentially affected. BSP later stated bsp.guam.gov was among domains compromised during the cPanel-hosted server incident and that most file downloads and embedded content could not be restored while the agency securely re-uploaded files, datasets, reports, and media. DysruptionHub's August 16 update now treats the incident as presumed resolved because BSP's restoration warning was removed from core pages and reports/data pages were repopulated. Freshness: Newly retained (>24h). | Treat as named public victim/disclosure, operational-impact, and bounded recovery-status evidence tied to the cPanel-hosted CVE-2026-41940 path. Do not claim confirmed sensitive PII breach, data theft, ransomware encryption, ransom demand, leak threat, named actor attribution, government-wide all-clear, exact final restoration date, or a raw victim/customer list. | Use for government-services scoping, public-web restoration and recovery-status questions, hosted-content integrity review, backup restoration evidence, and provider/agency assurance workflows. |
| Liquid Web 30-Jul-2026 · Newly retained (>24h) | Public hosting-provider status incident with CVE-2026-41940 remediation updates from April 28 through July 23, 2026. 25 | Liquid Web reported patching and mitigation activity, elevated support volume, remaining remediation, and restoration work for servers where compromise was evident; later updates stated all known affected systems had been addressed or were actively being addressed by July 21 and marked the incident resolved on July 23. Freshness: Newly retained (>24h). | Treat as a named provider/customer-notice disclosure. Do not infer that Liquid Web corporate systems, all Liquid Web customers, or any unnamed customer organization were compromised. | Use for provider-attestation questions, restore/remediation scoping, and customer communication patterns. |
| InMotion Hosting 19-Jul-2026 · Newly retained (>24h) | Public provider response report dated May 26, 2026 and direct customer follow-up updated May 20, 2026 covering fleet-level CVE-2026-41940 response. 26 32 | InMotion reported network-edge blocking, fleet patching, 99% of potentially affected customers protected without service disruption, direct remediation for a small subset of customer environments, exceptions where blocked ports remained in place, customer outreach, and customer review actions. Freshness: Newly retained (>24h). | Treat as provider-response and exposure-scoping evidence, not confirmed compromise for every potentially affected customer and not a named end-customer victim list. | Use as a benchmark for questions to managed hosts: port blocking, patch evidence, exception handling, direct outreach, and remediation support. |
| BinaryLane 19-Jul-2026 · Newly retained (>24h) | Public provider advisory last updated May 5, 2026 covering CVE-2026-41940 active exploitation and mitigation responsibilities. 33 | BinaryLane described active exploitation against cPanel servers on its network, provider-side mitigation/notification, and patch-validation responsibilities for unmanaged VPS customers. Freshness: Newly retained (>24h). | Treat as a named provider/customer-notice disclosure. Do not infer that BinaryLane corporate systems, all BinaryLane customers, or any unnamed customer organization was compromised. | Use for provider-attestation questions, unmanaged-VPS responsibility scoping, and customer communication patterns. |
| Bluehost 17-Jul-2026 · Newly retained (>24h) | Public provider customer guidance updated July 9, 2026, plus a related May 6 compromise-check guide for CVE-2026-41940. 30 31 | Bluehost described active exploitation, temporary access restrictions on affected VPS/Dedicated cPanel ports, CentOS 6 migration needs, backup/log-review guidance, and compromise-check categories. Freshness: Newly retained (>24h). | Treat as a named provider/customer-notice disclosure. Do not infer that Bluehost corporate systems, every Bluehost VPS/Dedicated customer, or any unnamed customer organization was compromised. | Use for provider-attestation questions, outage/customer-notice review, unsupported-OS migration scoping, and compromise-review evidence requests. |
| KnownHost 20-Jul-2026 · Newly retained (>24h) | Public provider response thread dated April 28-30, 2026 covering CVE-2026-41940 port blocking, patch rollout, access restoration, and log-review findings. 36 | KnownHost described network-level blocking of cPanel, WHM, Webmail, and WebDisk ports, managed-customer patch rollout across thousands of machines, later access restoration after patching, and a small number of access-attempt findings without active-compromise signs in reviewed cases. Freshness: Newly retained (>24h). | Treat as a named provider/customer-notice disclosure and bounded provider telemetry. Do not infer that KnownHost corporate systems, all KnownHost customers, or any unnamed customer organization was compromised. | Use for provider-attestation questions, port-blocking evidence, log-review scope, access-attempt findings, and customer-contact criteria. |
| Confirmed compromised named end-customer organizations beyond retained named disclosures | 25-Aug-2026 · Newly retained; undated The August 25 named-victim search found no validated public end-customer company/org compromise list beyond the bounded Government of Guam/BSP disclosure. | Aggregate telemetry, exposed-instance counts, public targeting reports, provider-wide notices, and community victim anecdotes do not create a verified end-customer victim list. | Do not convert Shadowserver telemetry/report tags or dashboard rows, Censys open-directory counts, CrowdSec IP counts, Imperva customer-environment telemetry, HoneyLabs pre-advisory probe telemetry, August 25 HoneyLabs live CVE scanning telemetry, exposed-instance totals, provider support queues, provider-wide port restrictions, provider exception lists, provider access-attempt counts, unnamed ACSC MSP/customer impact language, Government of Guam/BSP operational-impact evidence, China domestic attack warnings without named organizations, or individual/forum anecdotes into broader organization-level customer victim claims. 6 7 8 20 21 24 25 26 30 31 32 33 34 36 39 40 41 42 43 44 45 46 47 | Ask policyholders, hosting providers, MSPs, and web agencies for local evidence instead of relying on public victim naming. |
22-Associated Campaigns / Activity Clusters
This card tracks source-backed activity associated with CVE-2026-41940 without confusing those activity clusters with named victim organizations. A cluster can be useful for scoping even when public sources do not identify the operator, campaign name, or victim companies.
| Campaign / Activity Cluster | Activity Type | Source-Backed Evidence | Defensive Use | Boundary |
|---|---|---|---|---|
| CISA KEV-recognized exploitation 28-Jun-2026 · Newly retained (>24h) | Known exploited vulnerability activity | CISA's official KEV feed records April 30 catalog addition, May 3 due date, and known ransomware-campaign-use status; cPanel's response separately references May 1 confirmation. 2 4 | Use KEV status to justify emergency patch validation, provider outreach, and evidence preservation. | KEV status does not identify a specific actor, victim list, or single campaign. |
| Sorry ransomware exploitation reporting 26-Jun-2026 · Newly retained (>24h) | Reported ransomware follow-on activity | BleepingComputer reports CVE-2026-41940 exploitation in Sorry ransomware attacks, including Linux-host encryption indicators. 11-Aug-2026 · Newly retained (>24h) ThreatLocker adds malware-analysis detail for Sorry host markers, service/process disruption, SSH propagation attempts, and recovery scoping; Censys separately observed thousands of cPanel/WHM hosts exposing open directories where filenames ended in .sorry; Shadowserver later describes sorry-ransomware report tags for CVE-2026-41940-related compromise reporting; China Daily / CCTV News Client reporting attributed to the National Computer Virus Emergency Response Center adds multiple China domestic Sorry ransomware attack detail tied to cPanel/CVE-2026-41940 initial access, data theft, AES/RSA encryption, and weak-password SSH lateral movement. Freshness: Newly retained (>24h) for source 45. 7 16 20 24 27 45 | Scope for ransomware notes, .sorry extensions, host-level marker files, Linux encryptor activity, service/process interruption, SSH propagation attempts, backup impact, and hosted-site recovery needs. | Treat Sorry as a reported exploitation outcome; do not assume every cPanel compromise became ransomware or used the same payload path. |
| China domestic Sorry ransomware warning 11-Aug-2026 · Newly retained (>24h) | National warning / ransomware activity cluster / Linux web-server victimology | China Daily republished CCTV News Client reporting that attributes a National Computer Virus Emergency Response Center and National Engineering Laboratory warning to multiple domestic Sorry ransomware attacks against internet-exposed Linux web servers. The report says attackers used WebPros cPanel authorization-bypass vulnerability CNNVD-202604-5641 / CVE-2026-41940 for server-management access, then ran Sorry while masquerading as sshd, generated victim/environment identifiers, disrupted database/security/backup services, stole business data and configuration/internal files, encrypted files with AES and RSA-protected keys, and attempted lateral movement via SSH ports and weak passwords. Freshness: Newly retained (>24h). 45 | For Linux web servers and hosted environments, add China-warning-specific checks for sshd process masquerading, host/environment beaconing, service and backup interruption, data-theft staging, .sorry encryption, unsupported decryptor/communication-tool scams, and SSH weak-password lateral movement alongside fixed-build validation. | This source names no victim organizations, no actor, and no new ransomware family. Use as defensive activity-cluster evidence, not a public victim matrix population source or proof that every Sorry case used this exact path. |
| Mirai-pattern post-compromise activity 26-Jun-2026 · Newly retained (>24h) | Botnet / DDoS-client deployment signal | Censys reported malicious-host classifications with patterns consistent with Mirai and noted at least two distinct active attack paths: Mirai-variant deployment and .sorry ransomware activity. 20 | Check compromised cPanel hosts for DDoS clients, miners, new privileged users, firewall changes, suspicious processes, outbound attack traffic, and customer-hosted credential exposure. | Censys did not prove that the malware binary itself exploited cPanel directly; treat this as post-compromise deployment activity tied to the broader CVE-2026-41940 exploitation window. |
| South-East Asia government/military public-PoC targeting 26-Jun-2026 · Newly retained (>24h) | Targeted exploitation attempts / public PoC operationalization | Ctrl-Alt-Intel reported an unknown actor interactively attempting CVE-2026-41940 exploitation against named South-East Asian government/military entities and MSP/hosting-provider targets using public PoC tooling. 21 | For government, defense-sector, MSP, and hosting-provider environments, raise urgency from opportunistic-only assumptions to targeted-exploitation scoping and review for pivot tooling or persistence. | No firm attribution. Reported targeting/attempted exploitation does not equal confirmed compromise for every named organization. |
| Mr_Rot13 / Filemanager backdoor activity 27-Jun-2026 · Newly retained (>24h) | Named threat-actor activity / backdoor and credential-theft follow-on | QiAnXin XLab attributed one CVE-2026-41940 exploitation stream to Mr_Rot13 and reported automated attacks that deployed Filemanager remote-control tooling, PHP webshells, SSH-key persistence, login-page tampering, credential collection, and backdoor components. Shadowserver later added mr-rot13 report tags for related backdoors. Freshness: Newly retained (>24h). 22 24 | For any host with suspected exposure or compromise, hunt beyond ransomware: review SSH keys, cPanel-facing assets, webshells, credential access, remote-control services, suspicious processes, and persistence mechanisms. | This is a source-backed activity cluster, not a complete attribution for all exploitation and not a named-victim disclosure. Keep raw attacker infrastructure out of broad public summaries. |
| Shadowserver compromised-website report tags 28-Jun-2026 · Newly retained (>24h) | Security-vendor report / activity-tag cluster | Shadowserver describes cPanel and related Roundcube instances attempting honeypot exploitation or seen in darknets as likely CVE-2026-41940-related compromise, with sorry-ransomware, whmstealer, and mr-rot13 tags. Freshness: Newly retained (>24h). 24 | Use Shadowserver notifications and tags to route provider/ASN follow-up, website integrity checks, credential-stealer review, ransomware scoping, and Mr_Rot13/Filemanager hunts. | Report tags and telemetry are not named-victim disclosures, and raw event lists should not be republished. |
| CrowdSec reconnaissance and detection-control telemetry 20-Jul-2026 · Newly retained (>24h) | Reconnaissance / detection coverage / WAF virtual patching | CrowdSec reported first observed CVE-2026-41940 activity on April 27, 282 distinct IPs tied to the vulnerability between April 27 and May 4, a significant reconnaissance campaign since April 30, dedicated detection coverage, and WAF virtual patching for exposed setups. Freshness: Newly retained (>24h). 34 | Use as a bounded activity-cluster signal for exposed cPanel/WHM discovery pressure and as a control-evidence prompt for SOC/WAF teams that use CrowdSec. | This does not name victims, prove each observed IP achieved compromise, or replace vendor patch and local forensic evidence. |
| Focused pre-advisory WHM login-path probing 15-Aug-2026 · Newly retained (>24h) | Pre-publication reconnaissance / historical honeypot telemetry | HoneyLabs reported one narrowly focused source probing the cPanel/WHM login path on April 11-13, 2026, 17 days before cPanel's April 28 vendor advisory, then broader post-publication probing after April 30. HoneyLabs says its measurement used its own honeypot traffic, NVD publication dates, exploit-template history, scanner filtering, and coverage-start guards. Freshness: Newly retained (>24h). 46 | Use as a retrospective log-review prompt for WHM/cPanel login-path probes in April 2026 and as a reminder to compare local detections against the earliest public signal, not only NVD publication. | HoneyLabs says the pre-publication traffic was not exploit-shaped and could reflect research or attacker reconnaissance. Do not treat it as confirmed exploitation, victim evidence, new actor attribution, or a named campaign. |
| HoneyLabs live CVE scanning telemetry 25-Aug-2026 · Newly retained; undated | Current honeypot telemetry / scanning and exploitation pressure | HoneyLabs' live CVE dataset listed CVE-2026-41940 as actively exploited, with 5 events from 4 unique IPs in the 24-hour window and 46 events from 15 unique IPs in the seven-day window, last seen August 25, 2026. Freshness: Newly retained (publication date not visible). 47 | Use as a current scanning-pressure signal for SOC, hosting-provider, and insurer prioritization: preserve recent WHM/cPanel logs, check provider controls, and correlate local events before making compromise decisions. | Live telemetry is not a named-victim disclosure, successful-compromise count, actor attribution, botnet/ransomware family identification, or proof of a new exploit wave. |
| Imperva WAF/customer-environment telemetry 29-Jul-2026 · Newly retained (>24h) | WAF/customer telemetry / broad probing and opportunistic exploitation pressure / compensating-control evidence | Imperva reported nearly 4,000 CVE-2026-41940 attack requests against customer environments across 15 industries and 17 countries, with US sites accounting for almost 70% of observed attacks, and described Cloud WAF/WAF Gateway protection while still recommending vendor patching and local session/access-log review. Freshness: Newly retained (>24h). 40 | Use as a customer-environment telemetry signal and control-evidence prompt for WAF teams: verify coverage, preserve WAF event history, correlate with cPanel session/access logs, and continue fixed-build and compromise-review validation. | This is aggregate telemetry and protection guidance, not a named-victim list, proof of successful exploitation in each environment, or a replacement for cPanel patching. |
| GitHub Actions runner abuse and credential-harvesting campaign 24-Jul-2026 · Newly retained (>24h) | CI/CD abuse / distributed scanning and exploitation-attempt infrastructure / credential harvesting | Socket reported that compromised GitHub repositories and GitHub-hosted Actions runners were used to launch Linux payloads, scan for internet-facing cPanel/WHM systems, attempt CVE-2026-41940 exploitation, and collect server-side secrets including cloud keys, source-control tokens, database access, SSH material, payment-service keys, and email-service credentials. Socket also says affected Packagist development versions exposed malicious workflow artifacts, but ordinary package installation did not execute those workflows. Freshness: Newly retained (>24h). 38 | For organizations with GitHub, Packagist, or cPanel exposure, review repository workflow changes, Actions execution logs, runner egress, suspicious payload downloads, CI/CD permissions, affected development-version lockfiles, and exposed server-side credential rotation needs alongside normal cPanel patch/detection evidence. | This is an activity cluster, not a reliable named company victim list. Do not publish raw payload infrastructure, assume every matching repository was compromised, or treat package consumers as automatically infected. |
| Hosting-provider remediation, customer-notice, policyholder-coordination, and national-CERT MSP impact pattern 27-Jul-2026 · Newly retained (>24h) | Provider advisory / fleet remediation / customer-support cluster | 30-Jul-2026 · Newly retained (>24h) Liquid Web publicly described CVE-2026-41940-related patching, support-volume impact, restoration where compromise was evident, July 21 monitoring status after all known affected systems were addressed or actively being addressed, and July 23 incident resolution; InMotion reported network-edge blocking, fleet patching, 99% of potentially affected customers protected without service disruption, direct remediation for a small subset of customer environments, blocked exceptions, customer outreach, and post-patch customer actions; Bluehost described active exploitation, temporary port restrictions for affected VPS/Dedicated servers, CentOS 6 migration guidance, backups/log review, and compromise-check categories; BinaryLane described active exploitation on its network and customer/provider mitigation responsibilities; KnownHost described port blocking, managed-customer patch rollout, access restoration, log review, and bounded access-attempt findings; Beazley Security adds insurer-adjacent exposure-management and MDR hunt language; Coalition adds policyholder notification, hosting-provider patch-progress tracking, and on-premises remediation support; ACSC adds official Australian national-CERT language that several MSP-managed products were impacted with customer compromise. Freshness: Newly retained (>24h). 25 26 30 31 32 33 35 36 37 39 | Use as a checklist for provider/MSP/carrier outreach: fixed builds, port restrictions, exception handling for unsupported cPanel versions, OS migration, customer notifications, unmanaged-VPS responsibility, policyholder notification, provider patch-progress tracking, restore status, backups/log review, access-attempt findings, MDR hunts, compromise-review evidence, and third-party-managed customer impact confirmation. | This is a provider-response and MSP/customer-impact scoping pattern, not attribution to a threat actor and not a public list of named customer victims. |
| Compromised-website web-inject chains / TA569-SocGholish lens 13-Jul-2026 · Newly retained (>24h) | Compromised-website abuse / traffic-delivery and web-inject activity | Proofpoint's May 27 network-telemetry report says CVE-2026-41940 exploitation evolved into a multi-actor campaign and that Proofpoint increasingly observed the vulnerability in attack chains used by actors that compromise legitimate websites via web inject, such as TA569/SocGholish. Freshness: Newly retained (>24h). 29 | For compromised cPanel/WHM hosts and hosted sites, include website-defacement, injected JavaScript, redirect, traffic-distribution, and downstream visitor-impact checks in addition to ransomware and backdoor hunts. | Use this as an activity-cluster and scoping lens only. Proofpoint does not provide a named victim list here and this does not prove every CVE-2026-41940 compromise involved TA569 or SocGholish. |
| Shadowserver large-scale and current dashboard telemetry 13-Aug-2026 · Newly retained; undated | Aggregate scanning / likely compromise telemetry / current honeypot exploit activity | Shadowserver reported at least 44,000 likely compromised IPs observed scanning honeypots earlier in the exploitation window. Its August 13, 2026 exploited-vulnerabilities dashboard row still showed CVE-2026-41940 current activity, with 98 last-day unique IPs, 134 seven-day average, 164 thirty-day average, 259 ninety-day average, and a known ransomware-campaign-use flag. Freshness: Newly retained (publication date not visible). 7 8 41 | Use as scale and current exploit-pressure evidence for exposure validation, provider follow-up, and honeypot/WAF/log correlation, not as a customer notification list. | Aggregate telemetry and dashboard rankings are not named-victim evidence, do not prove unique organizations compromised, and do not identify a new actor, ransomware family, campaign name, or successful-compromise count. |
| Public PoC / copycat exploitation risk | Exploit reproducibility after public technical analysis | watchTowr published technical analysis and PoC after vendor fixes, Rapid7 described exploitability and exposed-instance context, and 24-Aug-2026 · Newly retained (>24h) VulnCheck later documented a malicious repository falsely claiming to exploit CVE-2026-41940 as an example of unsafe public-PoC handling. Freshness: Newly retained (>24h). 5 6 48 | Assume opportunistic exploitation becomes easier after public PoC, but validate exploit artifacts before use; prioritize patch and log review over passive waiting. | PoC availability is an activity-enablement factor, and malicious/fake PoC examples are source-deconfliction signals, not attribution to a named campaign. |
| Exposed hosting-control-plane scanning | Internet-facing cPanel/WHM discovery and exploitation pressure | Rapid7, CyCognito, Picus, and Qualys frame the issue as internet-facing hosting-control-plane exposure with downstream hosted-asset impact. 6 9 10 11 | Ask providers/MSPs to identify exposed cPanel/WHM/WP Squared assets, patch state, service restrictions, and detection-script results. | Exposure and scanning pressure are not the same as confirmed compromise or victim naming. |
| Future AI Agent population rule | Monitor-maintained activity cluster | Populate only when a reliable public source ties a ransomware family, intrusion set, botnet, scanning cluster, exploit campaign, hosting-provider advisory pattern, or named actor to CVE-2026-41940. | When a cluster is source-backed, update Timeline, Real World Examples, Source Deconfliction, AI Agent Delta Updates, Citations, and any affected response guidance. | Do not turn SEO rewrites, exploit reposts, unverified forum claims, or aggregate exposure counts into campaign claims. |
23-Threat Actor Glossary
Public attribution for CVE-2026-41940 is mixed and should stay bounded to the specific source-backed activity being discussed. This card separates named activity clusters from universal attribution claims.
| Name / Label | How To Use It | Boundary |
|---|---|---|
| Sorry ransomware | 11-Aug-2026 · Newly retained (>24h) Use as a reported ransomware follow-on outcome after CVE-2026-41940 exploitation; scope for .sorry extensions, ransom notes, backup impact, Linux-host encryption, service/process disruption, sshd masquerading, data theft, and SSH weak-password lateral-movement attempts. 7 16 24 45 | Reported ransomware linkage does not mean every exposed or compromised cPanel host was encrypted or followed the China warning's exact activity path. |
| Mr_Rot13 / Filemanager 27-Jun-2026 · Newly retained (>24h) | Use as a source-backed hunt lens for backdoors, webshells, SSH-key persistence, login-page tampering, credential collection, and Filemanager-style remote control. 22 24 | Do not attribute all CVE-2026-41940 exploitation to Mr_Rot13; apply only where local or source-backed evidence supports it. |
| Unknown South-East Asia public-PoC operator | Use for targeted-exploitation scoping against the named government/military targets and MSP/hosting-provider patterns reported by Ctrl-Alt-Intel. 21 | Reported targeting or attempted exploitation is not the same as confirmed compromise. |
| whmstealer report tag | Use as a Shadowserver reporting/tagging signal for credential-theft-oriented compromise follow-up. 24 | Treat report tags as defensive routing metadata, not as standalone attribution or victim evidence. |
24-Term Glossary
| Term | Definition | Why It Matters |
|---|---|---|
| WHM | WebHost Manager; server-level administration interface associated with cPanel hosting environments. | Compromise can affect multiple hosted accounts and sites. |
| cPanel | A widely used web-hosting control panel for managing websites, CMS installs, files, domains, databases, email, customer accounts, and hosting administration. | It is the affected control-plane layer, not a WordPress component. |
| WP Squared / WP2 | A WebPros/cPanel product listed in the vendor advisory as affected before fixed build 136.1.7; treat it as part of the hosting control-plane scope, not as WordPress core, a plugin, or a theme. | Scope should not stop at cPanel & WHM only, and the WP2 name can cause confusion with WordPress. |
| Hosted workload relationship | WordPress, other CMS platforms, ecommerce sites, custom sites, databases, and mail may be downstream workloads managed through cPanel, but CVE-2026-41940 is in the cPanel & WHM / WP Squared control plane. | Prevents inaccurate stakeholder messaging and patch ownership confusion. |
| CRLF injection | Injection of carriage-return/line-feed characters to manipulate line-oriented parsing or file content. | Public analyses frame the exploit around CRLF manipulation of session handling. |
| cpsrvd | cPanel service daemon referenced in vendor restart and mitigation guidance. | Patch validation requires service restart and version confirmation. |
| CISA KEV | Known Exploited Vulnerabilities catalog. | KEV status means active exploitation is officially recognized. |
26-Talking Points
| Audience | Talk Track |
|---|---|
| Executives | This is a hosting control-plane issue, not just a website bug. If our business depends on hosted sites, portals, mail, or databases running behind cPanel/WHM, we need assurance that the environment is patched and checked for compromise. |
| IT / MSP | Confirm exact fixed build, restart cpsrvd, run the vendor detection script, preserve logs, and review session/access artifacts before cleanup. |
| Claims / counsel | For affected SMBs, the key question is whether a vulnerable control panel was merely exposed or whether administrative access, website content, customer data, backups, or ransomware impact occurred. |
| Client-facing advisor | Ask the hosting provider or web agency for patch attestation, detection-script results, exposure window, and evidence of post-exploitation review. |
Scoping Call Quote
“CVE-2026-41940 is a critical cPanel and WHM authentication bypass. The practical concern is that an attacker may not need a password to reach administrative control of a hosting environment. For an SMB, that may mean the risk sits with a hosting provider, reseller, agency, or MSP rather than inside the company's own IT stack. This is not limited to WordPress; any website, CMS, mail, database, file, or customer-hosting workflow managed through the vulnerable control panel can be in scope. The first question is not only whether the patch was applied, but whether the environment was checked for session artifacts, admin activity, hosted-asset changes, and ransomware traces during the exposure window.”
27-Common Questions Q&A
| Question | Answer |
|---|---|
| Is CVE-2026-41940 a WordPress vulnerability? | No. This is a critical authentication bypass in cPanel & WHM and WP Squared, not a WordPress core, plugin, or theme vulnerability. WordPress is only one common downstream workload. The same control panel can manage many kinds of websites, CMS platforms, databases, mailboxes, domains, customer accounts, and hosted services. 3 13 17 18 |
| Why should website owners care if the flaw is not in their website software? | Because the vulnerable layer can sit above the sites. cPanel & WHM can manage websites, domains, databases, email, files, accounts, and server configuration; compromise of the hosting control plane can cascade into all hosted websites, whether they run WordPress, another CMS, ecommerce software, custom code, or static content. 6 11 17 18 |
| What is the shortest accurate description? | CVE-2026-41940 is a critical authentication bypass in the cPanel & WHM hosting control panel. It is not a WordPress vulnerability and is not limited to WordPress environments. Successful exploitation can give attackers administrative access to the hosting control plane and the websites, databases, files, mail, and customer environments managed through it. 3 6 13 17 |
| Does patching alone close the incident? | Patching is mandatory, but it does not prove the host was clean during the exposure window. Run the vendor detection script, preserve and review session files and access logs, and scope administrative actions, hosted-site changes, ransomware traces, SSH-key or persistence changes, cPanel template tampering, and hosted-account impact. 3 4 7 31 |
| Do the exposed-instance and telemetry numbers equal confirmed victims? | No. Rapid7 exposed-instance context and Shadowserver telemetry are useful urgency signals, but they are not verified named-victim lists or customer compromise counts. Use them for scoping priority, not victim assertions. 6 8 |
| Who is behind exploitation, and is Icarus involved? | The retained public source set ties exploitation to Sorry ransomware reporting, large-scale scanning/compromise telemetry, and a Mr_Rot13/Filemanager activity stream. 27-Jun-2026 · Newly retained (>24h) QiAnXin XLab attributes one exploitation stream to Mr_Rot13, but that should not be treated as universal attribution for every exposed or compromised cPanel host. The source set still does not attribute CVE-2026-41940 exploitation to Icarus, UNC6395, or another named SaaS-extortion actor. 2 7 8 22 |
| How would a threat actor find a cPanel URL before reconnaissance? | It is usually exposure enumeration, not luck. Threat actors can look for common cPanel and WHM hostnames, common management ports, HTTP titles, TLS certificates, provider fingerprints, passive attack-surface data, search-engine indexed panels, hosting-provider patterns, and previously shared target lists where locally evidenced. The defensive answer is to know where cPanel/WHM is exposed, restrict management access, and require the operator to provide version, patch, and log-review evidence. 3 6 10 17 |
| What is WP Squared? | WP Squared, also referenced as WP2 in the cPanel advisory, is a WebPros/cPanel product included in the affected product family for this CVE. It should be scoped as part of the hosting control plane, not as WordPress core, a WordPress plugin, or a WordPress theme. If a provider uses WP Squared, ask for the fixed build, patch timestamp, service restart, detection-script output, and log review just as you would for cPanel & WHM. 3 6 |
| Can an insurer remotely check whether a policyholder uses cPanel? | Partially. With appropriate authorization, an insurer or assessor can use passive attack-surface data, DNS names such as cpanel, whm, or webmail, common service ports such as 2082/2083/2086/2087/2095/2096, HTTP titles, TLS certificates, and provider fingerprints to identify probable cPanel/WHM exposure. That does not prove patch status or compromise; the policyholder or provider still needs to produce version, patch, detection-script, and log-review evidence. 3 6 10 |
Expansion Research Add
Expansion research was used specifically to prevent a misleading WordPress-only framing. WordPress can be a downstream workload managed through cPanel, but so can other CMS platforms, ecommerce sites, custom websites, mail, files, databases, and customer-hosting workflows. The vulnerability is in the cPanel & WHM / WP Squared control plane.
28-Tier 0 Through Tier 8 Source Summary
| Tier | Checked | Useful Hits | Used | Not Used |
|---|---|---|---|---|
| Tier 0 - Government / CVE authority | 7 | 7 | 7 | 0 |
| Tier 1 - Vendor / CNA / primary advisory | 7 | 4 | 4 | 3 |
| Tier 2 - Practitioner / telemetry / security research | 42 | 28 | 28 | 14 |
| Tier 3 - Corroborating security media | 11 | 2 | 2 | 9 |
| Tier 4 - Community signal | 4 | 1 | 0 | 4 |
| Tier 5 - Custom Source (defined by user) | 0 | 0 | 0 | 0 |
| Tier 6 - Custom Integrations with API/Keys | 1 | 0 | 0 | 1 |
| Tier 7 - Inner Discovery / Carved URLs | 5 | 3 | 3 | 2 |
| Tier 8 - Expansion Research | 6 | 5 | 5 | 1 |
| Total | 83 | 50 | 49 | 34 |
29-Source Deconfliction
| Source Issue | Agreement / Difference | Tension or Contradiction | How To Use It |
|---|---|---|---|
| Vulnerable product vs. downstream workload | Sources identify cPanel & WHM / WP Squared as the affected product, while expansion sources show cPanel is a broader hosting control plane for websites, CMS platforms, mail, databases, files, and customer accounts. | Calling this a WordPress vulnerability would be inaccurate, but calling it unrelated to WordPress would miss one common downstream SMB exposure path. | Say “not a WordPress vulnerability; any cPanel-managed hosted workload, including WordPress, may be downstream affected through vulnerable hosting control panels.” 3 13 17 18 |
| Vulnerability naming | Sources agree this is a critical authentication bypass; practitioner analyses explain the CRLF/session-file handling path. | Executive summaries can over-focus on CRLF and obscure the practical admin-access risk. | Use “authentication bypass” for business audiences and preserve CRLF/session details for technical teams. 1 4 5 6 |
| KEV and exploitation status 28-Jun-2026 · Newly retained (>24h) | CISA alert/catalog JSON records April 30, 2026 as the KEV addition date, with May 3 due date and known ransomware-campaign-use status; cPanel's response separately references May 1 confirmation. | KEV status establishes active exploitation urgency but not every exposed host is compromised, and date references can differ depending on whether the source is the CISA feed or vendor response post. | Use April 30 for official KEV catalog timing, preserve the May 1 cPanel response reference where discussing vendor communications, and validate exposure locally. Freshness: Newly retained (>24h). 2 4 |
| Public exploitability | watchTowr published technical analysis and PoC after vendor patches. | PoC availability increases copycat risk but does not replace local evidence. | Prioritize patch validation, detection-script results, logs, and session artifacts. 5 6 |
| Public PoC artifacts vs. malicious/fake exploit repositories 24-Aug-2026 · Newly retained (>24h) | VulnCheck's August 20 public-PoC curation research identifies a malicious repository that claimed to exploit CVE-2026-41940 and used encoded execution logic to download and run unwanted payloads. | The source improves defensive source-deconfliction, but it is not a new CVE exploit path, activity attribution, victim disclosure, or detection rule body to republish. | Treat unvetted CVE-2026-41940 GitHub/exploit artifacts as potentially malicious until reviewed; do not run opaque encoded code in production or analyst workstations. Freshness: Newly retained (>24h); raw repository and payload details are not republished. 48 |
| Detection script vs. behavior detections 08-Jul-2026 · Newly retained (>24h) | cPanel's vendor script remains the highest-priority local artifact check, while Unfold adds behavior-based session/access-log correlation guidance for exploit mechanics. | Detection teams should not depend only on public PoC strings or one script run; local log schemas, retention windows, and cleanup timing affect what can be proven. | Run the vendor script, preserve session files and access logs, and add behavior detections for abnormal session promotion and cpsess usage without a normal login path. Freshness: Newly retained (>24h). 3 4 28 |
| Exposure vs. victim count | Rapid7 and Shadowserver provide exposure and telemetry context. | 1.5M exposed instances and 44K IP telemetry are not verified named victims. | Use these numbers for urgency and scoping scale, not victim notification claims. 6 8 |
| CrowdSec reconnaissance telemetry vs. compromise proof 20-Jul-2026 · Newly retained (>24h) | CrowdSec adds bounded telemetry for first observed activity, distinct IPs tied to the vulnerability, reconnaissance pressure, dedicated detection coverage, and WAF virtual patching. | CrowdSec's IP count and control guidance improve scoping and defensive validation, but they do not identify named victims or prove every observed source achieved compromise. | Use as activity-cluster and control-evidence context; continue to require fixed-build evidence, vendor-script output, and local log/session review before compromise conclusions. Freshness: Newly retained (>24h). 34 |
| Ransomware linkage 11-Aug-2026 · Newly retained (>24h) | BleepingComputer reports Sorry ransomware as one exploitation outcome; ThreatLocker adds older but newly retained malware-analysis detail for host markers, process/service disruption, SSH propagation attempts, and recovery scoping; China Daily / CCTV News Client reporting attributed to the National Computer Virus Emergency Response Center adds China domestic multi-incident warning detail for cPanel/CVE-2026-41940 initial access, sshd masquerading, service/backup disruption, data theft, AES/RSA encryption, and weak-password SSH lateral movement. | The ransomware linkage does not mean every CVE-2026-41940 compromise followed that path, and malware-analysis or national-warning indicators are not named-victim disclosures. | Mention Sorry ransomware as a known reported outcome, use ThreatLocker and China Daily/CCTV/CVERC detail for bounded hunting and recovery, and still scope other post-exploitation possibilities. Freshness: Newly retained (>24h) for source 45. 7 27 45 |
| Activity clusters vs. named victims | Sources support multiple activity lenses: KEV exploitation, Sorry ransomware reporting, Shadowserver telemetry, public PoC-driven exploitation pressure, early reconnaissance telemetry, and exposed hosting-control-plane scanning. | Those are useful scoping clusters, but they are not public named-victim disclosures. | Use the activity-cluster card for defensive scoping and keep the victim/disclosure matrix reserved for named organizations. 2 5 6 7 8 10 46 |
| Provider notices, resolved provider status, ACSC MSP impact, and end-customer victim lists 30-Jul-2026 · Newly retained (>24h) | Liquid Web, InMotion Hosting, Bluehost, BinaryLane, and KnownHost publish named provider-response evidence tied to CVE-2026-41940, including fleet patching, access restrictions, blocked exceptions, support/remediation activity, customer outreach, customer-environment handling, unmanaged-VPS responsibilities, CentOS 6 migration pressure, backup/log-review guidance, compromise-check categories, provider log-review outcomes, and in Liquid Web's case July 21 monitoring plus July 23 resolution status. Beazley Security adds insurer-adjacent exposure-management and MDR hunt framing; Coalition adds policyholder notification, hosting-provider patch-progress tracking, and on-premises remediation support; ASD's ACSC adds official Australia-facing language that several MSP-managed products were impacted and customer compromise resulted. | Provider-wide, insurer coordination, and national-CERT/MSP impact evidence is valuable for scoping, but it does not identify every affected customer and does not prove all potentially exposed customer environments were compromised. | Use provider, insurer, and ACSC evidence to shape policyholder/provider questions and remediation benchmarks; keep raw customer identities, claim details, raw command bodies, raw log lines, hashes, aggregate support queues, provider exception lists, unnamed MSP/customer claims, and unsupported victim inferences out of public victim claims. Freshness: Newly retained (>24h). 25 26 30 31 32 33 35 36 37 39 |
| Government of Guam/BSP disclosure vs. breach, ransomware, or all-clear proof 18-Aug-2026 · Newly retained (>24h) | Government of Guam, Guam BSP, and DysruptionHub support a named public victim/disclosure row tied to the cPanel-hosted CVE-2026-41940 compromise path, with public web disruption, BSP file/content restoration impact, and DysruptionHub's August 16 presumed-resolved recovery-status revision. | The retained evidence supports presumed recovery, but it does not confirm sensitive personal-information breach, data theft, ransomware encryption, ransom demand, leak threat, named actor attribution, exact final restoration date, government-wide all-clear, complete affected-agency list, or a broader raw victim/customer list. | Use as bounded government-services, hosted-content restoration, and recovery-status evidence; keep breach, ransomware, attribution, all-clear, exact closure-date, and customer-list claims out unless a later reliable source explicitly confirms them. Freshness: Newly retained (>24h). 42 43 44 |
| Mr_Rot13 attribution vs. universal attribution 27-Jun-2026 · Newly retained (>24h) | QiAnXin XLab attributes one exploitation stream to Mr_Rot13 and describes Filemanager backdoor, webshell, SSH-key persistence, login-page tampering, and credential-theft behavior after CVE-2026-41940 exploitation. | The report improves activity-cluster and hunt guidance, but it does not prove that every exposed cPanel/WHM host was compromised by Mr_Rot13 or provide a verified named-victim list. | Use Mr_Rot13/Filemanager as a bounded campaign/hunting lens and keep broad victim or universal-attribution claims out of the executive summary. 22 |
| Official CVE metadata changes 26-Jun-2026 · Newly retained (>24h) | NVD's June 17 change history adds CISA SSVC metadata and expanded VulnCheck affected-record detail that aligns with the page's emergency-risk framing. | The June 17 metadata is newly retained by this monitor but older than 24 hours; it should not be presented as a fresh breaking update. | Label as Newly retained (>24h) and use it to reinforce active exploitation, automatable exploitation, total technical impact, and branch-specific affected-version scoping. 1 |
| Named targets vs. confirmed victims 26-Jun-2026 · Newly retained (>24h) | Ctrl-Alt-Intel publicly names several government/military entities as targets of CVE-2026-41940 public-PoC use by an unknown actor. | The same source does not establish that every named target was compromised, suffered ransomware impact, or issued a victim statement. | Populate the matrix as reported targeting/attempted exploitation only; do not call the named entities confirmed breached victims without later source confirmation. 21 |
| Censys activity telemetry vs. victimology 26-Jun-2026 · Newly retained (>24h) | Censys adds useful activity-cluster evidence for a cPanel-concentrated malicious-host spike, Mirai-pattern behavior, and .sorry open-directory telemetry. | Censys host counts and open-directory observations are not organization-level victim disclosures. | Use for scoping botnet/ransomware checks and exposure urgency; keep it out of the named-victim matrix except as a boundary caveat. 20 |
| WAF coverage vs. patch status 28-Jun-2026 · Newly retained (>24h) | Cloudflare published an emergency managed WAF rule for CVE-2026-41940-related cPanel & WHM authentication-bypass traffic and still recommended official vendor patches. | WAF coverage can reduce exploit traffic or add logs for assets in path, but it does not prove the underlying cPanel & WHM / WP Squared service is patched or uncompromised. | Treat WAF rule status and logs as compensating-control evidence only; continue to require fixed-build, restart, detection-script, and log-review evidence. Freshness: Newly retained (>24h). 23 |
| Shadowserver report tags vs. victimology 28-Jun-2026 · Newly retained (>24h) | Shadowserver's compromised-website report page ties CVE-2026-41940-related cPanel/Roundcube compromise reporting to sorry-ransomware, whmstealer, and mr-rot13 tags. | Those tags improve routing, hunting, and provider notification workflows, but they are still not publishable named-victim evidence. | Use tags for authorized network follow-up and defensive scoping; do not republish raw event lists or infer named victims from aggregate reporting. Freshness: Newly retained (>24h). 24 |
| Shadowserver dashboard row vs. victimology or attribution 13-Aug-2026 · Newly retained; undated | Shadowserver's embedded exploited-vulnerabilities dashboard result for August 13, 2026 shows CVE-2026-41940 still present in current exploit telemetry, with 98 last-day unique IPs, 134 seven-day average, 164 thirty-day average, 259 ninety-day average, and known ransomware-campaign-use flag. | The dashboard row improves current exploit-pressure tracking, but it is not a named-victim disclosure, successful-compromise count, actor attribution, or proof of a new exploit wave. | Use as bounded current telemetry for provider/SOC prioritization and log/WAF correlation. Freshness: Newly retained (publication date not visible). 41 |
| Web-inject activity vs. cPanel compromise proof 13-Jul-2026 · Newly retained (>24h) | Proofpoint adds network-telemetry evidence that CVE-2026-41940 exploitation appeared in multi-actor mass exploitation and in compromised-website web-inject chains such as TA569/SocGholish. | The source improves activity-cluster mapping, but it does not name victim organizations, prove every affected cPanel host was used for web injects, or universally attribute CVE-2026-41940 exploitation to TA569. | Use Proofpoint to add hosted-site integrity, redirect, injected-script, and traffic-delivery checks to scoping playbooks. Freshness: Newly retained (>24h). 29 |
| GitHub Actions abuse vs. package-consumer infection 24-Jul-2026 · Newly retained (>24h) | Socket adds evidence that compromised GitHub repositories and GitHub-hosted Actions runners were abused as distributed infrastructure for CVE-2026-41940 scanning/exploitation attempts and credential harvesting against cPanel/WHM targets. | The affected Packagist development versions reflected malicious workflow artifacts synchronized from compromised repositories, but Socket says ordinary package installation did not execute the workflows. Matching workflow-file counts and maintainer/package identifiers also are not a named organization/company victim list. | Use Socket to add CI/CD workflow review, Actions-log preservation, runner egress monitoring, secret rotation, and lockfile/source-reference checks to scoping while keeping raw infrastructure, exploit commands, and unsupported victim inferences out of the public brief. Freshness: Newly retained (>24h). 38 |
| Imperva WAF telemetry vs. compromise proof 29-Jul-2026 · Newly retained (>24h) | Imperva adds customer-environment telemetry showing nearly 4,000 attack requests across 15 industries and 17 countries, with US sites representing almost 70% of observed attacks, plus WAF protection guidance. | Attack-request telemetry improves exposure and control scoping, but it does not name victims, prove successful compromise, or replace cPanel fixed-build and forensic evidence. | Use Imperva to ask WAF teams for protection status, event-history preservation, and correlation against WHM/cPanel session and access logs. Freshness: Newly retained (>24h). 40 |
| Pre-advisory probe telemetry vs. exploitation proof 15-Aug-2026 · Newly retained (>24h) | HoneyLabs adds source-backed evidence that at least one focused source checked the cPanel/WHM login path before the vendor advisory and before broad post-publication probing. | HoneyLabs explicitly says the observed pre-publication request was not exploit-shaped and cannot distinguish a researcher testing unpublished detection from an attacker with early vulnerability knowledge. | Use as bounded early-reconnaissance and retrospective log-review evidence only; do not convert it into confirmed exploitation, actor attribution, victim evidence, or a new campaign name. Freshness: Newly retained (>24h). 46 |
| HoneyLabs live CVE telemetry vs. victimology or campaign proof 25-Aug-2026 · Newly retained; undated | HoneyLabs' live CVE dataset adds current source-backed scanning telemetry for CVE-2026-41940, including 24-hour and seven-day event and unique-IP counts with last_seen August 25, 2026. | The live row does not publish victim organizations, prove successful compromise, identify a threat actor, or establish a new ransomware/botnet/campaign name. | Use as bounded current exploit-pressure telemetry for provider/SOC prioritization and local log correlation. Freshness: Newly retained (publication date not visible). 47 |
| Threat actor attribution | Sources support exploitation, KEV status, public PoC, malicious-PoC source-deconfliction, Shadowserver telemetry/report tags/dashboard activity, HoneyLabs early-probe and live CVE telemetry, CrowdSec and Imperva reconnaissance/customer-environment telemetry, Socket GitHub Actions abuse infrastructure, Sorry ransomware reporting, China domestic Sorry ransomware warning detail, whmstealer report tags, a Mr_Rot13/Filemanager activity stream, Proofpoint's TA569/SocGholish web-inject scoping lens, and Government of Guam/BSP victim/disclosure impact. | The retained evidence does not attribute this CVE to Icarus/UNC6395 or another named SaaS-extortion actor, and Mr_Rot13, TA569/SocGholish, the Socket-observed CI/CD-abuse actor, current dashboard activity, HoneyLabs telemetry, the China domestic warning, the malicious-PoC example, or the Guam disclosure should not be treated as responsible for all exploitation. | Keep attribution bounded to the specific source-backed activity stream, report tag, dashboard telemetry row, reported ransomware outcome, national warning, HoneyLabs telemetry category, malicious-PoC source-deconfliction example, or named disclosure. 2 7 8 22 24 29 34 38 40 41 42 43 44 45 46 47 48 |
| Remote checks vs. proof 20-Jul-2026 · Newly retained (>24h) | Attack-surface sources support identifying exposed cPanel/WHM-like services from outside the network, and Beazley Security explicitly frames perimeter exposure management plus MDR hunts as response support. | External checks can suggest cPanel usage, but cannot prove patch status, detection-script results, or absence of compromise. | Use remote findings to prioritize policyholder/provider outreach, then request version, patch, log, detection, exposure-management, and MDR hunt evidence. Freshness: Newly retained (>24h). 3 6 10 35 |
30-About the Contributors
| Contributor | Role | Value To This Brief |
|---|---|---|
| NVD, CISA, CVE.org, VulnCheck, and cPanel | Authoritative CVE, KEV, CNA, and vendor record | Anchor the identity, affected products, fixed versions, KEV timing, ransomware-use flag, and vendor response posture. 1 2 3 4 13 14 |
| watchTowr Labs, Rapid7, VulnCheck, Unfold Security, CrowdSec, Imperva, Socket, HoneyLabs, Picus, CyCognito, and Qualys | Technical analysis, detection, and exposure framing | Explain exploit mechanics, public PoC availability, malicious-PoC source-deconfliction, behavior-based detection opportunities, reconnaissance/detection telemetry, WAF/customer-environment control evidence, GitHub Actions abuse and credential-harvesting infrastructure, HoneyLabs early-probing methodology and live CVE telemetry, exposed-instance context, and control-plane blast radius. 5 6 9 10 11 28 34 38 40 46 47 48 |
| Shadowserver, HoneyLabs, Censys, Ctrl-Alt-Intel, QiAnXin XLab, Cloudflare, Imperva, Proofpoint, Beazley Security, ACSC, China Daily/CCTV/CVERC reporting, Government of Guam/BSP, DysruptionHub, and hosting-provider notices | Telemetry, activity clusters, targeting, and compensating controls | Add source-backed evidence for compromise telemetry, current exploit-dashboard activity, HoneyLabs early-probe and live CVE telemetry, activity tags, named-target caveats, Mr_Rot13/Filemanager hunting, WAF mitigation/customer-telemetry context, compromised-website web-inject activity mapping, insurer scoping, national-CERT MSP/customer-impact scoping, China domestic Sorry ransomware warning detail, named Government of Guam/BSP disclosure impact, and provider-response patterns. 8 20 21 22 23 24 29 35 36 39 40 41 42 43 44 45 46 47 |
| BleepingComputer, TechRadar, and framework sources | Stakeholder framing and ATT&CK mapping | Support ransomware-impact framing, accessible explanation for non-technical stakeholders, and defensive mapping language. 7 12 15 16 |
31-Source Weighting / Relevance
| Source Tier | Use In This Brief | Publication Boundary |
|---|---|---|
| Tier 0 / Tier 1 | Controls CVE identity, KEV status, fixed builds, vendor instructions, affected-version ranges, official response language, and official named-disclosure evidence such as Government of Guam/BSP. | Use for facts that must survive legal, client, and provider challenge. |
| Tier 2 | Adds exploit mechanics, telemetry, WAF mitigation context, activity clusters, detection/hunting value, web-inject scoping signals, and source-reconciled incident/victimology profiles. | Use when it materially improves scoping or action; keep raw operational details out of broad stakeholder copy. |
| Tier 3 | Helps explain ransomware linkage and stakeholder urgency when corroborated by stronger sources. | Do not let media-only claims override NVD, CISA, vendor, CNA, or primary research. |
| Tier 8 / Expansion Research | Clarifies cPanel as a hosting control plane and prevents inaccurate WordPress-only framing. | Use for context, not as primary exploitation proof. |
32-Additional IntelliOS Threat Intel Products on This Topic
33-Notes
Create an account and sign-in to use this card.
Record your personal notes and comments in this card related to this brief.
35-Version Change Log
| Version | Date | Change |
|---|---|---|
| v1.0 | 23-Jun-2026 | Initial CVE / Exploit Watch Brief created from NVD, CISA KEV, cPanel, watchTowr, Rapid7, BleepingComputer, Shadowserver, and supporting sources. |
| v1.1 | 25-Jun-2026 Revised | Clarified pre-recon target discovery for cPanel/WHM endpoints; clarified WP Squared / WP2 as an affected WebPros/cPanel hosting-control-plane product; added AI Agent #3 monitor metadata, delta rules, and scheduled monitoring status. |
| v1.2 | 25-Jun-2026 Added | Added a dedicated Victim Matrix card so future AI Monitoring Agent runs can populate named public victim organizations only when reliable public sources specifically support them. |
| v1.3 | 25-Jun-2026 Added | Added a dedicated Associated Campaigns / Activity Clusters card and monitor rules so exploitation clusters, ransomware associations, telemetry clusters, and public PoC-driven activity can be tracked separately from named victim disclosures. |
| v1.4 | 25-Jun-2026 Revised | Strengthened the IOCs / Observables card with a forensicator-focused compromise proof matrix, explicitly distinguishing the absence of a universal public IOC blocklist from local evidence needed to prove or refute compromise. |
| v1.5 | 26-Jun-2026 Newly retained | AI Monitoring Agent run at 10:02 AM ET retained NVD's June 17 metadata update, Censys May 1 activity-cluster telemetry, and Ctrl-Alt-Intel May 2 public targeting reporting. Added named-target caveats to the Public Victim / Disclosure Matrix, revised Associated Campaigns / Activity Clusters for Mirai-pattern and targeted public-PoC activity, updated Timeline, Real World Examples, Source Deconfliction, Citations, and PANDA index timestamps. No Freshly reported (<24h) source was identified. |
| v1.6 | 27-Jun-2026 Newly retained | AI Monitoring Agent run at 10:02 AM ET retained QiAnXin XLab's May 11 Mr_Rot13/Filemanager activity-cluster reporting as Newly retained (>24h). Revised Associated Campaigns / Activity Clusters, Timeline, Real World Examples, IOCs / Observables, Detection & Hunting, TTPs, Source Deconfliction, Public Victim / Disclosure Matrix caveat, AI Agent Delta Updates, Citations, and PANDA index timestamps. No Freshly reported (<24h) source or new named victim organization was identified. |
| v1.7 | 28-Jun-2026 Newly retained | AI Monitoring Agent run at 10:02 AM ET retained CISA KEV JSON details, Cloudflare's April 30 emergency WAF release, and Shadowserver's compromised-website report tags as Newly retained (>24h). Corrected official KEV timing to April 30, added May 3 due-date and known-ransomware-use context, added compensating-control guidance, revised Associated Campaigns / Activity Clusters for sorry-ransomware/whmstealer/mr-rot13 report tags, updated Timeline, Real World Examples, Public Victim / Disclosure Matrix caveat, Source Deconfliction, Citations, and PANDA index timestamps. No Freshly reported (<24h) source or new named victim organization was identified. |
| v1.7 | 29-Jun-2026 10:03 AM ET | AI Monitoring Agent checked public sources; no source-backed content update identified. No version increment; no findings added, modified, subtracted, or newly qualified. Named-victim search found no reliable public organization or company confirmed compromised by CVE-2026-41940, and associated-campaign/activity-cluster search found no new or changed source-backed cluster. PANDA index date updated to Updated Jun 29, 2026. |
| v1.7 | 30-Jun-2026 10:01 AM ET | AI Monitoring Agent checked public sources; no source-backed content update identified. No version increment; no findings added, modified, subtracted, or newly qualified. Named-victim search found no reliable public organization or company confirmed compromised by CVE-2026-41940, and associated-campaign/activity-cluster search found no new or changed source-backed cluster. PANDA index date updated to Updated Jun 30, 2026. |
| v1.8 | 01-Jul-2026 10:02 AM ET Newly retained | AI Monitoring Agent retained Liquid Web's April 28-May 18 status incident and InMotion Hosting's May 26 provider-response report as Newly retained (>24h). Added hosting-provider disclosure and remediation-pattern evidence to Executive Summary, AI Agent Delta Updates, Why It Matters, Insurance Policyholder Scoping Lens, Timeline, Real World Examples, Public Victim / Disclosure Matrix, Associated Campaigns / Activity Clusters, Source Deconfliction, Citations, and PANDA index timestamps. No Freshly reported (<24h) source, new actor/ransomware family, or reliable named end-customer victim list was identified. |
| v1.8 | 02-Jul-2026 10:04 AM ET | AI Monitoring Agent checked public sources; no source-backed content update identified. No version increment; no findings added, modified, subtracted, or newly qualified. Named-victim search found no reliable public organization or company confirmed compromised by CVE-2026-41940, and associated-campaign/activity-cluster search found no new or changed source-backed cluster. PANDA index date updated to Updated Jul 2, 2026. |
| v1.9 | 03-Jul-2026 10:03 AM ET Newly retained | AI Monitoring Agent retained ThreatLocker's May 15 Sorry ransomware analysis as Newly retained (>24h). Added bounded ransomware hunt and recovery detail to Executive Summary, AI Agent Delta Updates, Timeline, Detection & Hunting, Incident Response Playbook Ideas, IOCs / Observables, TTPs, Real World Examples, Public Victim / Disclosure Matrix caveat, Associated Campaigns / Activity Clusters, Source Deconfliction, Citations, and PANDA index timestamps. No Freshly reported (<24h) source, new named victim organization, new actor, or new ransomware family was identified. |
| v1.9 | 04-Jul-2026 10:02 AM ET | AI Monitoring Agent checked public sources; no source-backed content update identified. No version increment; no findings added, modified, subtracted, or newly qualified. Named-victim search found no reliable public organization or company confirmed compromised by CVE-2026-41940, and associated-campaign/activity-cluster search found no new or changed source-backed cluster. PANDA index date updated to Updated Jul 4, 2026. |
| v1.9 | 05-Jul-2026 10:02 AM ET | AI Monitoring Agent checked public sources; no source-backed content update identified. No version increment; no findings added, modified, subtracted, or newly qualified. Named-victim search found no reliable public organization or company confirmed compromised by CVE-2026-41940, and associated-campaign/activity-cluster search found no new or changed source-backed cluster. PANDA index date updated to Updated Jul 5, 2026. |
| v1.9 | 06-Jul-2026 10:01 AM ET | AI Monitoring Agent checked public sources; no source-backed content update identified. No version increment; no findings added, modified, subtracted, or newly qualified. Named-victim search found no reliable public organization or company confirmed compromised by CVE-2026-41940, and associated-campaign/activity-cluster search found no new or changed source-backed cluster. PANDA index date updated to Updated Jul 6, 2026. |
| v1.9 | 07-Jul-2026 10:04 AM ET | AI Monitoring Agent checked public sources; no source-backed content update identified. No version increment; no findings added, modified, subtracted, or newly qualified. Named-victim search found no reliable public organization or company confirmed compromised by CVE-2026-41940, and associated-campaign/activity-cluster search found no new or changed source-backed cluster. PANDA index date updated to Updated Jul 7, 2026. |
| v1.10 | 08-Jul-2026 10:03 AM ET Newly retained | AI Monitoring Agent retained Unfold Security's May 6 detection research as Newly retained (>24h). Added behavior-based session/access-log correlation guidance to Executive Summary, AI Agent Delta Updates, Timeline, Action Rows, IOCs / Observables, Detection & Hunting, Source Deconfliction, contributor/source weighting context, Citations, and PANDA index timestamps. No Freshly reported (<24h) source, new named victim organization, new activity cluster, new actor, or new ransomware family was identified. |
| v1.10 | 09-Jul-2026 10:03 AM ET | AI Monitoring Agent checked public sources; no source-backed content update identified. No version increment; no findings added, modified, subtracted, or newly qualified. Named-victim search found no reliable public organization or company confirmed compromised by CVE-2026-41940, and associated-campaign/activity-cluster search found no new or changed source-backed cluster. PANDA index date updated to Updated Jul 9, 2026. |
| v1.10 | 10-Jul-2026 10:01 AM ET | AI Monitoring Agent checked public sources; no source-backed content update identified. No version increment; no findings added, modified, subtracted, or newly qualified. Named-victim search found no reliable public organization or company confirmed compromised by CVE-2026-41940, and associated-campaign/activity-cluster search found no new or changed source-backed cluster. PANDA index date updated to Updated Jul 10, 2026. |
| v1.10 | 11-Jul-2026 10:03 AM ET | AI Monitoring Agent checked public sources; no source-backed content update identified. No version increment; no findings added, modified, subtracted, or newly qualified. Named-victim search found no reliable public organization or company confirmed compromised by CVE-2026-41940, and associated-campaign/activity-cluster search found no new or changed source-backed cluster. PANDA index date updated to Updated Jul 11, 2026. |
| v1.10 | 12-Jul-2026 10:02 AM ET | AI Monitoring Agent checked public sources; no source-backed content update identified. No version increment; no findings added, modified, subtracted, or newly qualified. Named-victim search found no reliable public organization or company confirmed compromised by CVE-2026-41940, and associated-campaign/activity-cluster search found no new or changed source-backed cluster. Freshness labels applied to retained sources: none. PANDA index date updated to Updated Jul 12, 2026. |
| v1.11 | 13-Jul-2026 10:03 AM ET Newly retained | AI Monitoring Agent retained Proofpoint's May 27 network-telemetry report as Newly retained (>24h). Added source-backed activity-cluster mapping for multi-actor cPanel exploitation and compromised-website web-inject chains such as TA569/SocGholish. Updated BLUF, Executive Summary, AI Agent Delta Updates, Timeline, Real World Examples, Associated Campaigns / Activity Clusters, Source Deconfliction, Citations, and PANDA index timestamps. No Freshly reported (<24h) source or new named victim organization was identified. PANDA index date updated to Updated Jul 13, 2026. No external email or notification was sent under the current automation no-email policy. |
| v1.11 | 14-Jul-2026 10:02 AM ET | AI Monitoring Agent checked public sources; no source-backed content update identified. No version increment; no findings added, modified, subtracted, or newly qualified. Named-victim search found no reliable public organization or company confirmed compromised by CVE-2026-41940, and associated-campaign/activity-cluster search found no new or changed source-backed cluster. Freshness labels applied to retained sources: none. PANDA index date updated to Updated Jul 14, 2026. No external email or notification was sent under the current automation no-email policy. |
| v1.11 | 15-Jul-2026 10:01 AM ET | AI Monitoring Agent checked public sources; no source-backed content update identified. No version increment; no findings added, modified, subtracted, or newly qualified. Named-victim search found no reliable public organization or company confirmed compromised by CVE-2026-41940, and associated-campaign/activity-cluster search found no new or changed source-backed cluster. Freshness labels applied to retained sources: none. PANDA index date updated to Updated Jul 15, 2026. No external email or notification was sent under the current automation no-email policy. |
| v1.11 | 16-Jul-2026 10:03 AM ET | AI Monitoring Agent checked public sources; no source-backed content update identified. No version increment; no findings added, modified, subtracted, or newly qualified. Named-victim search found no reliable public organization or company confirmed compromised by CVE-2026-41940, and associated-campaign/activity-cluster search found no new or changed source-backed cluster. Freshness labels applied to retained sources: none. PANDA index date updated to Updated Jul 16, 2026. No external email or notification was sent under the current automation no-email policy. |
| v1.12 | 17-Jul-2026 10:11 AM ET Newly retained | AI Monitoring Agent retained Bluehost's July 9 VPS/Dedicated customer guidance and May 6 compromise-check guide as Newly retained (>24h). Added named hosting-provider disclosure evidence and provider-scoped compromise-review categories to Executive Summary, AI Agent Delta Updates, Why It Matters, Action Rows, IOCs / Observables, Detection & Hunting, Insurance Policyholder Scoping Lens, Patch & Mitigation Guidance, Timeline, Real World Examples, Public Victim / Disclosure Matrix, Associated Campaigns / Activity Clusters, Source Deconfliction, Citations, and PANDA index timestamps. No Freshly reported (<24h) source, new named end-customer victim organization, new actor, new ransomware family, or new public PoC-driven exploitation cluster was identified. No external email or notification was sent under the current automation no-email policy. |
| v1.12 | 18-Jul-2026 10:02 AM ET | AI Monitoring Agent checked public sources; no source-backed content update identified. No version increment; no findings added, modified, subtracted, or newly qualified. Named-victim search found no reliable public organization or company confirmed compromised by CVE-2026-41940, and associated-campaign/activity-cluster search found no new or changed source-backed cluster. Freshness labels applied to retained sources: none. PANDA index date updated to Updated Jul 18, 2026. No external email or notification was sent under the current automation no-email policy. |
| v1.13 | 19-Jul-2026 10:04 AM ET Newly retained | AI Monitoring Agent retained InMotion Hosting's May 20 direct customer follow-up and BinaryLane's May 5 provider advisory as Newly retained (>24h). Added provider-response/customer-notice evidence for port-blocking windows, blocked patch exceptions, customer outreach, unmanaged-VPS responsibility, credential/log/account review, detection-script execution, provider remediation-pattern scoping, Public Victim / Disclosure Matrix provider rows, Associated Campaigns / Activity Clusters provider-remediation revision, Source Deconfliction, Citations, and PANDA index timestamps. No Freshly reported (<24h) source, new named end-customer victim organization, new actor, new ransomware family, intrusion set, botnet, exploit wave, or new public PoC-driven exploitation cluster was identified. No external email or notification was sent under the current automation no-email policy. |
| v1.14 | 20-Jul-2026 10:02 AM ET Newly retained | AI Monitoring Agent retained CrowdSec's May 4 telemetry/detection report, Beazley Security's May 2026 insurer-adjacent advisory, and KnownHost's April 28-30 provider response thread as Newly retained (>24h). Added bounded reconnaissance telemetry, CrowdSec detection/WAF virtual-patching control evidence, insurer exposure-management/MDR scoping, KnownHost provider port-blocking, patch-rollout, log-review, and access-attempt context, Public Victim / Disclosure Matrix provider caveats, Associated Campaigns / Activity Clusters reconnaissance and provider-remediation revisions, Source Deconfliction, Citations, and PANDA index timestamps. No Freshly reported (<24h) source, new named end-customer victim organization, new actor, new ransomware family, intrusion set, botnet, exploit wave, or new public PoC-driven exploitation cluster was identified. No external email or notification was sent under the current automation no-email policy. |
| v1.14 | 21-Jul-2026 10:02 AM ET | AI Monitoring Agent checked public sources; no source-backed content update identified. No version increment; no findings added, modified, subtracted, or newly qualified. Named-victim search found no reliable public organization or company confirmed compromised by CVE-2026-41940, and associated-campaign/activity-cluster search found no new or changed source-backed cluster. Freshness labels applied to retained sources: none. PANDA index date updated to Updated Jul 21, 2026. No external email, Gmail, SMTP, Postmark, subscriber-delivery, or notification workflow was used under the current non-negotiable no-email policy. |
| v1.15 | 22-Jul-2026 10:03 AM ET Newly retained | AI Monitoring Agent retained Coalition Security Labs' May 1 insurer/security advisory as Newly retained (>24h). Added policyholder notification, hosting-provider patch-progress tracking, and on-premises remediation support evidence to BLUF, Executive Summary, AI Agent Delta Updates, Insurance Policyholder Scoping Lens, Timeline, Real World Examples, Public Victim / Disclosure Matrix caveat, Associated Campaigns / Activity Clusters provider-remediation pattern, Source Deconfliction, Citations, and PANDA index timestamps. No Freshly reported (<24h) source, new named end-customer victim organization, new actor, new ransomware family, intrusion set, botnet, exploit wave, or new public PoC-driven exploitation cluster was identified. No external email, Gmail, SMTP, Postmark, subscriber-delivery, or notification workflow was used under the current non-negotiable no-email policy. |
| v1.15 | 23-Jul-2026 10:03 AM ET | AI Monitoring Agent checked public sources; no source-backed content update identified. No version increment; no findings added, modified, subtracted, or newly qualified. Named-victim search found no reliable public organization or company confirmed compromised by CVE-2026-41940, and associated-campaign/activity-cluster search found no new or changed source-backed cluster. Freshness labels applied to retained sources: none. PANDA index date updated to Updated Jul 23, 2026. No external email, Gmail, SMTP, Postmark, subscriber-delivery, or notification workflow was used under the current non-negotiable no-email policy. |
| v1.16 | 24-Jul-2026 10:02 AM ET Newly retained | AI Monitoring Agent retained Socket's July 22 GitHub Actions abuse research as Newly retained (>24h). Added source-backed activity-cluster mapping for compromised GitHub repositories and GitHub-hosted Actions runners used as distributed CVE-2026-41940 scanning/exploitation-attempt and credential-harvesting infrastructure against cPanel/WHM targets. Updated BLUF, Executive Summary, AI Agent Delta Updates, Timeline, Action Rows, IOCs / Observables, TTPs, Real World Examples, Public Victim / Disclosure Matrix caveat, Associated Campaigns / Activity Clusters, Source Deconfliction, contributor/source weighting context, Citations, and PANDA index timestamps. No Freshly reported (<24h) source, new named organization/company victim, new ransomware family, or universal attribution claim was identified. PANDA index date updated to Updated Jul 24, 2026. No external email, Gmail, SMTP, Postmark, subscriber-delivery, or notification workflow was used under the current non-negotiable no-email policy. |
| v1.16 | 25-Jul-2026 10:01 AM ET | AI Monitoring Agent checked public sources; no source-backed content update identified. No version increment; no findings added, modified, subtracted, or newly qualified. Named-victim search found no reliable public organization or company confirmed compromised by CVE-2026-41940, and associated-campaign/activity-cluster search found no new or changed source-backed cluster. Freshness labels applied to retained sources: none. PANDA index date updated to Updated Jul 25, 2026. No external email, Gmail, SMTP, Postmark, subscriber-delivery, or notification workflow was used under the current non-negotiable no-email policy. |
| v1.16 | 26-Jul-2026 10:04 AM ET | AI Monitoring Agent checked public sources; no source-backed content update identified. No version increment; no findings added, modified, subtracted, or newly qualified. Named-victim search found no reliable public organization or company confirmed compromised by CVE-2026-41940, and associated-campaign/activity-cluster search found no new or changed source-backed cluster. Freshness labels applied to retained sources: none. PANDA index date updated to Updated Jul 26, 2026. No external email, Gmail, SMTP, Postmark, subscriber-delivery, or notification workflow was used under the current non-negotiable no-email policy. |
| v1.17 | 27-Jul-2026 10:03 AM ET Newly retained | AI Monitoring Agent retained ASD ACSC's May 1 national-CERT advisory as Newly retained (>24h). Added Australia active-exploitation and unnamed MSP-managed customer-compromise scoping evidence to BLUF, Executive Summary, AI Agent Delta Updates, Timeline, Action Rows, Real World Examples, Public Victim / Disclosure Matrix caveat, Associated Campaigns / Activity Clusters, Source Deconfliction, contributor/source weighting context, Citations, and PANDA index timestamps. No Freshly reported (<24h) source, new named organization/company victim, new actor, new ransomware family, intrusion set, botnet, exploit wave, or universal attribution claim was identified. PANDA index date updated to Updated Jul 27, 2026. No external email, Gmail, SMTP, Postmark, subscriber-delivery, or notification workflow was used under the current non-negotiable no-email policy. |
| v1.17 | 28-Jul-2026 10:02 AM ET | AI Monitoring Agent checked public sources; no source-backed content update identified. No version increment; no findings added, modified, subtracted, or newly qualified. Named-victim search found no reliable public organization or company confirmed compromised by CVE-2026-41940, and associated-campaign/activity-cluster search found no new or changed source-backed cluster. Freshness labels applied to retained sources: none. VulnCheck XDB's July 26 exploit-repository row was reviewed as exploit-code indexing and not retained as a defensive delta. PANDA index date confirmed as Updated Jul 28, 2026. No external email, Gmail, SMTP, Postmark, subscriber-delivery, or notification workflow was used under the current non-negotiable no-email policy. |
| v1.18 | 29-Jul-2026 10:02 AM ET Newly retained | AI Monitoring Agent retained Imperva Threat Research's April 30 WAF/customer-environment telemetry as Newly retained (>24h). Added bounded evidence for nearly 4,000 observed CVE-2026-41940 attack requests across 15 industries and 17 countries, with US sites accounting for almost 70% of observed attacks, plus WAF protection and log-review scoping. Updated BLUF, Executive Summary, AI Agent Delta Updates, Timeline, Patch & Mitigation Guidance, Real World Examples, Public Victim / Disclosure Matrix caveat, Associated Campaigns / Activity Clusters, Source Deconfliction, contributor/source weighting context, Citations, and PANDA index timestamps. No Freshly reported (<24h) source, reliable named public victim organization, new actor, new ransomware family, intrusion set, botnet, exploit wave, or universal attribution claim was identified. PANDA index date updated to Updated Jul 29, 2026. No external email, Gmail, SMTP, Postmark, subscriber-delivery, or notification workflow was used under the current non-negotiable no-email policy. |
| v1.19 | 30-Jul-2026 10:04 AM ET Newly retained | AI Monitoring Agent retained Liquid Web's July 21 monitoring update and July 23 resolved status on the existing cPanel/WHM provider incident as Newly retained (>24h). Revised AI Agent Delta Updates, Executive Summary/provider narrative, Timeline, Insurance / Policyholder Scoping Lens, Real World Examples, Public Victim / Disclosure Matrix provider caveat, Associated Campaigns / Activity Clusters provider-remediation pattern, Source Deconfliction, Citations/source freshness, and PANDA index timestamps. Freshly reported (<24h): none. Newly retained (publication date not visible): none. No reliable named end-customer victim organization, new actor, ransomware family, intrusion set, botnet, exploit wave, public PoC-driven campaign name, or universal clean-state/compromise claim was identified. No external email, Gmail, SMTP, Postmark, subscriber-delivery, or notification workflow was used under the current non-negotiable no-email policy. |
| v1.20 | 31-Jul-2026 10:02 AM ET Newly retained | AI Monitoring Agent retained Shadowserver's embedded July 30 top exploited-vulnerabilities dashboard row for CVE-2026-41940 as Newly retained (publication date not visible). Added bounded current exploit-pressure telemetry: rank 18, 114 last-day unique IPs, 196 seven-day average unique IPs, KEV status, and known ransomware-campaign-use flag. Updated AI Agent Delta Updates, Exploit Watch Snapshot, Timeline, Public Victim / Disclosure Matrix caveat, Associated Campaigns / Activity Clusters, Source Deconfliction, contributor/source weighting context, Citations, and PANDA index timestamps. Freshly reported (<24h): none. Newly retained (>24h): none. No reliable named end-customer victim organization, new actor, ransomware family, intrusion set, botnet, exploit wave, public PoC-driven campaign name, or successful-compromise count was identified. No external email, Gmail, SMTP, Postmark, subscriber-delivery, or notification workflow was used under the current non-negotiable no-email policy. |
| v1.20 | 01-Aug-2026 10:03 AM ET | AI Monitoring Agent checked public sources; no source-backed content update identified. No version increment; no findings added, modified, subtracted, or newly qualified. Named-victim search found no reliable public organization or company confirmed compromised by CVE-2026-41940, and associated-campaign/activity-cluster search found no new or changed source-backed cluster. Freshness labels applied to retained sources: none. PANDA index date updated to Updated Aug 1, 2026. No external email, Gmail, SMTP, Postmark, subscriber-delivery, or notification workflow was used under the current non-negotiable no-email policy. |
| v1.20 | 02-Aug-2026 10:04 AM ET | AI Monitoring Agent checked public sources; no source-backed content update identified. No version increment; no findings added, modified, subtracted, or newly qualified. Named-victim search found no reliable public organization or company confirmed compromised by CVE-2026-41940, and associated-campaign/activity-cluster search found no new or changed source-backed cluster. Freshness labels applied to retained sources: none. Pentest-Tools' July 21 scanner page, Chubb's May insurer alert, Singapore/Canada government advisories, provider notices, social posts, and newer crawls were reviewed but not retained as material deltas. PANDA index date updated to Updated Aug 2, 2026. No external email, Gmail, SMTP, Postmark, subscriber-delivery, or notification workflow was used under the current non-negotiable no-email policy. |
| v1.21 | 03-Aug-2026 10:03 AM ET Newly retained | AI Monitoring Agent retained Guam Homeland Security/OCD's May 2 official response statement, Guam BSP's undated restoration notice, and DysruptionHub's May 2/August 3 incident profile as named Government of Guam/BSP public victim/disclosure evidence tied to the cPanel-hosted CVE-2026-41940 compromise path. Added Government of Guam/BSP operational impact to BLUF, Executive Summary, AI Agent Delta Updates, Timeline, Real World Examples, Public Victim / Disclosure Matrix, Source Deconfliction, contributor/source weighting context, Citations, and PANDA index timestamps. Freshness labels: Newly retained (>24h) for the May 2 official statement and DysruptionHub profile; Newly retained (publication date not visible) for the BSP restoration notice. Associated-campaign/activity-cluster search found no new actor, ransomware family, intrusion set, botnet, exploit wave, or public PoC-driven campaign name; no confirmed sensitive personal-information breach, ransomware encryption, ransom demand, leak threat, named actor attribution, or raw victim/customer list was retained. No external email, Gmail, SMTP, Postmark, subscriber-delivery, or notification workflow was used under the current non-negotiable no-email policy. |
| v1.21 | 04-Aug-2026 10:03 AM ET | AI Monitoring Agent checked public sources; no source-backed content update identified. No version increment; no findings added, modified, subtracted, or newly qualified. Named-victim search found no additional reliable public organization or company newly tied to confirmed CVE-2026-41940 exploitation, ransomware impact, hosted-site compromise, provider notice, or customer notice beyond the retained Government of Guam/BSP row. Associated-campaign/activity-cluster search found no new or changed source-backed cluster. Freshness labels applied to retained sources: none. CVE.org API dateUpdated 2026-08-04T03:56:07.892Z and CISA KEV catalog release timestamp 2026-08-03T18:55:09.067Z were reviewed but not retained as material content deltas. PANDA index date updated to Updated Aug 4, 2026. No external email, Gmail, SMTP, Postmark, subscriber-delivery, retry workflow, or notification workflow was used under the current non-negotiable no-email policy. |
| v1.21 | 05-Aug-2026 10:03 AM ET | AI Monitoring Agent checked public sources; no source-backed content update identified. No version increment; no findings added, modified, subtracted, or newly qualified. Named-victim search found no additional reliable public organization or company newly tied to confirmed CVE-2026-41940 exploitation, ransomware impact, hosted-site compromise, provider notice, or customer notice beyond the retained Government of Guam/BSP row. Associated-campaign/activity-cluster search found no new or changed source-backed cluster. Freshness labels applied to retained sources: none. CVE.org API dateUpdated 2026-08-04T03:56:07.892Z, CISA KEV catalog release timestamp 2026-08-04T16:45:52.0783Z, and NVD lastModified 2026-06-17T10:47:13.957 were reviewed but not retained as material content deltas. The separate CVE-2026-58048 cPanel database-privilege-escalation advisory/news cycle was reviewed as cPanel/WP Squared deconfliction and not retained as a CVE-2026-41940 delta. PANDA index date updated to Updated Aug 5, 2026. No external email, Gmail, SMTP, Postmark, subscriber-delivery, retry workflow, or notification workflow was used under the current non-negotiable no-email policy. |
| v1.21 | 06-Aug-2026 10:03 AM ET | AI Monitoring Agent checked public sources; no source-backed content update identified. No version increment; no findings added, modified, subtracted, or newly qualified. Named-victim search found no additional reliable public organization or company newly tied to confirmed CVE-2026-41940 exploitation, ransomware impact, hosted-site compromise, provider notice, or customer notice beyond the retained Government of Guam/BSP row. Associated-campaign/activity-cluster search found no new or changed source-backed cluster. Freshness labels applied to retained sources: none. CISA KEV catalog release timestamp 2026-08-06T12:26:27.015Z, CVE.org API dateUpdated 2026-08-04T03:56:07.892Z, and NVD lastModified 2026-06-17T10:47:13.957 were reviewed; the CISA catalog timestamp advanced but the CVE-2026-41940 row did not materially change. Search also reviewed eSentire, Mallory exploit-project indexing, DysruptionHub recrawl, social reposts, exploit-code indexes, scanner pages, and SEO/security-news rewrites without retaining a material delta. PANDA index date updated to Updated Aug 6, 2026. No external email, Gmail, SMTP, Postmark, subscriber-delivery, retry workflow, or notification workflow was used under the current non-negotiable no-email policy. |
| v1.21 | 07-Aug-2026 10:03 AM ET | AI Monitoring Agent checked public sources; no source-backed content update identified. No version increment; no findings added, modified, subtracted, or newly qualified. Named-victim search found no additional reliable public organization or company newly tied to confirmed CVE-2026-41940 exploitation, ransomware impact, hosted-site compromise, provider notice, or customer notice beyond the retained Government of Guam/BSP row. Associated-campaign/activity-cluster search found no new or changed source-backed cluster. Freshness labels applied to retained sources: none. CISA KEV catalog release timestamp 2026-08-06T18:15:23.8295Z, CVE.org API dateUpdated 2026-08-04T03:56:07.892Z, and NVD lastModified 2026-06-17T10:47:13.957 were reviewed; the CISA catalog timestamp advanced but the CVE-2026-41940 row did not materially change. Search also reviewed Bitsight, eSentire, Dataminr, Trend Micro, SecurityWeek, Cybersecurity Dive, Cato Networks, Center for Internet Security, Smarthost status/search noise, social reposts, exploit-code indexes, scanner pages, and SEO/security-news rewrites without retaining a material delta. PANDA index date updated to Updated Aug 7, 2026. No external email, Gmail, SMTP, Postmark, subscriber-delivery, retry workflow, or notification workflow was used under the current non-negotiable no-email policy. |
| v1.21 | 08-Aug-2026 10:03 AM ET | AI Monitoring Agent checked public sources; no source-backed content update identified. No version increment; no findings added, modified, subtracted, or newly qualified. Named-victim search found no additional reliable public organization or company newly tied to confirmed CVE-2026-41940 exploitation, ransomware impact, hosted-site compromise, provider notice, or customer notice beyond the retained Government of Guam/BSP row. Associated-campaign/activity-cluster search found no new or changed source-backed cluster. Freshness labels applied to retained sources: none. CISA KEV catalog release timestamp 2026-08-07T16:45:47.0648Z, CVE.org API dateUpdated 2026-08-04T03:56:07.892Z, and NVD lastModified 2026-06-17T10:47:13.957 were reviewed; the CISA catalog timestamp advanced but the CVE-2026-41940 row did not materially change. Search also reviewed SecPod, CybelAngel, SecurityAffairs, ColorTokens, Skynet Hosting, webhosting.today, DysruptionHub registry/profile recrawls, official vendor pages, social reposts, exploit-code indexes, scanner pages, and SEO/security-news rewrites without retaining a material delta. PANDA index date updated to Updated Aug 8, 2026. No external email, Gmail, SMTP, Postmark, subscriber-delivery, retry workflow, or notification workflow was used under the current non-negotiable no-email policy. |
| v1.22 | 09-Aug-2026 10:01 AM ET Newly retained | AI Monitoring Agent retained Shadowserver's embedded August 8 top exploited-vulnerabilities dashboard row for CVE-2026-41940 as Newly retained (publication date not visible). Added bounded current exploit-pressure telemetry: rank 14, 151 last-day unique IPs, 190 seven-day average, 167 thirty-day average, 266 ninety-day average, 1,099 connections, KEV status, and known ransomware-campaign-use flag. Updated AI Agent Delta Updates, Exploit Watch Snapshot, Timeline, Associated Campaigns / Activity Clusters, Source Deconfliction, Citations/source freshness, and PANDA index timestamps. Freshly reported (<24h): none. Newly retained (>24h): none. No additional reliable named public victim organization, new actor, ransomware family, intrusion set, botnet, exploit wave, public PoC-driven campaign name, or successful-compromise count was identified. No external email, Gmail, SMTP, Postmark, subscriber-delivery, retry workflow, or notification workflow was used under the current non-negotiable no-email policy. |
| v1.22 | 10-Aug-2026 10:04 AM ET | AI Monitoring Agent checked public sources; no source-backed content update identified. No version increment; no findings added, modified, subtracted, or newly qualified. Named-victim search found no additional reliable public organization or company newly tied to confirmed CVE-2026-41940 exploitation, ransomware impact, hosted-site compromise, provider notice, or customer notice beyond the retained Government of Guam/BSP row. Associated-campaign/activity-cluster search found no new or changed source-backed cluster. Freshness labels applied to retained sources: none. CISA KEV catalog release timestamp 2026-08-07T16:45:47.0648Z, CVE.org API dateUpdated 2026-08-04T03:56:07.892Z, and NVD lastModified 2026-06-17T10:47:13.957 were reviewed with no material row change. Shadowserver's static dashboard shell and public search cache did not expose a newer CVE-specific row suitable for retention. Search also reviewed Bitsight, SecPod, Malwarebytes, Trend Micro, hosting-provider notices, victim/disclosure searches, social reposts, exploit-code indexes, scanner pages, and SEO/security-news rewrites without retaining a material delta. PANDA index date updated to Updated Aug 10, 2026. No external email, Gmail, SMTP, Postmark, subscriber-delivery, retry workflow, or notification workflow was used under the current non-negotiable no-email policy. |
| v1.23 | 11-Aug-2026 10:02 AM ET Newly retained | AI Monitoring Agent retained China Daily / CCTV News Client reporting attributed to the National Computer Virus Emergency Response Center and National Engineering Laboratory as Newly retained (>24h). Added China-focused Sorry ransomware activity-cluster detail for multiple domestic attacks against internet-exposed Linux web servers using CNNVD-202604-5641 / CVE-2026-41940, including sshd masquerading, victim/environment profiling, service and backup disruption, data theft, AES/RSA encryption, and weak-password SSH lateral-movement risk. Updated BLUF, Executive Summary, AI Agent Delta Updates, Timeline, Action Rows, Real World Examples, Public Victim / Disclosure Matrix caveat, Associated Campaigns / Activity Clusters, Threat Actor Glossary, Source Deconfliction, contributor/source weighting context, Citations, and PANDA index timestamps. Freshly reported (<24h): none. Newly retained (>24h): source 45. No additional reliable named public victim organization, new actor, new ransomware family, intrusion set, botnet, named exploit wave, public PoC-driven campaign name, or successful-compromise count was identified. No external email, Gmail, SMTP, Postmark, subscriber-delivery, retry workflow, or notification workflow was used under the current non-negotiable no-email policy. |
| v1.23 | 12-Aug-2026 10:02 AM ET | AI Monitoring Agent checked public sources; no source-backed content update identified. No version increment; no findings added, modified, subtracted, or newly qualified. Named-victim search found no additional reliable public organization or company newly tied to confirmed CVE-2026-41940 exploitation, ransomware impact, hosted-site compromise, provider notice, or customer notice beyond the retained Government of Guam/BSP row. Associated-campaign/activity-cluster search found no new or changed source-backed cluster. Freshness labels applied to retained sources: none. CISA KEV catalog release timestamp 2026-08-11T18:59:43.6861Z, CVE.org API dateUpdated 2026-08-11T03:55:30.673Z, and NVD lastModified 2026-06-17T10:47:13.957 were reviewed with no material row change. CERT-In's page footer displayed August 12, 2026, but the CVE-specific note remained duplicative of retained official guidance. Search also reviewed hosting-provider advisories, victim/disclosure searches, activity-cluster searches, social reposts, exploit-code indexes, scanner pages, and SEO/security-news rewrites without retaining a material delta. PANDA index date updated to Updated Aug 12, 2026. No external email, Gmail, SMTP, Postmark, subscriber-delivery, retry workflow, or notification workflow was used under the current non-negotiable no-email policy. |
| v1.24 | 13-Aug-2026 10:03 AM ET Newly retained | AI Monitoring Agent retained DysruptionHub's August 10 Government of Guam/BSP active-recovery update as Newly retained (>24h) and Shadowserver's current exploited-vulnerabilities dashboard row as Newly retained (publication date not visible). Revised BLUF, Executive Summary, Exploit Watch Snapshot, AI Agent Delta Updates, Timeline, Real World Examples, Public Victim / Disclosure Matrix, Associated Campaigns / Activity Clusters, Source Deconfliction, Citations/source freshness, and PANDA index timestamps. Freshly reported (<24h): none. No additional reliable named public victim organization, new actor, new ransomware family, intrusion set, botnet, named exploit wave, public PoC-driven campaign name, successful-compromise count, data-theft finding, ransomware confirmation, or actor attribution was identified. No external email, Gmail, SMTP, Postmark, subscriber-delivery, retry workflow, or notification workflow was used under the current non-negotiable no-email policy. |
| v1.24 | 14-Aug-2026 10:03 AM ET | AI Monitoring Agent checked public sources; no source-backed content update identified. No version increment; no findings added, modified, subtracted, or newly qualified. Named-victim search found no additional reliable public organization or company newly tied to confirmed CVE-2026-41940 exploitation, ransomware impact, hosted-site compromise, provider notice, or customer notice beyond the retained Government of Guam/BSP row. Associated-campaign/activity-cluster search found no new or changed source-backed cluster. Freshness labels applied to retained sources: none. CISA KEV catalog release timestamp 2026-08-11T18:59:43.6861Z, CVE.org API dateUpdated 2026-08-11T03:55:30.673Z, and NVD lastModified 2026-06-17T10:47:13.957 were reviewed with no material row change. Search also reviewed the separate CVE-2026-58048 cPanel database-privilege-escalation news cycle, GitHub exploit-code indexes, scanner pages, ranking pages, social/forum reposts, provider advisories, victim/disclosure searches, and SEO/security-news rewrites without retaining a material delta. PANDA index date updated to Updated Aug 14, 2026. No external email, Gmail, SMTP, Postmark, subscriber-delivery, retry workflow, or notification workflow was used under the current non-negotiable no-email policy. |
| v1.25 | 15-Aug-2026 10:04 AM ET Newly retained | AI Monitoring Agent retained HoneyLabs' July 23 pre-publication WHM login-path probing analysis as Newly retained (>24h). Added bounded early-reconnaissance and historical-log-review evidence to AI Agent Delta Updates, Timeline, Action Rows, Detection & Hunting, Real World Examples, Public Victim / Disclosure Matrix caveat, Associated Campaigns / Activity Clusters, Source Deconfliction, contributor/source weighting context, Citations, and PANDA index timestamps. Freshly reported (<24h): none. No additional reliable named public victim organization, new actor, new ransomware family, intrusion set, botnet, named exploit wave, provider notice, successful-compromise count, or confirmed exploitation finding was identified. CISA KEV catalog release timestamp 2026-08-14T16:34:49.0391Z, CVE.org API dateUpdated 2026-08-11T03:55:30.673Z, and NVD lastModified 2026-06-17T10:47:13.957 were reviewed with no material row change. No external email, Gmail, SMTP, Postmark, subscriber-delivery, retry workflow, or notification workflow was used under the current non-negotiable no-email policy. |
| v1.25 | 16-Aug-2026 10:02 AM ET | AI Monitoring Agent checked public sources; no source-backed content update identified. No version increment; no findings added, modified, subtracted, or newly qualified. Named-victim search found no additional reliable public organization or company newly tied to confirmed CVE-2026-41940 exploitation, ransomware impact, hosted-site compromise, provider notice, or customer notice beyond the retained Government of Guam/BSP row. Associated-campaign/activity-cluster search found no new or changed source-backed cluster. Freshness labels applied to retained sources: none. CISA KEV catalog release timestamp 2026-08-14T16:34:49.0391Z, CVE.org API dateUpdated 2026-08-11T03:55:30.673Z, and NVD lastModified 2026-06-17T10:47:13.957 were reviewed with no material row change. Search also reviewed Guam/BSP follow-up, Socket/Corgea Packagist/GitHub Actions coverage, Shadowserver/dashboard searches, social/forum reposts, exploit-code indexes, scanner pages, provider advisories, victim/disclosure searches, activity-cluster searches, and SEO/security-news rewrites without retaining a material delta. PANDA index date updated to Updated Aug 16, 2026. No external email, Gmail, SMTP, Postmark, subscriber-delivery, retry workflow, or notification workflow was used under the current non-negotiable no-email policy. |
| v1.25 | 17-Aug-2026 10:03 AM ET | AI Monitoring Agent checked public sources; no source-backed content update identified. No version increment; no findings added, modified, subtracted, or newly qualified. Named-victim search found no additional reliable public organization or company newly tied to confirmed CVE-2026-41940 exploitation, ransomware impact, hosted-site compromise, provider notice, or customer notice beyond the retained Government of Guam/BSP row. Associated-campaign/activity-cluster search found no new or changed source-backed cluster. Freshness labels applied to retained sources: none. CISA KEV catalog release timestamp 2026-08-14T16:34:49.0391Z, CVE.org API dateUpdated 2026-08-11T03:55:30.673Z, and NVD lastModified 2026-06-17T10:47:13.957 were reviewed with no material row change. Search also reviewed cPanel/cPanel Security Advisory and response pages, WP Squared references, VulnCheck/NVD/CVE/CISA records, Rapid7, watchTowr, BleepingComputer, Shadowserver/dashboard searches, Bitsight, Beazley, SecPod, Trend Micro, Arctic Wolf, eSentire, GitHub exploit-code indexes, LinkedIn/social reposts, provider advisories, victim/disclosure searches, activity-cluster searches, and SEO/security-news rewrites without retaining a material delta. PANDA index date updated to Updated Aug 17, 2026. No external email, Gmail, SMTP, Postmark, subscriber-delivery, retry workflow, or notification workflow was used under the current non-negotiable no-email policy. |
| v1.26 | 18-Aug-2026 10:01 AM ET Newly retained | AI Monitoring Agent retained DysruptionHub's August 16 Government of Guam/BSP presumed-resolved revision as Newly retained (>24h). Revised BLUF, Executive Summary, AI Agent Delta Updates, Timeline, Real World Examples, Public Victim / Disclosure Matrix, Source Deconfliction, Citations/source freshness, and PANDA index timestamps. Freshly reported (<24h): none. Newly retained (publication date not visible): none. Named-victim search found no newly named victim organization beyond the retained Government of Guam/BSP row; associated-campaign/activity-cluster search found no new actor, ransomware family, intrusion set, botnet, named campaign, exploit wave, provider advisory pattern, or successful-compromise count. CISA KEV catalog release timestamp advanced to 2026-08-17T17:00:24.7655Z with no material CVE-2026-41940 row change; CVE.org API dateUpdated remained 2026-08-11T03:55:30.673Z; NVD lastModified remained 2026-06-17T10:47:13.957. PANDA index date updated to Updated Aug 18, 2026. No external email, Gmail, SMTP, Postmark, subscriber-delivery, retry workflow, or notification workflow was used under the current non-negotiable no-email policy. |
| v1.26 | 19-Aug-2026 10:02 AM ET | AI Monitoring Agent checked public sources; no source-backed content update identified. No version increment; no findings added, modified, subtracted, or newly qualified. Named-victim search found no additional reliable public organization or company newly tied to confirmed CVE-2026-41940 exploitation, ransomware impact, hosted-site compromise, provider notice, or customer notice beyond the retained Government of Guam/BSP row. Associated-campaign/activity-cluster search found no new or changed source-backed cluster. Freshness labels applied to retained sources: none. CISA KEV catalog release timestamp advanced to 2026-08-18T16:52:08.5398Z with no material CVE-2026-41940 row change; CVE.org API dateUpdated remained 2026-08-11T03:55:30.673Z; NVD lastModified remained 2026-06-17T10:47:13.957. Search also reviewed cPanel/cPanel Security Advisory and response pages, WP Squared references, VulnCheck advisory and exploit-database listings, Rapid7, watchTowr, BleepingComputer, Shadowserver/dashboard searches, Mallory exploit-project indexing, hosting-provider advisories, victim/disclosure searches, activity-cluster searches, social/forum reposts, exploit-code indexes, scanner pages, and SEO/security-news rewrites without retaining a material delta. PANDA index date updated to Updated Aug 19, 2026. No external email, Gmail, SMTP, Postmark, subscriber-delivery, retry workflow, or notification workflow was used under the current non-negotiable no-email policy. |
| v1.26 | 20-Aug-2026 10:01 AM ET | AI Monitoring Agent checked public sources; no source-backed content update identified. No version increment; no findings added, modified, subtracted, or newly qualified. Named-victim search found no additional reliable public organization or company newly tied to confirmed CVE-2026-41940 exploitation, ransomware impact, hosted-site compromise, provider notice, or customer notice beyond the retained Government of Guam/BSP row. Associated-campaign/activity-cluster search found no new or changed source-backed cluster. Freshness labels applied to retained sources: none. CISA KEV catalog release timestamp advanced to 2026-08-19T17:00:32.1366Z with no material CVE-2026-41940 row change; CVE.org API dateUpdated remained 2026-08-11T03:55:30.673Z; NVD lastModified remained 2026-06-17T10:47:13.957. Search also reviewed cPanel/cPanel Security Advisory and response pages, WP Squared references, VulnCheck advisory and exploit-database listings, Rapid7, watchTowr, BleepingComputer, Shadowserver/dashboard searches, The Hacker News, TechCrunch, SecurityWeek, Help Net Security, hosting-provider advisories, victim/disclosure searches, activity-cluster searches, social/forum reposts, exploit-code indexes, scanner pages, and SEO/security-news rewrites without retaining a material delta. PANDA index date updated to Updated Aug 20, 2026. No external email, Gmail, SMTP, Postmark, subscriber-delivery, retry workflow, or notification workflow was used under the current non-negotiable no-email policy. |
| v1.27 | 21-Aug-2026 10:01 AM ET Newly retained | AI Monitoring Agent retained HoneyLabs' live CVE scanning telemetry as Newly retained (publication date not visible). Added bounded current exploit-pressure evidence: CVE-2026-41940 listed as actively exploited, 8 events from 4 unique IPs in the 24-hour window, 82 events from 21 unique IPs in the seven-day window, and last_seen August 21, 2026. Updated AI Agent Delta Updates, Exploit Watch Snapshot, Timeline, Public Victim / Disclosure Matrix caveat, Associated Campaigns / Activity Clusters, Source Deconfliction, contributor/source weighting context, Citations/source freshness, and PANDA index timestamps. Freshly reported (<24h): none. Newly retained (>24h): none. No additional reliable named public victim organization, new actor, ransomware family, intrusion set, botnet, named campaign, exploit wave, provider advisory pattern, successful-compromise count, data-theft finding, ransomware confirmation, or actor attribution was identified. CISA KEV catalog release timestamp advanced to 2026-08-21T11:57:27.4632Z with no material CVE-2026-41940 row change; CVE.org API dateUpdated remained 2026-08-11T03:55:30.673Z; NVD lastModified remained 2026-06-17T10:47:13.957. PANDA index date updated to Updated Aug 21, 2026. No external email, Gmail, SMTP, Postmark, subscriber-delivery, retry workflow, or notification workflow was used under the current non-negotiable no-email policy. |
| v1.28 | 22-Aug-2026 10:02 AM ET Newly retained | AI Monitoring Agent retained updated HoneyLabs live CVE scanning telemetry as Newly retained (publication date not visible). Revised bounded current exploit-pressure evidence: CVE-2026-41940 remained actively exploited, with 5 events from 3 unique IPs in the 24-hour window, 82 events from 21 unique IPs in the seven-day window, and last_seen August 22, 2026. Updated AI Agent Delta Updates, Exploit Watch Snapshot, Timeline, Associated Campaigns / Activity Clusters, Source Deconfliction, Citations/source freshness, and PANDA index timestamps. Freshly reported (<24h): none. Newly retained (>24h): none. No additional reliable named public victim organization, new actor, ransomware family, intrusion set, botnet, named campaign, exploit wave, provider advisory pattern, successful-compromise count, data-theft finding, ransomware confirmation, or actor attribution was identified. CISA KEV catalog release timestamp advanced to 2026-08-21T17:46:43.6019Z with no material CVE-2026-41940 row change; CVE.org API dateUpdated remained 2026-08-11T03:55:30.673Z; NVD lastModified remained 2026-06-17T10:47:13.957. PANDA index date updated to Updated Aug 22, 2026. No external email, Gmail, SMTP, Postmark, subscriber-delivery, retry workflow, or notification workflow was used under the current non-negotiable no-email policy. |
| v1.29 | 23-Aug-2026 10:02 AM ET Newly retained | AI Monitoring Agent retained updated HoneyLabs live CVE scanning telemetry as Newly retained (publication date not visible). Revised bounded current exploit-pressure evidence: CVE-2026-41940 remained actively exploited, with 11 events from 8 unique IPs in the 24-hour window, 48 events from 19 unique IPs in the seven-day window, and last_seen August 23, 2026. Updated AI Agent Delta Updates, Exploit Watch Snapshot, Timeline, Associated Campaigns / Activity Clusters, Source Deconfliction, Citations/source freshness, and PANDA index timestamps. Freshly reported (<24h): none. Newly retained (>24h): none. No additional reliable named public victim organization, new actor, ransomware family, intrusion set, botnet, named campaign, exploit wave, provider advisory pattern, successful-compromise count, data-theft finding, ransomware confirmation, or actor attribution was identified. CISA KEV catalog release timestamp remained 2026-08-21T17:46:43.6019Z with no material CVE-2026-41940 row change; CVE.org API dateUpdated remained 2026-08-11T03:55:30.673Z; NVD lastModified remained 2026-06-17T10:47:13.957. PANDA index date updated to Updated Aug 23, 2026. No external email, Gmail, SMTP, Postmark, subscriber-delivery, retry workflow, or notification workflow was used under the current non-negotiable no-email policy. |
| v1.30 | 24-Aug-2026 10:02 AM ET Newly retained | AI Monitoring Agent retained updated HoneyLabs live CVE scanning telemetry as Newly retained (publication date not visible) and VulnCheck's August 20 public-PoC curation research as Newly retained (>24h). Revised bounded current exploit-pressure evidence: CVE-2026-41940 remained actively exploited, with 8 events from 6 unique IPs in the 24-hour window, 47 events from 16 unique IPs in the seven-day window, and last_seen August 24, 2026. Added source-deconfliction guidance that a malicious repository falsely claimed to exploit CVE-2026-41940; raw repository, payload, and execution details were not republished. Updated AI Agent Delta Updates, Exploit Watch Snapshot, Timeline, Public Victim / Disclosure Matrix caveat, Associated Campaigns / Activity Clusters, Source Deconfliction, contributor/source weighting context, Citations/source freshness, and PANDA index timestamps. Freshly reported (<24h): none. No additional reliable named public victim organization, new actor, ransomware family, intrusion set, botnet, named campaign, exploit wave, provider advisory pattern, successful-compromise count, data-theft finding, ransomware confirmation, or actor attribution was identified. CISA KEV catalog release timestamp remained 2026-08-21T17:46:43.6019Z with no material CVE-2026-41940 row change; CVE.org API dateUpdated remained 2026-08-11T03:55:30.673Z; NVD lastModified remained 2026-06-17T10:47:13.957. PANDA index date updated to Updated Aug 24, 2026. No external email, Gmail, SMTP, Postmark, subscriber-delivery, retry workflow, or notification workflow was used under the current non-negotiable no-email policy. |
| v1.31 | 25-Aug-2026 10:01 AM ET Newly retained | AI Monitoring Agent retained updated HoneyLabs live CVE scanning telemetry as Newly retained (publication date not visible). Revised bounded current exploit-pressure evidence: CVE-2026-41940 remained actively exploited, with 5 events from 4 unique IPs in the 24-hour window, 46 events from 15 unique IPs in the seven-day window, and last_seen August 25, 2026. Updated AI Agent Delta Updates, Exploit Watch Snapshot, Timeline, Public Victim / Disclosure Matrix caveat, Associated Campaigns / Activity Clusters, Source Deconfliction, Citations/source freshness, and PANDA index timestamps. Freshly reported (<24h): none. Newly retained (>24h): none. No additional reliable named public victim organization, new actor, ransomware family, intrusion set, botnet, named campaign, exploit wave, provider advisory pattern, successful-compromise count, data-theft finding, ransomware confirmation, or actor attribution was identified. CISA KEV catalog release timestamp advanced to 2026-08-24T18:00:04.7056Z with no material CVE-2026-41940 row change; CVE.org API dateUpdated remained 2026-08-11T03:55:30.673Z; NVD lastModified remained 2026-06-17T10:47:13.957. PANDA index date updated to Updated Aug 25, 2026. No external email, Gmail, SMTP, Postmark, subscriber-delivery, retry workflow, or notification workflow was used under the current non-negotiable no-email policy. |
34-Citations
Baseline Retained Sources
| # | Source | Publisher | Published | Why Used |
|---|---|---|---|---|
| 1 | CVE-2026-41940 Detail | NVD / NIST | April 29, 2026; last modified June 17, 2026 26-Jun-2026 · Newly retained (>24h) | Official vulnerability record for description, CVSS severity, affected cPanel & WHM versions, reference set, and June 17 CISA SSVC / affected-record metadata. Freshness: Newly retained (>24h); retrieved June 26, 2026 at 10:02 AM ET. |
| 2 | Known Exploited Vulnerabilities Catalog: CVE-2026-41940 | CISA | April 30, 2026 28-Jun-2026 · Newly retained (>24h) | Authoritative KEV status, April 30 catalog addition, May 3 due date, and known ransomware-campaign-use flag. Freshness: Newly retained (>24h); retrieved June 28, 2026 at 10:02 AM ET. |
| 3 | Security: CVE-2026-41940 - cPanel & WHM / WP2 Security Update 04/28/2026 | cPanel Support | April 28, 2026; updated May 22, 2026 | Vendor advisory for affected versions, patched builds, required actions, mitigation options, and official detection script guidance. |
| 4 | CVE-2026-41940: Response, Actions and Next Steps | cPanel | May 10, 2026 | Vendor response timeline, root-cause framing in session management, CISA KEV confirmation, and response posture including more than 98% update adoption claim. |
| 5 | The Internet Is Falling Down, Falling Down, Falling Down | watchTowr Labs | April 29, 2026 | Practitioner root-cause analysis and public PoC for the CRLF/session-file authentication bypass chain. |
| 6 | CVE-2026-41940: cPanel & WHM Authentication Bypass | Rapid7 | April 29, 2026; updated May 5, 2026 | Technical overview, impact assessment, fixed-version summary, approximately 1.5 million exposed-instance context, and authenticated-check availability. |
| 7 | Critical cPanel flaw mass-exploited in Sorry ransomware attacks | BleepingComputer | May 2, 2026 | Security-media reporting that ties exploitation to Sorry ransomware, reports widespread exploitation, and cites Shadowserver 44,000-IP compromise telemetry. |
| 8 | Trending query: cPanel/WHM CVE-2026-41940 attacks ongoing | Shadowserver Foundation | April 30, 2026 | Telemetry signal reporting at least 44,000 likely compromised IPs observed scanning Shadowserver honeypots. |
| 9 | CVE-2026-41940 Explained: The cPanel & WHM Authentication Bypass That Hit 1.5M Servers | Picus Security | May 1, 2026 | Practitioner explainer on CRLF injection, session-writer behavior, CISA KEV status, exploitation timing, and session-directory triage. |
| 10 | Emerging Threat: CVE-2026-41940 cPanel & WHM Authentication Bypass via CRLF Injection | CyCognito | May 2026 | Attack-surface perspective on pre-authentication remote authentication bypass and exposure-management implications. |
| 11 | cPanel and WHM Authentication Bypass Vulnerability Exploited in the Wild | Qualys Threat Protection | April 30, 2026 | Practitioner corroboration that exploitation can allow control over host configuration, databases, and managed websites. |
| 12 | Critical cPanel CRLF injection vulnerability puts websites at risk | TechRadar | April 30, 2026 | Corroborating mainstream technology coverage used only for accessible stakeholder framing and patch urgency. |
| 13 | WebPros cPanel and WHM Authentication Bypass via Login Flow | VulnCheck | April 29, 2026 | CNA/advisory source for affected-version ranges, CVE assignment context, and severity metadata. |
| 14 | CVE-2026-41940 CVE Record | CVE.org | April 2026 | Official CVE-listing source for stable identifier and description cross-checking. |
| 15 | T1190 - Exploit Public-Facing Application | MITRE ATT&CK | Living framework | TTP mapping for remote exploitation of internet-facing cPanel/WHM services. |
| 16 | T1486 - Data Encrypted for Impact | MITRE ATT&CK | Living framework | TTP mapping for reported Sorry ransomware encryption impact after exploitation. |
Expansion Research / AI Monitor Delta Sources
| # | Source | Publisher | Published | Why Used |
|---|---|---|---|---|
| 17 | cPanel: Web Hosting Control Panel & Server Management Tools | cPanel | Living product page | Expansion context explaining cPanel as a hosting control panel for managing servers, websites, domains, files, databases, email, and hosted services at scale; used to clarify business impact and hosting-control-plane exposure. |
| 18 | How to Install WordPress with cPanel | cPanel Documentation | Living documentation | Expansion context showing cPanel's WordPress-management relationship through WP Toolkit; used to clarify that CVE-2026-41940 affects the hosting control panel, not WordPress core, themes, or plugins. |
| 19 | Critical cPanel and WHM bug exploited as a zero-day, PoC now available | BleepingComputer | April 30, 2026 | Expansion corroboration that cPanel, WHM, and WP Squared exploitation attempts were reported before public disclosure and that a public PoC became available after patches. |
| 20 | The cPanel Situation Is... | Censys ARC | May 1, 2026 26-Jun-2026 · Newly retained (>24h) | Retained for source-backed activity-cluster detail: Censys observed a May 1 malicious-host surge concentrated on cPanel/WHM, Mirai-pattern activity, and thousands of cPanel/WHM hosts exposing files renamed with the .sorry extension. Freshness: Newly retained (>24h); retrieved June 26, 2026 at 10:02 AM ET. |
| 21 | South-East Asian Military Entities Targeted via cPanel (CVE-2026-41940) | Ctrl-Alt-Intel | May 2, 2026; updated May 2, 2026 26-Jun-2026 · Newly retained (>24h) | Retained for named public targeting and activity-cluster mapping: an unknown actor reportedly used public CVE-2026-41940 PoC tooling against South-East Asian government/military entities and MSP/hosting-provider targets, with no firm attribution. Freshness: Newly retained (>24h); retrieved June 26, 2026 at 10:02 AM ET. |
| 22 | Threat Actor Mr_Rot13 Actively Exploits CVE-2026-41940 for Backdoor Deployment | QiAnXin XLab | May 11, 2026 27-Jun-2026 · Newly retained (>24h) | Retained for source-backed activity-cluster and hunting guidance: XLab attributed one exploitation stream to Mr_Rot13 and described post-exploitation backdoor, webshell, SSH-key, credential-theft, and Filemanager remote-control activity tied to CVE-2026-41940. Freshness: Newly retained (>24h); retrieved June 27, 2026 at 10:02 AM ET. |
| 23 | WAF Release - 2026-04-30 - Emergency | Cloudflare | April 30, 2026 28-Jun-2026 · Newly retained (>24h) | Retained for compensating-control guidance: Cloudflare introduced a managed WAF rule to block cPanel & WHM authentication-bypass traffic related to CVE-2026-41940 while still recommending official vendor patches. Freshness: Newly retained (>24h); retrieved June 28, 2026 at 10:02 AM ET. |
| 24 | Compromised Website Report | Shadowserver Foundation | Last updated June 18, 2026; cPanel tags first added May 4 / May 13, 2026 28-Jun-2026 · Newly retained (>24h) | Retained for reporting and activity-tag guidance: Shadowserver describes cPanel/Roundcube instances attempting honeypot exploitation or seen in darknets as likely CVE-2026-41940-related compromise, with sorry-ransomware, whmstealer, and mr-rot13 tags. Freshness: Newly retained (>24h); retrieved June 28, 2026 at 10:02 AM ET. |
| 25 | Critical Authentication Vulnerability on cPanel/WHM | Liquid Web | Incident updates April 28-July 23, 2026 30-Jul-2026 · Newly retained (>24h) | Retained for hosting-provider customer-notice and remediation evidence: Liquid Web described CVE-2026-41940 patching, support-volume impact, restoration where compromise was evident, July 21 monitoring status, and July 23 incident resolution. Freshness: Newly retained (>24h); original source retained July 1, 2026, July 21/23 status updates retrieved July 30, 2026 at 10:04 AM ET. |
| 26 | InMotion Hosting Keeps Customer Sites Online Through Industry-Wide cPanel Security Response | InMotion Hosting | May 26, 2026 01-Jul-2026 · Newly retained (>24h) | Retained for hosting-provider advisory-pattern evidence: InMotion reported network-edge blocking, fleet patching, 99% of potentially affected customers protected without service disruption, and direct remediation for a small subset of customer environments. Freshness: Newly retained (>24h); retrieved July 1, 2026 at 10:02 AM ET. |
| 27 | Sorry ransomware exploits cPanel authentication bypass | ThreatLocker | May 15, 2026 03-Jul-2026 · Newly retained (>24h) | Retained for source-backed Sorry ransomware activity-cluster and hunting detail: ThreatLocker analyzed Linux encryptor behavior, host-level markers, service/process disruption, SSH propagation attempts, and recovery implications after CVE-2026-41940 compromise. Freshness: Newly retained (>24h); retrieved July 3, 2026 at 10:03 AM ET. |
| 28 | Searching for bulletproof detections in cPanel Land | Unfold Security Research Lab | May 6, 2026 08-Jul-2026 · Newly retained (>24h) | Retained for source-backed detection guidance: Unfold describes behavior-based cPanel session/access-log hunting focused on exploit mechanics instead of brittle PoC strings. Freshness: Newly retained (>24h); retrieved July 8, 2026 at 10:03 AM ET. |
| 29 | More CVEs, Same Playbook: 2026 Vulnerability Exploitation in the Wild | Proofpoint | May 27, 2026 13-Jul-2026 · Newly retained (>24h) | Retained for source-backed activity-cluster refinement: Proofpoint observed CVE-2026-41940 in network telemetry, framed the cPanel exploitation pattern as multi-actor mass exploitation, and tied some compromised-website web-inject chains to threat actors such as TA569/SocGholish. Freshness: Newly retained (>24h); retrieved July 13, 2026 at 10:03 AM ET. |
| 30 | cPanel Vulnerability for VPS & Dedicated Customers | Bluehost | Updated July 9, 2026 17-Jul-2026 · Newly retained (>24h) | Retained for named hosting-provider customer guidance: Bluehost described active exploitation, temporary port restrictions for affected VPS/Dedicated cPanel servers, CentOS 6 migration pressure, backup and log-review advice, and customer-facing outage/data-impact language. Freshness: Newly retained (>24h); retrieved July 17, 2026 at 10:11 AM ET. |
| 31 | Bluehost: CVE-2026-41940: Compromise Check Guide | Bluehost | Updated May 6, 2026 17-Jul-2026 · Newly retained (>24h) | Retained for provider-scoped compromise-review guidance: Bluehost lists checks for patched version validation, Sorry ransomware markers, suspicious process and shell-startup evidence, root SSH-key changes, cPanel template tampering, shell history review, evidence preservation, credential rotation, and hosted-account review. Freshness: Newly retained (>24h); retrieved July 17, 2026 at 10:11 AM ET; raw command bodies and hashes are not republished in this brief. |
| 32 | CVE-2026-41940: Full Technical Details and InMotion's Response | InMotion Hosting | Updated May 20, 2026 19-Jul-2026 · Newly retained (>24h) | Retained for direct hosting-provider customer-notice detail: InMotion described fleet port blocking, patching, blocked exceptions for systems that could not receive updates, customer outreach, credential/log/account review, and detection-script use. Freshness: Newly retained (>24h); retrieved July 19, 2026 at 10:04 AM ET; exploit-chain specifics and raw commands are not republished in this brief. |
| 33 | Critical cPanel/WHM/WP2 Vulnerability - CVE-2026-41940 (Authentication Bypass) | BinaryLane | Last updated May 5, 2026 19-Jul-2026 · Newly retained (>24h) | Retained for provider advisory-pattern detail: BinaryLane described CVE-2026-41940 active exploitation against cPanel servers on its network, provider-side mitigation/notification, and unmanaged-VPS patch-validation responsibilities. Freshness: Newly retained (>24h); retrieved July 19, 2026 at 10:04 AM ET. |
| 34 | CVE-2026-41940: cPanel & WHM Authentication Bypass Puts Millions of Servers at Risk | CrowdSec | May 4, 2026 20-Jul-2026 · Newly retained (>24h) | Retained for telemetry and detection-control detail: CrowdSec reported first observed CVE-2026-41940 activity on April 27, 282 distinct IPs tied to the issue through May 4, a significant reconnaissance campaign, dedicated detection coverage, and WAF virtual patching guidance. Freshness: Newly retained (>24h); retrieved July 20, 2026 at 10:02 AM ET. |
| 35 | Critical Vulnerability in cPanel and WHM Under Active Exploitation (CVE-2026-41940) | Beazley Security | May 2026 20-Jul-2026 · Newly retained (>24h) | Retained for insurer-adjacent scoping: Beazley Security described hosting-provider port blocking, review of internet-exposed self-hosted cPanel, vendor detection-script use, Exposure Management perimeter identification, and MDR threat hunts. Freshness: Newly retained (>24h); retrieved July 20, 2026 at 10:02 AM ET; raw exploit examples are not republished in this brief. |
| 36 | cPanel Zero Day Exploit - Network wide protections in place for cPanel and WHM logins/ports | KnownHost | April 28-30, 2026 20-Jul-2026 · Newly retained (>24h) | Retained for direct hosting-provider response and bounded telemetry: KnownHost described network-level blocking of cPanel, WHM, Webmail, and WebDisk ports, managed-customer patch rollout, access restoration after patching, review of server logs, and a small number of access-attempt findings without active-compromise signs in reviewed cases. Freshness: Newly retained (>24h); retrieved July 20, 2026 at 10:02 AM ET; raw sample log lines are not republished in this brief. |
| 37 | Security Alert: Critical Authentication Bypass Vulnerability in cPanel | Coalition Security Labs | May 1, 2026 22-Jul-2026 · Newly retained (>24h) | Retained for insurer and policyholder coordination evidence: Coalition says it notified impacted policyholders on April 29, worked with policyholders to track hosting-provider patch progress, helped on-premises cPanel/WHM policyholders remediate, and advised businesses that rely on hosting providers to confirm patching directly. Freshness: Newly retained (>24h); retrieved July 22, 2026 at 10:03 AM ET. |
| 38 | Large-Scale GitHub Actions Abuse Powers a Distributed cPanel and WHM Exploitation Campaign | Socket | July 22, 2026 24-Jul-2026 · Newly retained (>24h) | Retained for source-backed activity-cluster mapping: Socket reported compromised GitHub repositories and GitHub-hosted Actions runners used as distributed infrastructure to scan for and attempt CVE-2026-41940 exploitation against cPanel/WHM targets, with server-side credential harvesting and Packagist development versions acting as exposure artifacts rather than the execution path. Freshness: Newly retained (>24h); retrieved July 24, 2026 at 10:02 AM ET. |
| 39 | Active exploitation of cPanel/WHM critical vulnerability | ASD's Australian Cyber Security Centre | First published May 1, 2026; last updated May 1, 2026 27-Jul-2026 · Newly retained (>24h) | Retained for national-CERT/MSP scoping: ASD's ACSC stated it was aware of active exploitation in Australia, warned that several MSP-managed products had been impacted with customer compromise, and advised third-party managed customers to confirm patching and monitoring with their provider. Freshness: Newly retained (>24h); retrieved July 27, 2026 at 10:03 AM ET. |
| 40 | Imperva Customers Protected Against CVE-2026-41940 in cPanel & WHM | Imperva Threat Research | April 30, 2026 29-Jul-2026 · Newly retained (>24h) | Retained for bounded WAF/customer-telemetry and compensating-control evidence: Imperva observed nearly 4,000 CVE-2026-41940 attack requests across 15 industries and 17 countries, with US sites accounting for almost 70% of observed attacks, while still recommending vendor patching and local review. Freshness: Newly retained (>24h); retrieved July 29, 2026 at 10:02 AM ET. |
| 41 | Monitoring - Exploited vulnerabilities: CVE-2026-41940 | Shadowserver Foundation | Dashboard result date August 13, 2026; publication timestamp not visible 13-Aug-2026 · Newly retained; undated | Retained for bounded current exploit-telemetry evidence: Shadowserver's embedded top exploited-vulnerabilities table still showed CVE-2026-41940 current activity for the August 13, 2026 result set, with 98 last-day unique IPs, a 134 seven-day average, 164 thirty-day average, 259 ninety-day average, and known ransomware-campaign-use flag. Freshness: Newly retained (publication date not visible); retrieved August 13, 2026 at 10:03 AM ET. |
| 42 | Government of Guam Activates Cyber Incident Response; Global Vulnerability Under Investigation | Guam Homeland Security / Office of Civil Defense | May 2, 2026 03-Aug-2026 · Newly retained (>24h) | Retained for named public victim/disclosure evidence: the Government of Guam said it activated cyber incident response after a widespread incident linked to a critical vulnerability affecting cPanel-hosted websites, with multiple guam.gov websites potentially affected and no confirmed sensitive personal-information breach at that time. Freshness: Newly retained (>24h); retrieved August 3, 2026 at 10:03 AM ET. |
| 43 | BSP Website Restoration Update | Guam Bureau of Statistics and Plans | Publication date not visible 03-Aug-2026 · Newly retained; undated | Retained for named public operational-impact evidence: BSP's site-wide restoration notice says bsp.guam.gov was among domains compromised during the cPanel-hosted server incident and that most file downloads and embedded content could not be restored while the agency re-uploaded files, datasets, reports, and media. Freshness: Newly retained (publication date not visible); retrieved August 3, 2026 at 10:03 AM ET. |
| 44 | Guam cyber incident disrupts government websites | DysruptionHub | Published May 2, 2026; last updated August 16, 2026 18-Aug-2026 · Newly retained (>24h) | Retained for source reconciliation and CVE-specific victimology: DysruptionHub's August 16 update now treats the Government of Guam/BSP incident as presumed resolved after the BSP restoration warning disappeared and report/data pages were repopulated, while preserving that no government-wide all-clear, final restoration date, data-theft, ransomware, or actor-attribution finding had been published. Freshness: Newly retained (>24h); retrieved August 18, 2026 at 10:01 AM ET. |
| 45 | Warning: Multiple Sorry ransomware attacks found in China | China Daily / CCTV News Client | August 10, 2026 at 20:34 CST / 08:34 AM ET 11-Aug-2026 · Newly retained (>24h) | Retained for national warning and activity-cluster detail: China Daily republished CCTV News Client reporting that attributes a National Computer Virus Emergency Response Center / National Engineering Laboratory warning to multiple domestic Sorry ransomware attacks against internet-exposed Linux web servers, explicitly tying initial access to WebPros cPanel authorization-bypass vulnerability CNNVD-202604-5641 / CVE-2026-41940. Freshness: Newly retained (>24h); retrieved August 11, 2026 at 10:02 AM ET. |
| 46 | The probe that came 17 days before the CVE | HoneyLabs | July 23, 2026 15-Aug-2026 · Newly retained (>24h) | Retained for bounded early-reconnaissance evidence: HoneyLabs reported focused WHM login-path probing 17 days before cPanel's vendor advisory, then explicitly caveated that the observed traffic was not exploit-shaped and could represent either research or attacker reconnaissance. Freshness: Newly retained (>24h); retrieved August 15, 2026 at 10:04 AM ET. |
| 47 | CVEs being scanned for in the wild | HoneyLabs | Live CVE telemetry; source publication timestamp not visible; CVE last_seen August 25, 2026 25-Aug-2026 · Newly retained; undated | Retained for bounded current scanning telemetry: HoneyLabs' live CVE dataset listed CVE-2026-41940 as actively exploited, with 5 events from 4 unique IPs in the 24-hour window and 46 events from 15 unique IPs in the seven-day window, last seen August 25, 2026. Freshness: Newly retained (publication date not visible); retrieved August 25, 2026 at 10:01 AM ET. |
| 48 | Death By 20,000 PoCs | VulnCheck | August 20, 2026 24-Aug-2026 · Newly retained (>24h) | Retained for source-deconfliction and safe-handling guidance: VulnCheck described a malicious repository that claimed to be a CVE-2026-41940 exploit and used nested encoded code to download and execute unwanted payloads. Freshness: Newly retained (>24h); retrieved August 24, 2026 at 10:02 AM ET; raw repository, payload, and execution details are not republished. |
