CVE-2026-41940
cPanel & WHM Authentication Bypass
Research Framing
| Field | Value | |||||||||||||||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| User Topic | CVE-2026-41940 cPanel and WHM / WP Squared authentication bypass: impact on US SMBs, exploitation, KEV status, public PoC, and remediation urgency. | |||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Interpreted Questions | What is the vulnerability, who is exposed, how is it exploited, what evidence supports active exploitation, how urgent is remediation, and what should hosting providers, MSPs, SMBs, and client-facing advisors do first? | |||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Source Coverage |
|
Expansion Research Add
Expansion research clarifies the website-software relationship: cPanel & WHM is a hosting control panel that can manage many hosted workloads, including WordPress, other CMS platforms, custom websites, email, databases, files, and customer accounts. CVE-2026-41940 is not a WordPress core, theme, or plugin vulnerability; WordPress is a common example of downstream impact, not the vulnerable product.17 18
1-Topic
This CVE Watch Brief covers CVE-2026-41940, a critical authentication bypass in cPanel & WHM and WP Squared. The brief is focused on practical exposure validation, exploitation status, public PoC availability, KEV urgency, downstream hosting-control-plane impact, and the evidence responders should preserve before cleanup. 1 2 3 6 13
| Focus | Source-Backed Answer |
|---|---|
| What is the issue? | An unauthenticated attacker may abuse session-management behavior in cPanel & WHM / WP Squared to reach authenticated control-panel state. |
| Who is exposed? | Hosting providers, MSPs, resellers, agencies, and SMBs whose web, mail, database, CMS, or customer-hosting workflows depend on exposed cPanel/WHM or WP Squared infrastructure. |
| Why now? | The CVE is KEV-listed, public exploit material exists, public reporting describes active exploitation and ransomware linkage, and remediation must be paired with compromise scoping. |
2-Persona / Audience Lens
This CVE / Exploit Watch Brief is written for vulnerability-management teams, hosting providers, MSPs, SOC and incident-response teams, cyber insurers, breach counsel, and SMB-facing advisors. It emphasizes immediate exposure validation, patch status, exploitation evidence, detection steps, and plain-language client communication for organizations that may not operate cPanel directly but rely on a hosting provider that does. 3 6 7
3-BLUF
- CVE-2026-41940 is a critical cPanel & WHM / WP Squared authentication bypass with CVSS 9.8 severity and no required credentials or user interaction. 1 3 6 13
- Target discovery can happen before formal reconnaissance through commodity exposure enumeration: common cPanel/WHM hostnames, ports, service fingerprints, provider patterns, passive attack-surface data, and scanning. 3 6 10 17
- This is not a WordPress vulnerability and is not limited to WordPress. It affects the hosting control panel layer used to manage websites, CMS platforms, databases, mail, domains, files, and customer accounts; WordPress sites are one common downstream exposure path. 3 13 17 18
- 28-Jun-2026 · Newly retained (>24h) CISA's official KEV feed records April 30, 2026 as the catalog-addition date, with a May 3 due date and known ransomware-campaign-use flag; cPanel's response separately references May 1 confirmation. Public reporting describes active exploitation, including Sorry ransomware follow-on activity. 2 4 7
- The vulnerability affects cPanel & WHM versions after 11.40 before the applicable fixed builds; WP Squared is fixed at 136.1.7 and later. 3 13
- watchTowr published technical analysis and PoC after vendor patches became available, materially increasing exploit reproducibility. 5 6
- 28-Jun-2026 · Newly retained (>24h) Newly retained defense-side evidence adds Cloudflare emergency WAF rule coverage and Shadowserver compromised-website report tags for sorry-ransomware, whmstealer, and mr-rot13 patterns. 23 24
- 13-Jul-2026 · Newly retained (>24h) Proofpoint adds network-telemetry context that CVE-2026-41940 exploitation followed a multi-actor mass-exploitation pattern and appeared in compromised-website web-inject chains such as TA569/SocGholish. 29
- For exposed systems, patching is necessary but not sufficient: run the vendor detection script, review session/access logs, scope administrator activity, and check for ransomware or web-host compromise. 3 4 7
4-Executive Summary
CVE-2026-41940 is a critical authentication bypass in cPanel & WHM and WP Squared. The vendor describes it as a session-management vulnerability in which one code path that writes session files lacked the sanitization applied elsewhere; under a specially crafted request, an unauthenticated session could be treated as authenticated. The public risk is severe because cPanel & WHM commonly sits on internet-facing hosting infrastructure and can control hosted websites, databases, email, reseller accounts, and server configuration. 3 4 6
The attacker story is straightforward enough for non-technical stakeholders: find an exposed cPanel/WHM service, send a crafted pre-authentication request that manipulates session state, reach privileged control panel functionality, and then use that access to change hosting accounts, alter sites, access databases or files, plant webshells, or deploy ransomware. This is why the brief treats the CVE as a hosting control-plane compromise risk rather than a narrow website bug. 4 5 6 7 11
The “find an exposed service” step is not magic. Threat actors can discover candidate targets through internet-wide scanning, common cPanel/WHM hostnames, common management ports, HTTP and TLS fingerprints, hosting-provider patterns, passive attack-surface data, or target lists when those are present in a particular investigation. WP Squared, also referenced as WP2 in vendor materials, is a WebPros/cPanel product in the affected product family and should be scoped as hosting-control-plane exposure rather than as a WordPress core, plugin, or theme issue. 3 6 10 17
The WordPress connection needs to be stated carefully. cPanel & WHM is a widely used web-hosting control panel for managing websites, CMS platforms, databases, email, domains, files, customer accounts, and server administration. WordPress is a common workload managed through cPanel, but CVE-2026-41940 is not a WordPress vulnerability and not limited to WordPress. Successful exploitation can endanger any hosted assets managed through the same control plane. 6 11 17 18
The exploitation picture is mature enough for emergency handling. cPanel released fixes on April 28, watchTowr published root-cause analysis and PoC on April 29, 28-Jun-2026 · Newly retained (>24h) CISA's official KEV feed records an April 30 catalog addition, May 3 due date, and known ransomware-campaign-use flag, while cPanel's response references May 1 confirmation. BleepingComputer reported exploitation tied to Sorry ransomware on May 2. Shadowserver also reported at least 44,000 likely compromised IPs seen scanning honeypots. 2 5 7 8
26-Jun-2026 · Newly retained (>24h) AI Monitoring Agent run at June 26, 2026 10:02 AM ET retained three older-but-new-to-this-brief deltas: NVD's June 17 official metadata update, Censys activity-cluster telemetry for Mirai-pattern and .sorry ransomware activity, and Ctrl-Alt-Intel's named public targeting report involving CVE-2026-41940 PoC use.1 20 21
27-Jun-2026 · Newly retained (>24h) AI Monitoring Agent run at June 27, 2026 10:02 AM ET retained QiAnXin XLab's May 11 Mr_Rot13/Filemanager reporting as a source-backed activity-cluster delta. The update adds backdoor, credential-theft, webshell, and persistence hunting guidance without publishing raw attacker payload infrastructure and without converting aggregate compromise activity into a named-victim list.22
28-Jun-2026 · Newly retained (>24h) AI Monitoring Agent run at June 28, 2026 10:02 AM ET retained older defense-side deltas: Cloudflare's April 30 emergency WAF release for CVE-2026-41940 and Shadowserver's compromised-website report tags for sorry-ransomware, whmstealer, and mr-rot13 patterns. These add mitigation/reporting workflow guidance and do not create a named-victim list. Freshness: Newly retained (>24h).23 24
01-Jul-2026 · Newly retained (>24h) AI Monitoring Agent run at July 1, 2026 10:02 AM ET retained older hosting-provider disclosure evidence: Liquid Web's public status incident for CVE-2026-41940 remediation and InMotion Hosting's fleet-response report. These sources improve provider-notice, customer-scoping, and remediation-pattern guidance, while preserving the boundary that they are not a raw named end-customer victim list. Freshness: Newly retained (>24h).25 26
03-Jul-2026 · Newly retained (>24h) AI Monitoring Agent run at July 3, 2026 10:03 AM ET retained ThreatLocker's May 15 Sorry ransomware analysis as an older-but-useful detection and recovery delta. The update strengthens bounded ransomware hunting for host-level markers, service/process disruption, SSH propagation attempts, and recovery scoping, without adding exploit instructions, raw victim lists, or a universal compromise assumption. Freshness: Newly retained (>24h).27
08-Jul-2026 · Newly retained (>24h) AI Monitoring Agent run at July 8, 2026 10:03 AM ET retained Unfold Security's May 6 detection research as an older-but-useful detection-engineering delta. The update adds behavior-based session and access-log correlation guidance while avoiding raw exploit payloads, raw rule bodies, and brittle PoC-string-only detection framing. Freshness: Newly retained (>24h).28
13-Jul-2026 · Newly retained (>24h) AI Monitoring Agent run at July 13, 2026 10:03 AM ET retained Proofpoint's May 27 network-telemetry report as an older-but-useful activity-cluster delta. Proofpoint frames CVE-2026-41940 as multi-actor mass exploitation and reports that the vulnerability is increasingly observed in compromised-website web-inject chains such as TA569/SocGholish. Freshness: Newly retained (>24h).29
17-Jul-2026 · Newly retained (>24h) AI Monitoring Agent run at July 17, 2026 10:11 AM ET retained Bluehost's July 9 provider guidance and May 6 compromise-check guide as older-but-useful provider/customer-notice deltas. The update adds Bluehost to the named provider response pattern, strengthens VPS/Dedicated and CentOS 6 scoping, and captures provider-published compromise-review categories without republishing raw command bodies or hashes. Freshness: Newly retained (>24h).30 31
19-Jul-2026 · Newly retained (>24h) AI Monitoring Agent run at July 19, 2026 10:04 AM ET retained InMotion Hosting's May 20 direct customer follow-up and BinaryLane's May 5 provider advisory as older-but-useful provider-response deltas. The update strengthens port-blocking, patch exception, customer outreach, unmanaged-VPS, detection-script, credential/log/account review, and provider-attestation scoping without adding a new named end-customer victim list, actor, ransomware family, or exploit instructions. Freshness: Newly retained (>24h).32 33
20-Jul-2026 · Newly retained (>24h) AI Monitoring Agent run at July 20, 2026 10:02 AM ET retained CrowdSec's May 4 telemetry/detection report, Beazley Security's insurer-adjacent advisory, and KnownHost's April 28-30 provider response thread as older-but-useful deltas. The update adds bounded reconnaissance telemetry, WAF virtual-patching and detection-control evidence, insurer/MDR scoping language, and direct provider port-blocking/log-review detail without adding a named end-customer victim list or raw exploit/log examples. Freshness: Newly retained (>24h).34 35 36
For US SMBs, the risk is often indirect but still urgent. Many small businesses do not administer WHM themselves; they rely on a web host, MSP, reseller, or agency. Those stakeholders should validate whether any cPanel/WHM or WP Squared environment is internet-facing, patched to a fixed build, scanned with the vendor detection script, and reviewed for post-exploitation activity. 3 6 10 25 26 30 31 35 36
For insurers, brokers, breach counsel, and MSPs, the practical question is not only “does the policyholder run WordPress?” or “what CMS does the site use?” It is “does the policyholder, host, reseller, MSP, or web agency use cPanel/WHM or WP Squared to operate the insured web, mail, database, or customer-hosting environment?” External attack-surface checks can identify probable cPanel exposure, but they cannot prove patch status or absence of compromise; that requires provider attestation, version evidence, vendor detection-script output, retained logs, and hosted-asset review. 3 6 10 17 18 35
Decision-makers should avoid treating this as a routine patch notice. KEV status, public exploit details, ransomware reporting, and exposed-hosting blast radius make this an exposure-validation and incident-scoping problem. Patching closes the known flaw, but response should also preserve logs, inspect session artifacts, rotate affected administrative credentials where warranted, and confirm hosted-site integrity. 3 4 7
Expansion Research Add
Practical summary: CVE-2026-41940 is a critical authentication bypass in the cPanel & WHM hosting control panel. It is not a WordPress vulnerability and is not limited to WordPress. Successful exploitation can give attackers administrative access to hosted websites, databases, files, mail, and customer environments managed through the affected control plane.3 6 13 17 18
CVE-2026-41940 Exploit Watch Snapshot
5-AI Agent Delta Updates
| Field | Value |
|---|---|
| AI Agent Status | 25-Jun-2026 · Added AI Agent #3 - CVE-2026-41940 cPanel & WHM Watch Monitor is scheduled for daily review at 2:00 PM ET for six months. |
| Baseline State | Initial static product created June 23, 2026 from public sources and source reconciliation. |
| Last AI Agent Run | Run completed July 20, 2026 at 10:02 AM ET. AI Monitoring Agent retained three older telemetry, insurer-adjacent, and provider-response sources as source-backed deltas. Product version increments to v1.14. |
| Sources Added / Newly Used | 20-Jul-2026 · Newly retained (>24h) July 20 run added CrowdSec's May 4 telemetry/detection report, Beazley Security's May 2026 advisory, and KnownHost's April 28-30 provider response thread as Newly retained (>24h). Freshly reported (<24h): none. Newly retained (publication date not visible): none.34 35 36 |
| Named Victim / Disclosure Search Outcome | July 20 named-victim/provider-disclosure search retained KnownHost only as an additional named provider/customer-notice disclosure. No reliable public named end-customer organization or company newly tied to confirmed CVE-2026-41940 compromise, ransomware impact, or hosted-site compromise was found. Aggregate telemetry, exposed-instance counts, screenshots, community anecdotes, raw customer/victim lists, individual community self-reports, and unverifiable forum claims remain excluded. |
| Associated Campaign / Activity Search Outcome | July 20 associated-campaign/activity-cluster search retained CrowdSec reconnaissance and detection telemetry as a bounded exploitation-pressure cluster, but found no new named actor, ransomware family, intrusion set, botnet, or named victim campaign. It revised provider/remediation and insurer-evidence scoping with Beazley Security and KnownHost evidence. |
| Previous AI Agent Delta | July 20, 2026 run retained CrowdSec, Beazley Security, and KnownHost evidence. July 19, 2026 run retained InMotion Hosting and BinaryLane provider-response evidence. July 18, 2026 run found no source-backed content delta. July 17, 2026 run retained Bluehost provider/customer guidance. July 13, 2026 run retained Proofpoint's May 27 network-telemetry report. July 8, 2026 run retained Unfold Security's May 6 detection research. 28 29 30 31 32 33 34 35 36 |
| Checked But Not Retained | July 20 run checked CISA KEV/search results, NVD detail/change records, CVE.org, VulnCheck, cPanel advisory/response/release-note pages, WP Squared release notes/changelog, Rapid7, watchTowr, BleepingComputer tag/news pages, Shadowserver trending/reporting/monitoring pages, Censys ARC/advisory pages, Ctrl-Alt-Intel, QiAnXin XLab, Cloudflare, ThreatLocker, Unfold Security, Proofpoint, CrowdSec, Beazley Security, KnownHost, Bluehost, InMotion, BinaryLane, Namecheap, Liquid Web, F5 Labs, SecPod, eSentire, Arctic Wolf, Barracuda, CIS/MS-ISAC, Trend Micro, CyCognito, Qualys, Picus, CybelAngel, Bitsight, Cato Networks, WaterISAC, SecurityAffairs, The Hacker News, SC World, Tenable, Mallory, Pentest-Tools, TechRadar, Tech Insider, IT Security Guru, BankInfoSecurity, cPanel support/community posts, GitHub verification/exploit-code and IOC-detector repositories, customer-notice searches, victim/disclosure searches, Reddit/forum/social reposts, LinkedIn/X/social reposts, Rapid7 page-shell last-updated markers, Shadowserver rolling dashboard signals, and SEO/security-news rewrites for novelty. Duplicative explainers, exploit-code reposts, scanner/tool pages, product-marketing-only notes, individual or unverifiable anecdotes, page-shell date changes without visible substantive CVE-2026-41940 change, unrelated cPanel/plugin/licensing advisories, KEV aggregators, and older sources that did not improve confidence, scoping, mitigation, victimology, or activity-cluster mapping were not retained. |
| Next Scheduled Run | Daily at 2:00 PM ET through December 25, 2026. |
| Email Report | No external email or notification sent for the July 20 run under the current automation no-email policy; run status is retained in Codex output and automation memory only. |
| Delta Rules | Always append the Change Log; distinguish Freshly reported (<24h) from Newly retained (>24h) sources; use dated pills and color coding for changed content; update PANDA index date; deploy after successful verification when the deployment path is available; do not send external email under the current no-email policy. |
| Future Delta Candidates | CISA KEV due-date changes, vendor advisory updates, new exploitation telemetry, ransomware linkage updates, associated campaigns or activity clusters, WP Squared/cPanel product guidance, named victim organizations, or new detection guidance. |
6-Why It Matters
cPanel & WHM is not just another web application on a host. In many environments, it is the management layer for websites, databases, email, DNS-adjacent workflows, reseller access, and server administration. An authentication bypass against that control plane can become a customer-impacting event quickly, especially for hosting providers, MSPs, agencies, and SMBs that share infrastructure or depend on a third party for web operations. 6 11 12
That distinction matters for scoping. A website owner may not have a flaw in WordPress, Joomla, Drupal, Magento, custom code, or another hosted application to patch, but still needs assurance from the hosting provider, MSP, reseller, or web agency that the cPanel/WHM control plane was patched and checked for exploitation. This is a hosting-control-plane risk with downstream website and hosted-service consequences.3 17 18
26-Jun-2026 · Newly retained (>24h) Newly retained telemetry adds that Censys observed a May 1 malicious-host surge overwhelmingly concentrated on cPanel/WHM, plus distinct Mirai-pattern and .sorry ransomware activity signals. This improves activity scoping but does not create a public named-victim list.20
01-Jul-2026 · Newly retained (>24h) Newly retained hosting-provider notices show why customers need provider-specific evidence instead of only generic CVE status: Liquid Web publicly described CVE-2026-41940-related remediation, support-volume impact, and restoration where compromise was evident, while InMotion reported network-edge blocking, fleet patching, and direct work with a small subset of customer environments. Freshness: Newly retained (>24h).25 26
17-Jul-2026 · Newly retained (>24h) Bluehost adds another named provider-response example for VPS and Dedicated customers: temporary cPanel/WHM/Webmail/WebDisk port restrictions on affected servers, CentOS 6 migration guidance, backup and log-review advice, and compromise-review categories for ransomware markers, persistence, SSH keys, cPanel template tampering, shell history, credential rotation, and hosted-account review. Freshness: Newly retained (>24h).30 31
19-Jul-2026 · Newly retained (>24h) InMotion's direct follow-up and BinaryLane's advisory add provider-response detail that customers can request from hosts: port-blocking windows, patch exception handling, direct customer outreach, unmanaged VPS responsibilities, credential rotation, log/account review, and detection-script execution. Freshness: Newly retained (>24h).32 33
Business Risk
Hosting Control
Unauthorized WHM access can cascade into hosted sites, mail, databases, and customer data.
Response Risk
Patch + Scope
Updating closes the known flaw, but responders still need to inspect sessions, logs, and hosted content.
Client Risk
Indirect Exposure
SMBs may not know they use cPanel; their exposure may sit with a host, reseller, MSP, or agency.
Expansion Research Add
For client communications, do not call this a WordPress bug. Say: “This is a cPanel/WHM hosting control panel vulnerability that can put websites, databases, mail, files, and hosted customer environments at risk when they are managed through vulnerable hosting infrastructure. WordPress is one common downstream example, not the vulnerable product.”
7-Vulnerability Details
| Attribute | Assessment | Source Basis |
|---|---|---|
| CVE | CVE-2026-41940 | NVD and CVE.org provide the stable CVE identity. 1 14 |
| Affected products | cPanel & WHM, including DNSOnly per cPanel advisory; WP Squared also affected before fixed build. | Vendor and advisory sources identify the affected product family. 3 4 6 |
| Hosted workload relationship | Not a WordPress core, plugin, or theme vulnerability and not limited to WordPress; any websites, CMS platforms, databases, mail, files, or customer accounts managed by vulnerable cPanel/WHM infrastructure may be downstream affected. | cPanel product and WordPress-management documentation support the hosting-control-plane distinction. 3 17 18 |
| Vulnerability class | Authentication bypass in session-management / login flow, associated with CRLF injection and unsanitized session-file handling. | Vendor and practitioner analyses describe the session-management exploit path. 4 5 6 10 |
| Privileges required | None. Public sources frame this as unauthenticated remote access to administrative control paths. | NVD, Rapid7, and VulnCheck support the no-credential framing. 1 6 13 |
| Potential impact | Administrative control of cPanel host system, configurations, databases, websites, mail, files, customer accounts, and hosted services. | Practitioner sources support the hosting-control-plane impact assessment. 6 11 |
8-Affected Products & Fixed Versions
| Product | Affected | Fixed / Required Build |
|---|---|---|
| cPanel & WHM | All versions after 11.40 before fixed branch builds | 26-Jun-2026 · Newly retained (>24h) NVD's June 17 affected-record update corroborates the branch-specific fixed-build ranges. 11.86.0.41, 11.94.0.28, 11.102.0.39, 11.110.0.97, 11.118.0.63, 11.124.0.35, 11.126.0.54, 11.130.0.19, 11.132.0.29, 11.134.0.20, 11.136.0.5 and later 1 3 13 |
| WP Squared | WP Squared builds before fixed release | 136.1.7 and later 3 6 |
| CentOS 6 / CloudLinux 6 cPanel v110.0.50 path | Legacy environments called out by vendor | Vendor described v110.0.103 direct update path and tier-setting instructions 3 |
9-KEV, Exploitation & Public PoC Status
| Item | Status | What It Means |
|---|---|---|
| CISA KEV | Known Exploited | Treat as an urgent, externally validated exploitation risk rather than a theoretical vulnerability. 2 4 |
| Public PoC | Available | Technical exploitation became easier to reproduce after watchTowr publication. 5 6 |
| Ransomware reporting | Reported | BleepingComputer reports Sorry ransomware deployment after exploitation; scope for encryption and backup impact. 7 |
| Compromise telemetry | Large-scale signal | 26-Jun-2026 · Newly retained (>24h) Shadowserver and Censys reporting support broad exploitation, scanning, and post-compromise activity signals, not a victim list. 8 20 |
10-Technical Breakdown
Before exploitation, the attacker still has to find candidate cPanel/WHM or WP Squared endpoints. That is usually not luck. Publicly reachable hosting-control panels can be located through internet-wide scanning, common hostnames such as cpanel, whm, and webmail, common cPanel ports such as 2082/2083, 2086/2087, and 2095/2096, HTTP titles, TLS certificates, provider fingerprints, passive attack-surface datasets, and known hosting-provider or reseller patterns. Underground or shared target lists can also exist in real incidents, but this brief treats internet exposure discovery and attack-surface enumeration as the source-supported baseline unless a source proves a specific list-driven campaign. 3 6 10 17
At a defensive level, the public technical record points to a pre-authentication path in which attacker controlled input can influence cPanel session-file state. cPanel describes two code paths writing session files, one of which lacked sanitization during Basic authentication handling. Rapid7 and watchTowr describe the exploitability around CRLF injection, malformed session material, and the ability to insert privileged session properties before authentication is complete. 4 5 6
The attacker does not need to start with a WordPress login, another CMS login, a stolen cPanel password, or an installed website plugin. The exploit target is the exposed cPanel/WHM service itself. If successful, the attacker can arrive inside a trusted administration layer and then use normal control-panel functions to create or modify accounts, reach hosted files, inspect databases, change site content, add SSH keys, access mail-adjacent assets, or prepare follow-on ransomware. That means investigation should include the cPanel host, hosted websites, customer accounts, databases, mail, SSH keys, backups, and reseller or privileged account activity. 3 6 7 11
Expansion Research Add
In WordPress-heavy hosting environments, this means the attacker is not exploiting WordPress directly. More broadly, they are potentially bypassing authentication on the control panel that manages hosted website files, CMS installs, databases, domains, backups, email, customer accounts, and administrative workflows.
11-MITRE ATT&CK / Attack Flow
| Step | MITRE / Attack Phase | Likely Attacker Activity | Defensive Focus |
|---|---|---|---|
| 0 | Target acquisition / exposed-control discovery | Locate probable cPanel/WHM or WP Squared endpoints through internet-wide scanning, common cPanel hostnames, common management ports, HTTP/TLS fingerprints, passive attack-surface data, hosting-provider patterns, or shared target lists where locally evidenced. | Know whether the organization or provider exposes cPanel/WHM, restrict admin portals, monitor for scanning, and use attack-surface management to find shadow or third-party hosting dependencies. |
| 1 | Reconnaissance / version and service confirmation | Confirm internet-facing cPanel/WHM, DNSOnly, or WP Squared services and estimate version, patch state, or exploitability from reachable service behavior and fingerprints. | Maintain asset inventory, restrict cPanel/WHM access, and validate exposed versions before incidents. |
| 2 | T1190 - Exploit Public-Facing Application | Send a crafted unauthenticated request that abuses session-management behavior, CRLF/session-file handling, or login-flow weakness to obtain authenticated control-panel state. | Patch to fixed build, restart cpsrvd, run vendor detection script, and preserve session files and access logs. |
| 3 | Privileged control-panel access | Use WHM/cPanel administrative functions after bypassing authentication, rather than exploiting WordPress directly. | Review administrative actions, reseller accounts, new users, password changes, SSH keys, package changes, and privilege changes. |
| 4 | Collection / hosted asset access | Access hosted files, databases, website directories, backups, mail-adjacent assets, and customer or reseller environments managed by the control panel. | Scope hosted websites, databases, backups, webshells, malicious uploads, data access, and integrity of customer-facing sites. |
| 5 | T1486 - Data Encrypted for Impact | Deploy malware, alter hosted sites, steal data, or encrypt files as reported in Sorry ransomware cases. | Check ransomware notes, .sorry extensions, backup integrity, restoration paths, and whether compromise stayed at control-panel access or became business impact. |
Expansion Research Add
The key scoping distinction: the flaw can place an attacker above the websites and hosted services at the hosting-control layer. If a policyholder only checks WordPress plugins, website code, or CMS updates, they can miss the actual compromised plane of control.
12-TTPs
| Tactic | MITRE ATT&CK / Mapping | Source-Backed Detail | Caveat | Source Basis |
|---|---|---|---|---|
| Initial Access | T1190 - Exploit Public-Facing Application | Exploit exposed cPanel/WHM web service without valid credentials. | Map only where the affected service is internet-facing. | Exploit analysis and ATT&CK mapping support this behavior. 5 6 15 |
| Privilege / Control | Session-state abuse / control-panel administration | Injected session state can be treated as authenticated administrative access, after which the attacker may use normal cPanel/WHM functions. | Do not describe this as password theft unless logs prove credential access; the vulnerability is an authentication bypass. | Vendor and technical sources describe the session-state bypass path. 3 4 5 6 |
| Persistence | T1078 - Valid Accounts | If an attacker creates or changes WHM/cPanel, reseller, SSH, database, or hosted-site accounts after bypassing authentication, those accounts become post-exploitation persistence or re-entry paths. | Only map when local logs show account creation, password changes, SSH key additions, or similar administrative actions. | The control-plane impact described by Rapid7, Qualys, and cPanel makes account review a necessary local hunt. 3 6 11 |
| Persistence / Credential Access | Webshell, SSH-key, login-page tampering, and remote-control backdoor activity | 27-Jun-2026 · Newly retained (>24h) QiAnXin XLab reported Mr_Rot13 post-exploitation activity that implants access paths, modifies cPanel-facing assets, steals credentials, and deploys Filemanager remote-control tooling. | Map only when local artifacts support this activity; do not publish raw attacker infrastructure in broad stakeholder guidance. | Retained as source-backed activity-cluster evidence. 22 |
| Impact | T1486 - Data Encrypted for Impact | 03-Jul-2026 · Newly retained (>24h) Sorry ransomware reporting describes Linux-host encryption following exploitation, with newly retained ThreatLocker analysis adding host-level marker, process/service interruption, and SSH-propagation hunt detail. | Ransomware linkage is reported; not every exploitation case becomes ransomware or the same payload path. | Ransomware impact is reported as a real-world outcome, not a universal result. 7 16 27 |
13-IOCs / Observables
This brief does not publish a stable universal IP/domain/hash blocklist for CVE-2026-41940. Forensicators should prove compromise through a local evidence chain: vendor detection-script results, session-file artifacts, cPanel/WHM access logs, privileged administrative actions, hosted-asset changes, and ransomware or malware traces where present. 3 4 7
| Forensic Evidence | What It Can Prove | What To Collect / Preserve | Evidence Boundary |
|---|---|---|---|
| Public IOC status | No retained source publishes a reliable universal CVE-2026-41940 IP, domain, hash, JA3, user-agent, or exploit-client blocklist suitable for proving compromise by itself. | Use public exploitation status and telemetry for urgency; use local artifacts to prove or refute compromise. 2 3 4 7 8 | A host can be vulnerable or exposed without being proven compromised. |
| Vendor detection-script output | Positive or suspicious findings from the cPanel-provided detection script against relevant session files and log context. | Run the vendor script before session-file cleanup and preserve the script, version, runtime, output, and reviewed files. 3 4 | Treat script output as high-value local evidence; correlate with logs and administrative actions before final impact conclusions. |
| Session-file + access-log correlation | Suspicious session artifacts that line up with cPanel/WHM access-log activity, successful administrative responses, unusual source IPs, or abnormal request timing. | Preserve session directories, cPanel access logs, cpsrvd/error logs where available, web server logs, timestamps, source IPs, account names, and request/response context. 3 5 6 9 | A suspicious session file alone may show exploit attempt or artifact creation; correlated successful admin activity is stronger compromise evidence. |
| Control-panel administration after suspicious access | New or modified WHM/cPanel/reseller accounts, password resets, SSH key additions, package changes, domain changes, backup changes, mail/database access, or other privileged actions after the suspected exploit window. | Export WHM/cPanel account history, privileged user changes, SSH authorized keys, package/domain changes, database/mail access evidence, and backup activity. 6 11 | These artifacts prove post-access behavior; they may not by themselves prove CVE-2026-41940 unless tied to the exploit-window and session/access evidence. |
| Backdoor and persistence evidence 27-Jun-2026 · Newly retained (>24h) | Mr_Rot13/Filemanager-style artifacts can show post-exploitation persistence, credential theft, and remote-control activity after a cPanel compromise path. | Preserve SSH authorized-key changes, webshell evidence, modified login-page assets, suspicious credential-access scripts, remote-control service evidence, process listings, and clean-room malware triage notes. 22 | Use these as compromise and persistence indicators, not as universal proof that every exposed cPanel host was hit by Mr_Rot13. |
| Hosted-asset impact evidence | Webshells, unauthorized file changes, modified hosted sites, database dumps, suspicious uploads, new cron jobs, malware, encrypted files, ransom notes, or .sorry extensions. | 03-Jul-2026 · Newly retained (>24h) Preserve webroot diffs, file-integrity output, malware scan results, database access logs, backup status, ransom notes, encryption indicators, host-level marker files, service/process interruption evidence, SSH-propagation traces, and restoration evidence. 6 7 11 16 27 | Hosted-site compromise or ransomware impact can prove an incident occurred, but responders still need to determine whether CVE-2026-41940 was the entry path. |
Observable Hunt Leads
| Artifact | What To Look For | Why It Matters | Response Use |
|---|---|---|---|
| /var/cpanel/sessions | Suspicious session files, injected session attributes, anomalous auth markers, badpass-origin artifacts. | Vendor detection script centers on filesystem session indicators. 3 4 | Preserve before cleanup. |
| /usr/local/cpanel/logs/access_log | Requests tied to suspicious tokens, Basic auth abuse, anomalous WHM/cPanel access, follow-on 200 responses. | Access-log context helps determine whether suspicious session material was used. 3 | Correlate with session files. |
| Session and access-log correlation 08-Jul-2026 · Newly retained (>24h) | Authenticated cpsess activity without the expected preceding successful login path; suspicious session promotion or token use that lines up with access-log activity. | Unfold recommends behavior-based detection for exploit mechanics rather than brittle matching on public PoC strings. 28 | Freshness: Newly retained (>24h); adapt to local log retention and SIEM schemas. |
| WHM/cPanel accounts | New admin/reseller accounts, password changes, SSH key additions, unexpected package or domain changes. | Successful exploitation can grant administrative access to hosting control planes. 6 11 | Scope control-plane impact. |
| Hosted websites | Webshells, unauthorized file changes, malware uploads, mass defacement, encrypted files. | Compromised WHM access can cascade into hosted websites and customer data. 6 7 11 | Inspect hosted assets. |
| Backdoor / credential-theft traces 27-Jun-2026 · Newly retained (>24h) | Unexpected SSH keys, PHP webshells, cPanel login-page tampering, credential collection, and Filemanager-style remote-control tooling after suspected CVE-2026-41940 access. | QiAnXin XLab tied this post-exploitation pattern to Mr_Rot13 activity abusing CVE-2026-41940. 22 | Use as hunt leads; keep raw attacker infrastructure out of public guidance. |
| Ransomware traces 03-Jul-2026 · Newly retained (>24h) | .sorry file extension, ransom notes, backup deletion, Linux encryptor execution paths, host-level marker files, service/process disruption, and SSH propagation attempts. | BleepingComputer, Shadowserver, and ThreatLocker reporting tie CVE-2026-41940 compromise workflows to Sorry ransomware reporting/tags and bounded host-level hunting detail. 7 16 24 27 | Freshness: Newly retained (>24h); check reported impact path without treating it as universal exploitation behavior. |
| Shadowserver compromised-website report tags 28-Jun-2026 · Newly retained (>24h) | Check whether your network, ASN, or hosted domains appear in Shadowserver notifications tagged sorry-ransomware, whmstealer, or mr-rot13 for cPanel/Roundcube compromise patterns. | Shadowserver describes CVE-2026-41940-related report tagging for likely compromised cPanel/Roundcube assets. 24 | Freshness: Newly retained (>24h); use as notification workflow, not public victim evidence. |
| Provider compromise-review checklist 17-Jul-2026 · Newly retained (>24h) | Validate patched build, then review for ransomware-marker files, persistence or shell-startup anomalies, root SSH-key changes, cPanel template tampering, suspicious shell history, hosted-account changes, and evidence-preservation needs. | Bluehost published customer-facing CVE-2026-41940 compromise-review guidance for VPS/Dedicated environments. 31 | Freshness: Newly retained (>24h); use categories as hunt leads without republishing raw command bodies or hashes. |
| Provider response and exception records 20-Jul-2026 · Newly retained (>24h) | Port-blocking windows, patch exception lists, direct customer outreach, unmanaged-VPS responsibility statements, credential rotation guidance, log/account review prompts, detection-script execution records, and provider log-review outcomes. | InMotion, BinaryLane, Beazley Security, and KnownHost publish provider-side response, customer-action, or insurer-evidence details useful for scoping indirect hosting-control-plane exposure. 32 33 35 36 | Freshness: Newly retained (>24h); provider notices are not end-customer victim lists. |
| CrowdSec telemetry and virtual patching 20-Jul-2026 · Newly retained (>24h) | CrowdSec observed 282 distinct IPs tied to CVE-2026-41940 between April 27 and May 4 and published detection/WAF virtual-patching coverage for exposed setups. | Use as bounded reconnaissance/detection telemetry and compensating-control evidence. 34 | Freshness: Newly retained (>24h); telemetry and control status do not prove a named victim or clean state. |
14-Detection & Hunting
The vendor detection script is the highest-priority local check because it is tailored to session-file indicators for this vulnerability. Run it before deleting session artifacts, and preserve output for IR review. The script looks at session files and access-log context, and cPanel has refined it across multiple advisory updates to reduce false positives. 3 4 08-Jul-2026 · Newly retained (>24h) Unfold Security adds a detection-engineering layer: hunt for exploit-invariant behavior such as suspicious session promotion and authenticated cpsess activity without the normal preceding login path, instead of depending only on static PoC-string matches. Freshness: Newly retained (>24h).28 20-Jul-2026 · Newly retained (>24h) CrowdSec and KnownHost add older-but-newly-retained operational context: dedicated detection/WAF virtual-patching coverage, reconnaissance telemetry, and provider log-review outcomes should complement, not replace, vendor script output and local access/session correlation. Freshness: Newly retained (>24h).34 36
| Hunt | Detail | Owner |
|---|---|---|
| Version validation | Confirm fixed build on every cPanel, WHM, DNSOnly, and WP Squared deployment. | Vulnerability management / hosting admin |
| Session-file triage | Run the vendor script against cPanel session directories and inspect suspicious sessions. | Linux admin / IR |
| Access-log correlation | Review suspicious session tokens, anomalous Basic auth paths, successful administrative access, and cpsess activity that lacks a prior legitimate login event. | SOC / DFIR |
| Behavior-based exploit detection 08-Jul-2026 · Newly retained (>24h) | Build detections around session-file invariants and access-log sequence anomalies that should hold across exploit variants. Freshness: Newly retained (>24h). 28 | Detection engineering / SIEM |
| CrowdSec detection and virtual patching 20-Jul-2026 · Newly retained (>24h) | Where deployed, confirm CrowdSec detection-rule and WAF virtual-patching status, then correlate any hits with cPanel session/access logs, patch timing, and provider evidence. Freshness: Newly retained (>24h). 34 | SOC / platform engineering |
| Provider compromise-review checklist 17-Jul-2026 · Newly retained (>24h) | Use Bluehost's customer guidance as provider-scoped categories for review: ransomware markers, persistence changes, SSH keys, cPanel template tampering, shell history, hosted-account review, evidence preservation, and credential rotation. Freshness: Newly retained (>24h). 31 | Hosting provider / IR / Linux admin |
| Provider log-review attestation 20-Jul-2026 · Newly retained (>24h) | Ask hosts whether they reviewed cPanel access and session logs, how many systems showed access-attempt evidence, whether customers were contacted directly, and whether active-compromise signs were ruled in or out. Freshness: Newly retained (>24h). 35 36 | Provider management / breach counsel |
| Hosted impact | Check hosted sites, files, databases, mail, and backups for unauthorized change or encryption. | IR / web operations |
15-Incident Response Playbook Ideas
| # | Action | Likely Owner | Evidence |
|---|---|---|---|
| 1 | Update cPanel & WHM / WP Squared to a fixed build immediately and restart cpsrvd. 3 4 6 | Server admin / hosting provider | Stops the known authentication-bypass path. |
| 2 | Inventory internet-facing WHM/cPanel endpoints, reseller environments, DNSOnly hosts, and WP Squared deployments. 3 6 10 | IT / MSP / ASM | Finds direct and indirect hosting-control exposure. |
| 3 | Run the vendor detection script against session files and preserve findings before cleanup. 3 4 | IR / Linux admin | Preserves vulnerability-specific evidence. |
| 4 | 08-Jul-2026 · Newly retained (>24h) Add behavior-based detections that correlate suspicious cPanel session-file markers with access-log usage and authenticated cpsess activity that lacks a preceding legitimate login path. 28 | SOC / detection engineering | Freshness: Newly retained (>24h); improves detection resilience without relying only on public PoC strings. |
| 5 | Review cPanel access logs, session directories, root/admin activity, account creation, SSH key additions, webshell indicators, hosted-site changes, database access, and backup deletion. 3 6 7 9 11 28 | IR / DFIR | Scopes whether control-panel access became hosted-site, data, or ransomware impact. |
| 6 | 03-Jul-2026 · Newly retained (>24h) Look for Sorry ransomware impact, .sorry file extensions, ransom notes, host-level marker files, service/process disruption, SSH propagation attempts, and web-host encryption impact. 7 16 24 27 | IR / recovery | Freshness: Newly retained (>24h); checks a reported exploitation outcome and newly retained malware-analysis detail. |
| 7 | 27-Jun-2026 · Newly retained (>24h) For compromised hosts, hunt for Mr_Rot13/Filemanager-style post-exploitation signs: unexpected SSH keys, webshells, modified cPanel login assets, credential collection, and remote-control backdoors. 22 | DFIR / Linux admin | Checks a newly retained activity-cluster outcome without publishing raw payload infrastructure. |
| 8 | If patching cannot happen immediately, restrict cPanel service exposure and apply vendor-supported mitigations; then rotate privileged hosting credentials if compromise is suspected. 3 6 7 | Network / platform team | Reduces reachable attack surface while containment and impact review continue. |
| 9 | 28-Jun-2026 · Newly retained (>24h) Where Cloudflare WAF is in path, confirm the April 30 emergency managed rule is active and review block/log events, while still patching cPanel & WHM / WP Squared. 23 | Network / appsec / hosting provider | Freshness: Newly retained (>24h); adds compensating-control evidence and telemetry triage. |
| 10 | 17-Jul-2026 · Newly retained (>24h) For Bluehost-like VPS/Dedicated scenarios, combine fixed-build validation with compromise review for ransomware markers, persistence changes, SSH keys, cPanel template tampering, shell history, evidence preservation, credential rotation, and hosted-account impact. 30 31 | Hosting provider / IR / Linux admin | Freshness: Newly retained (>24h); adds provider-scoped customer guidance without republishing raw command bodies or hashes. |
| 11 | 20-Jul-2026 · Newly retained (>24h) Ask providers whether exposed ports were blocked, which systems could not receive patches, whether any customers received direct compromise outreach, whether logs were reviewed for access attempts, and whether post-patch customer actions included credential rotation, log/account review, and detection-script execution. 32 33 35 36 | Provider management / MSP / breach counsel | Freshness: Newly retained (>24h); strengthens provider-notice, unmanaged-VPS, insurer-evidence, and log-review scoping. |
| 12 | 20-Jul-2026 · Newly retained (>24h) Where CrowdSec coverage is deployed, review CVE-2026-41940 detection-rule and WAF virtual-patching status alongside vendor patch evidence and local cPanel session/access-log review. 34 | SOC / platform engineering | Freshness: Newly retained (>24h); adds third-party detection and virtual-patching evidence without treating controls as proof of clean state. |
16-Decision Ready Actions
| Decision Owner | Decision / Action | Timeframe |
|---|---|---|
| Executives / business owners | Ask whether any hosted websites, customer portals, or business mail depend on cPanel/WHM and whether the host can attest to fixed builds and exploit checks. | Immediate |
| IT / MSP | Patch, restart cpsrvd, run vendor detection tooling, and inventory all exposed cPanel/WHM endpoints. | Immediate |
| SOC / IR | Preserve logs and session artifacts before cleanup; scope for admin abuse, website compromise, and Sorry ransomware traces. | 0-24 hours |
| Claims / breach counsel | Treat unpatched vulnerable hosting control planes as potential unauthorized-access events requiring evidence preservation and impact scoping. | 0-72 hours |
| Client-facing advisors | Prepare plain-language guidance for SMBs that may use hosted cPanel indirectly through a provider or agency. | Same day |
17-US SMB / Insurance Policyholder Scoping Lens
Many SMBs are not direct cPanel administrators. They may use cPanel indirectly through shared hosting, managed website providers, WordPress hosts, resellers, digital agencies, web developers, or MSP-managed hosting. Scoping should therefore ask both the organization and its providers whether affected cPanel/WHM or WP Squared infrastructure existed, whether it was patched to a fixed build, whether the vendor script was run, and whether hosted assets showed unauthorized access or encryption. The right question is not “was WordPress vulnerable?” or “was the site code vulnerable?” but “was the hosting control panel that manages the web environment vulnerable or compromised?” 3 6 7 17 18
| Question For Policyholder / Provider | Why It Matters | Evidence To Request |
|---|---|---|
| Who operates the cPanel/WHM or WP Squared environment: policyholder, hosting provider, MSP, reseller, web agency, or developer? | Determines who owns patching, logs, detection-script execution, and hosted-asset review. | Hosting agreement, provider name, control-panel URL, admin owner, MSP/web agency contact. |
| Was any cPanel/WHM, DNSOnly, or WP Squared instance exposed during the February-May 2026 risk window, and what exact version/build was running? | Determines whether the environment fell into the affected version range and whether historical exploitation needs to be scoped. | Version output, update logs, patch timestamp, cpsrvd restart evidence, fixed-build attestation. |
| Was the cPanel vendor detection script run before session files were deleted or rotated? | The vendor script is the most specific public check for this CVE’s session-file evidence. | Script output, retained session files, access-log excerpts, provider incident ticket. |
| Did the host, MSP, or reseller issue a CVE-2026-41940 customer notice, restrict ports, restore affected servers, keep unpatched exceptions blocked, review logs for access attempts, or contact customers whose environments required direct remediation? 20-Jul-2026 · Newly retained (>24h) | Provider notices from Liquid Web, InMotion, Bluehost, BinaryLane, and KnownHost show that customer impact can sit in provider remediation queues even when the policyholder did not operate WHM directly; Beazley adds insurer-adjacent perimeter and MDR scoping language. Freshness: Newly retained (>24h). | Provider incident notice, ticket history, restore status, fixed-build evidence, exception list, customer outreach, outage notice, OS-migration guidance, unmanaged-VPS responsibility statement, log-review attestation, and compromise-review notes. 25 26 30 31 32 33 35 36 |
| Were cPanel access logs, session directories, privileged account changes, SSH keys, and hosted-site changes reviewed? | Confirms whether exposure remained theoretical or became unauthorized administration. | Access-log review, new account list, SSH key inventory, file-integrity results, database access review. |
| Were hosted websites, backups, mail-adjacent assets, databases, or customer-facing portals modified, encrypted, or exfiltrated? | Separates vulnerable-but-clean from suspected compromise, ransomware, or data-access impact. | Webroot diff, backup status, ransomware indicators, database audit, webshell scan, restoration notes. |
| Remote Check | What It Can Show | Boundary |
|---|---|---|
| DNS and hostnames | Probable cPanel/WHM use from names such as cpanel.example.com, whm.example.com, or webmail.example.com. | Shows likely control-panel exposure or provider pattern; does not prove vulnerability or compromise. |
| Common cPanel ports | Externally reachable services on 2082/2083, 2086/2087, 2095/2096, or related management endpoints. | Requires authorization and rate-limited, non-invasive checking; cannot prove fixed build without authenticated or provider evidence. |
| Passive attack-surface intelligence | Search-engine, certificate, HTTP-title, banner, ASN, nameserver, or hosting-provider fingerprints that suggest cPanel/WHM presence. | Useful for triage and outreach, but patch and compromise status must be validated by the operator. 6 10 |
| Provider attestation 20-Jul-2026 · Newly retained (>24h) | Whether the host patched all affected instances, ran the detection script, reviewed logs, applied exposure-management checks, and identified or ruled out access attempts or active compromise. Freshness: Newly retained (>24h). 35 36 | Ask for evidence, not a generic secure-state statement. |
Expansion Research Add
Insurance-facing language: remote checks can identify probable cPanel usage and exposed management surfaces, but they should trigger evidence requests rather than become proof of compromise. Ask for version/build, patch timestamp, cpsrvd restart evidence, detection-script results, access-log review, exposure-management findings, MDR hunt outcomes, customer-contact criteria, and hosted-asset integrity checks. 35
18-Patch & Mitigation Guidance
The primary control is to update to a fixed version and restart cPanel services. Vendor-supported mitigations exist for environments that cannot update immediately, including service exposure restrictions and temporary service changes, but Rapid7 and cPanel both frame patching as the preferred long-term fix.3 6
28-Jun-2026 · Newly retained (>24h) Cloudflare's April 30 emergency WAF release adds a source-backed compensating-control check for environments fronted by Cloudflare: confirm the managed rule is active and review logs/blocks, but do not treat WAF coverage as a substitute for updating cPanel & WHM / WP Squared. Freshness: Newly retained (>24h).23
| Control | Guidance |
|---|---|
| Update | Run cPanel update to a fixed build and confirm version with the cPanel version command. 3 |
| Restart | Restart cpsrvd after update as vendor guidance requires. 3 |
| Legacy path | For CentOS 6 / CloudLinux 6 v110.0.50, follow the vendor-designated v110.0.103 update path. 3 |
| Temporary mitigation | If immediate patching is impossible, restrict inbound access to exposed cPanel/WHM services and apply vendor-supported mitigation steps. 3 6 |
| Cloudflare WAF managed rule 28-Jun-2026 · Newly retained (>24h) | For Cloudflare-fronted assets, validate the emergency managed WAF rule for CVE-2026-41940-related cPanel & WHM authentication-bypass traffic is enabled and review rule hits. Freshness: Newly retained (>24h). 23 |
| Provider port restrictions and OS migration 17-Jul-2026 · Newly retained (>24h) | Bluehost described temporary cPanel/WHM/Webmail/WebDisk port restrictions for affected VPS/Dedicated servers and framed migration off CentOS 6 as the durable remediation path for unsupported cPanel stacks. Freshness: Newly retained (>24h). 30 |
| Provider port blocking and patch exceptions 19-Jul-2026 · Newly retained (>24h) | InMotion and BinaryLane provider guidance reinforces that exposed cPanel/WHM/Webmail/WebDisk ports may be blocked while fleets are patched, and that systems unable to receive fixes need explicit exception handling, customer outreach, and owner-side patch validation. Freshness: Newly retained (>24h). 32 33 |
| Provider log review and exposure management 20-Jul-2026 · Newly retained (>24h) | KnownHost and Beazley Security reinforce that provider/client evidence should include port-blocking windows, patch rollout, cPanel access/session-log review, detection-script use, perimeter exposure checks, and MDR hunt outcomes. Freshness: Newly retained (>24h). 35 36 |
| CrowdSec detection and WAF virtual patching 20-Jul-2026 · Newly retained (>24h) | Where CrowdSec is in use, confirm CVE-2026-41940 detection and virtual-patching coverage, but keep fixed-build validation and local forensic review as the control of record. Freshness: Newly retained (>24h). 34 |
19-Timeline
| Date / Period | Event | Source-Backed Meaning |
|---|---|---|
| February 2026 (reported) | Public reporting and later summaries reference possible pre-disclosure exploitation activity beginning around late February. | Treat unpatched or recently patched servers as potentially exposed; do not assume risk began on public disclosure day. 6 7 9 19 |
| April 27, 2026 | cPanel says the vulnerability was confirmed and classified, triggering incident response. | Vendor response window begins. 4 |
| April 28, 2026 | cPanel published the support advisory and released patched builds across supported tiers. | Emergency update window begins for exposed servers. 3 4 |
| April 28-30, 2026 20-Jul-2026 · Newly retained (>24h) | KnownHost published a provider response thread describing network-level cPanel/WHM/Webmail/WebDisk port blocking, managed-customer patch rollout, log review, access restoration, and a small number of access-attempt findings without active-compromise signs in reviewed cases. 36 | Freshness: Newly retained (>24h); use as provider-response and bounded telemetry evidence, not an end-customer victim list. |
| April 29, 2026 | watchTowr published technical analysis and public PoC; Rapid7 published an emergent-threat overview. | Exploitability became broadly reproducible for capable operators. 5 6 |
| April 27-May 4, 2026 20-Jul-2026 · Newly retained (>24h) | CrowdSec reported first observed CVE-2026-41940 activity on April 27, 282 distinct IPs tied to the issue through May 4, a significant reconnaissance campaign, dedicated detection coverage, and WAF virtual patching guidance. 34 | Freshness: Newly retained (>24h); use as bounded reconnaissance/detection telemetry, not a named-victim list. |
| April 30, 2026 | Shadowserver reported at least 44,000 likely compromised IPs seen scanning honeypots. | Exploitation moved beyond theoretical risk into large telemetry signal. 8 |
| April 30, 2026 28-Jun-2026 · Newly retained (>24h) | CISA added CVE-2026-41940 to the Known Exploited Vulnerabilities catalog; the KEV JSON records a May 3, 2026 due date and known ransomware-campaign-use flag. 2 | Freshness: Newly retained (>24h); use April 30 as the official KEV catalog date while noting cPanel's May 1 response reference separately. |
| April 30, 2026 28-Jun-2026 · Newly retained (>24h) | Cloudflare published an emergency WAF managed-rule release for cPanel & WHM authentication-bypass traffic related to CVE-2026-41940. 23 | Freshness: Newly retained (>24h); use as compensating-control evidence, not as a replacement for vendor patching. |
| May 1, 2026 26-Jun-2026 · Newly retained (>24h) | Censys reported a May 1 spike in GreyNoise-classified malicious hosts concentrated on cPanel/WHM and identified Mirai-pattern and .sorry ransomware activity. 20 | Use this as activity-cluster evidence, not as a named-victim list. |
| May 2, 2026 | BleepingComputer reported mass exploitation in Sorry ransomware attacks. | IR scoping should include ransomware and web-host compromise checks. 7 |
| May 2, 2026 26-Jun-2026 · Newly retained (>24h) | Ctrl-Alt-Intel reported an unknown actor using public CVE-2026-41940 PoC tooling against South-East Asian government/military entities plus MSP/hosting-provider targets. 21 | Treat as reported targeting/attempted exploitation with no firm attribution and no automatic compromise conclusion. |
| May 5, 2026 19-Jul-2026 · Newly retained (>24h) | BinaryLane updated its CVE-2026-41940 advisory, describing active exploitation against cPanel servers on its network and provider/customer mitigation responsibilities. 33 | Freshness: Newly retained (>24h); use as provider advisory-pattern evidence, not as a named end-customer victim list. |
| May 6, 2026 08-Jul-2026 · Newly retained (>24h) | Unfold Security published CVE-2026-41940 detection research focused on behavior-based cPanel session and access-log correlation instead of PoC-string matching. 28 | Freshness: Newly retained (>24h); use as detection-engineering guidance while keeping raw rule and exploit material out of broad stakeholder summaries. |
| May 6, 2026 17-Jul-2026 · Newly retained (>24h) | Bluehost published a CVE-2026-41940 compromise-check guide for customers that covers version validation, ransomware-marker checks, persistence and SSH-key review, cPanel template tampering, shell-history review, evidence preservation, credential rotation, and hosted-account scoping. 31 | Freshness: Newly retained (>24h); use as provider-scoped IR checklist evidence while avoiding republication of raw command bodies and hashes. |
| May 10, 2026 | cPanel published response, actions, and next-steps post with root-cause summary and adoption status. | Vendor clarified session-management cause and response path. 4 |
| May 11, 2026 27-Jun-2026 · Newly retained (>24h) | QiAnXin XLab reported Mr_Rot13 exploitation of CVE-2026-41940 to deploy Filemanager backdoor tooling and credential-theft/webshell/persistence components. 22 | Use this as activity-cluster and hunt-priority evidence; do not publish raw payload details or convert it into a named-victim list. |
| May 15, 2026 03-Jul-2026 · Newly retained (>24h) | ThreatLocker published Sorry ransomware malware-analysis detail for CVE-2026-41940 follow-on activity, including Linux encryptor behavior, host markers, service/process disruption, SSH propagation attempts, and recovery implications. 27 | Freshness: Newly retained (>24h); use as bounded hunt and recovery guidance, not as a named-victim list or universal payload path. |
| May 4 and May 13, 2026 28-Jun-2026 · Newly retained (>24h) | Shadowserver added compromised-website report tags for CVE-2026-41940-related cPanel/Roundcube compromise patterns, including sorry-ransomware, whmstealer, and mr-rot13. 24 | Freshness: Newly retained (>24h); use for reporting workflow and activity tags, not as a raw victim list. |
| May 18, 2026 01-Jul-2026 · Newly retained (>24h) | Liquid Web's status incident recorded ongoing remediation following CVE-2026-41940, extended support impact, and restoration work where compromise was evident. 25 | Freshness: Newly retained (>24h); use as named hosting-provider disclosure evidence, not as a raw customer-victim list. |
| May 20, 2026 19-Jul-2026 · Newly retained (>24h) | InMotion Hosting published direct customer follow-up guidance describing fleet port blocking and patching, exceptions where ports stayed blocked, customer outreach, and post-patch review steps. 32 | Freshness: Newly retained (>24h); strengthens provider/customer-notice scoping while avoiding raw exploit-chain detail. |
| May 26, 2026 01-Jul-2026 · Newly retained (>24h) | InMotion Hosting reported fleet-level blocking and patching, 99% of potentially affected customers protected without service disruption, and hands-on remediation for a small subset of environments. 26 | Freshness: Newly retained (>24h); use as provider-response and exposure-scoping evidence, not confirmed compromise for every customer. |
| May 2026 20-Jul-2026 · Newly retained (>24h) | Beazley Security published insurer-adjacent CVE-2026-41940 guidance for exposed self-hosted cPanel review, vendor detection-script use, perimeter exposure management, and MDR threat hunts. 35 | Freshness: Newly retained (>24h); use for insurance and provider-evidence scoping while keeping raw exploit examples out of the public brief. |
| May 27, 2026 13-Jul-2026 · Newly retained (>24h) | Proofpoint published network-telemetry reporting that described CVE-2026-41940 as part of a multi-actor cPanel exploitation cluster and observed use in compromised-website web-inject chains such as TA569/SocGholish. 29 | Freshness: Newly retained (>24h); use as activity-cluster and prioritization evidence, not as a named-victim list or proof that every compromised website involved TA569. |
| June 17, 2026 26-Jun-2026 · Newly retained (>24h) | NVD shows CISA ADP SSVC metadata and VulnCheck affected-record changes added to the CVE record. 1 | Official metadata reinforces active exploitation, automatable exploitation, and total technical-impact framing. |
| July 9, 2026 17-Jul-2026 · Newly retained (>24h) | Bluehost updated customer-facing guidance for VPS and Dedicated customers, including active-exploitation language, temporary cPanel/WHM/Webmail/WebDisk port restrictions for affected servers, CentOS 6 migration as durable remediation, backup/log-review advice, and customer communication language for potentially affected servers. 30 | Freshness: Newly retained (>24h); use as named provider-response and customer-notice evidence, not as a named end-customer victim list. |
20-Real World Examples
| Example | What It Shows | Boundary |
|---|---|---|
| Sorry ransomware reporting 03-Jul-2026 · Newly retained (>24h) | BleepingComputer reports attackers exploited CVE-2026-41940 to breach servers and deploy a Go-based Linux encryptor appending the .sorry extension; ThreatLocker adds bounded malware-analysis detail for host markers, service/process disruption, SSH propagation attempts, and recovery scoping. Freshness: Newly retained (>24h). 7 27 | Use as reported ransomware linkage and hunt guidance; not every exploitation case is ransomware or the same payload path. |
| Censys .sorry exposure telemetry 26-Jun-2026 · Newly retained (>24h) | Censys reported thousands of cPanel/WHM hosts exposing open directories where filenames ended in .sorry, alongside Mirai-pattern activity in malicious-host classifications. 20 | Use as public telemetry and activity-cluster evidence; do not convert exposed directory counts into named victim organizations. |
| Ctrl-Alt-Intel public targeting report 26-Jun-2026 · Newly retained (>24h) | Ctrl-Alt-Intel reported an unknown actor using public CVE-2026-41940 PoC tooling against South-East Asian government/military entities and MSP/hosting-provider targets. 21 | Reported targeting/attempted exploitation is not the same as confirmed compromise, ransomware impact, or attribution to a named actor. |
| Mr_Rot13 / Filemanager activity 27-Jun-2026 · Newly retained (>24h) | QiAnXin XLab reported Mr_Rot13 exploitation of CVE-2026-41940 to deploy Filemanager remote-control tooling, webshells, SSH-key persistence, login-page tampering, and credential-theft components. 22 | Use as source-backed activity-cluster and hunt guidance; do not treat it as a named-victim disclosure or publish raw attacker infrastructure. |
| Shadowserver compromised-website report tags 28-Jun-2026 · Newly retained (>24h) | Shadowserver describes CVE-2026-41940-related cPanel/Roundcube compromise reporting with sorry-ransomware, whmstealer, and mr-rot13 tags. Freshness: Newly retained (>24h). 24 | Use as report-routing and activity-tag evidence; do not publish Shadowserver event data as a victim list. |
| Hosting-provider customer notices 20-Jul-2026 · Newly retained (>24h) | Liquid Web disclosed CVE-2026-41940 remediation and restoration work where compromise was evident; InMotion disclosed network-edge blocking, fleet patching, direct remediation for a small subset of customer environments, blocked exceptions, customer outreach, and post-patch customer actions; Bluehost described active exploitation, temporary port restrictions, CentOS 6 migration pressure, backup/log-review guidance, and compromise-check categories for VPS/Dedicated customers; BinaryLane described active exploitation on its network and customer/provider mitigation responsibilities; KnownHost described network-wide port blocking, managed-customer patching, log review, and bounded access-attempt findings. Freshness: Newly retained (>24h). 25 26 30 31 32 33 36 | Use as provider-response and customer-scoping evidence; do not infer all customers were compromised or publish end-customer names. |
| CrowdSec reconnaissance telemetry 20-Jul-2026 · Newly retained (>24h) | CrowdSec reported first observed activity on April 27, 282 distinct IPs tied to CVE-2026-41940 through May 4, a significant reconnaissance campaign, and dedicated detection/WAF virtual-patching coverage. Freshness: Newly retained (>24h). 34 | Use as bounded telemetry and control evidence; not as a named-victim list or proof that every observed IP achieved compromise. |
| Proofpoint compromised-website web-inject telemetry 13-Jul-2026 · Newly retained (>24h) | Proofpoint described CVE-2026-41940 as part of a multi-actor cPanel exploitation cluster and increasingly observed it in compromised-website web-inject chains such as TA569/SocGholish. Freshness: Newly retained (>24h). 29 | Use as activity-cluster and hosted-site scoping evidence; not a named-victim disclosure and not universal attribution to TA569/SocGholish. |
| Shadowserver 44K+ telemetry | Shadowserver reported at least 44,000 likely compromised IPs seen scanning honeypots. 8 | Telemetry is not a publishable named-victim list and should not be treated as unique customer count. |
| Hosting provider exposure | Rapid7 notes exposed cPanel/WHM instances may number around 1.5 million in simple internet-exposure queries. 6 | Exposure counts vary by scan method and do not equal confirmed compromise. |
| Policyholder / SMB web environment | The realistic real-world pattern is an SMB, hosted website customer, reseller customer, or agency-managed site whose exposure depends on a third-party cPanel/WHM control plane. That may include WordPress, another CMS, ecommerce software, custom sites, mail, databases, or customer portals. 3 6 17 18 | This is a scoping archetype, not a named confirmed victim. |
21-Public Victim / Disclosure Matrix
This card is intentionally reserved for named public victim organizations or companies tied to CVE-2026-41940 exploitation. 26-Jun-2026 · Newly retained (>24h) The June 26 monitor found named public organizations in Ctrl-Alt-Intel reporting, but only as reported targets of public PoC use / attempted exploitation. The retained source set still does not support a validated public list of organizations confirmed compromised by CVE-2026-41940.21 27-Jun-2026 · Newly retained (>24h) The June 27 monitor retained Mr_Rot13 activity-cluster reporting, but it did not add a reliable named public victim organization or company directly tied to confirmed CVE-2026-41940 compromise.22 28-Jun-2026 · Newly retained (>24h) The June 28 monitor retained Shadowserver report tags and Cloudflare WAF guidance, but found no new reliable named public victim organization or company. Freshness: Newly retained (>24h).23 24 01-Jul-2026 · Newly retained (>24h) The July 1 monitor retained named hosting-provider disclosure evidence from Liquid Web and InMotion Hosting. These sources improve provider/customer-notice scoping, but they do not publish a reliable named end-customer victim list. Freshness: Newly retained (>24h).25 26 03-Jul-2026 · Newly retained (>24h) The July 3 monitor retained ThreatLocker's Sorry ransomware malware-analysis detail, but found no new reliable named victim organization or company. Freshness: Newly retained (>24h).27 17-Jul-2026 · Newly retained (>24h) The July 17 monitor retained Bluehost as a named hosting-provider customer-notice source. The sources improve VPS/Dedicated, CentOS 6, outage, backup, log-review, and compromise-check scoping, but they do not publish a reliable named end-customer victim list. Freshness: Newly retained (>24h).30 31 19-Jul-2026 · Newly retained (>24h) The July 19 monitor retained InMotion Hosting's direct follow-up and BinaryLane's advisory as named provider/customer-notice sources. These sources strengthen provider-response and unmanaged-VPS scoping, but they do not publish a reliable named end-customer victim list. Freshness: Newly retained (>24h).32 33 20-Jul-2026 · Newly retained (>24h) The July 20 monitor retained KnownHost as an additional named provider/customer-notice source and retained CrowdSec/Beazley Security for telemetry, detection-control, and insurer-adjacent scoping. These sources improve provider-response and evidence-request language, but they do not publish a reliable named end-customer victim list. Freshness: Newly retained (>24h).34 35 36
| Organization / Entity | Public Status | Reported Impact | Evidence Boundary | How To Use It |
|---|---|---|---|---|
| Philippine Coast Guard; Philippine Air Force, 15th Strike Wing; Philippine Government Arsenal; Lao Ministry of National Defence; Lao Ministry of Natural Resources and Environment 26-Jun-2026 · Newly retained (>24h) | Reported by Ctrl-Alt-Intel on May 2, 2026 as targets of an unknown actor's CVE-2026-41940 public-PoC use. 21 | Reported targeting / attempted exploitation; no confirmed compromise, data theft, ransomware impact, or victim statement is established by this source. | Use as named public targeting evidence only. Do not describe these organizations as confirmed breached victims unless a reliable source later confirms compromise or impact. | Use for government/MSP scoping questions, targeted-exploitation caveats, and activity-cluster monitoring. |
| Unnamed MSPs and hosting providers in the Philippines, Laos, Canada, South Africa, and the United States 26-Jun-2026 · Newly retained (>24h) | Ctrl-Alt-Intel reported MSP/hosting-provider targeting alongside the named South-East Asian government/military targets. 21 | No public organization names, compromise confirmations, customer notices, or provider statements were retained for this group. | Do not populate unnamed providers as victims; use this as sector/victimology guidance only. | Prioritize hosting providers, MSPs, resellers, and web agencies for patch-evidence and detection-script follow-up. |
| Liquid Web 01-Jul-2026 · Newly retained (>24h) | Public hosting-provider status incident with CVE-2026-41940 remediation updates from April 28 through May 18, 2026. 25 | Liquid Web reported patching and mitigation activity, elevated support volume, remaining remediation, and restoration work for servers where compromise was evident. Freshness: Newly retained (>24h). | Treat as a named provider/customer-notice disclosure. Do not infer that Liquid Web corporate systems, all Liquid Web customers, or any unnamed customer organization were compromised. | Use for provider-attestation questions, restore/remediation scoping, and customer communication patterns. |
| InMotion Hosting 19-Jul-2026 · Newly retained (>24h) | Public provider response report dated May 26, 2026 and direct customer follow-up updated May 20, 2026 covering fleet-level CVE-2026-41940 response. 26 32 | InMotion reported network-edge blocking, fleet patching, 99% of potentially affected customers protected without service disruption, direct remediation for a small subset of customer environments, exceptions where blocked ports remained in place, customer outreach, and customer review actions. Freshness: Newly retained (>24h). | Treat as provider-response and exposure-scoping evidence, not confirmed compromise for every potentially affected customer and not a named end-customer victim list. | Use as a benchmark for questions to managed hosts: port blocking, patch evidence, exception handling, direct outreach, and remediation support. |
| BinaryLane 19-Jul-2026 · Newly retained (>24h) | Public provider advisory last updated May 5, 2026 covering CVE-2026-41940 active exploitation and mitigation responsibilities. 33 | BinaryLane described active exploitation against cPanel servers on its network, provider-side mitigation/notification, and patch-validation responsibilities for unmanaged VPS customers. Freshness: Newly retained (>24h). | Treat as a named provider/customer-notice disclosure. Do not infer that BinaryLane corporate systems, all BinaryLane customers, or any unnamed customer organization was compromised. | Use for provider-attestation questions, unmanaged-VPS responsibility scoping, and customer communication patterns. |
| Bluehost 17-Jul-2026 · Newly retained (>24h) | Public provider customer guidance updated July 9, 2026, plus a related May 6 compromise-check guide for CVE-2026-41940. 30 31 | Bluehost described active exploitation, temporary access restrictions on affected VPS/Dedicated cPanel ports, CentOS 6 migration needs, backup/log-review guidance, and compromise-check categories. Freshness: Newly retained (>24h). | Treat as a named provider/customer-notice disclosure. Do not infer that Bluehost corporate systems, every Bluehost VPS/Dedicated customer, or any unnamed customer organization was compromised. | Use for provider-attestation questions, outage/customer-notice review, unsupported-OS migration scoping, and compromise-review evidence requests. |
| KnownHost 20-Jul-2026 · Newly retained (>24h) | Public provider response thread dated April 28-30, 2026 covering CVE-2026-41940 port blocking, patch rollout, access restoration, and log-review findings. 36 | KnownHost described network-level blocking of cPanel, WHM, Webmail, and WebDisk ports, managed-customer patch rollout across thousands of machines, later access restoration after patching, and a small number of access-attempt findings without active-compromise signs in reviewed cases. Freshness: Newly retained (>24h). | Treat as a named provider/customer-notice disclosure and bounded provider telemetry. Do not infer that KnownHost corporate systems, all KnownHost customers, or any unnamed customer organization was compromised. | Use for provider-attestation questions, port-blocking evidence, log-review scope, access-attempt findings, and customer-contact criteria. |
| Confirmed compromised named end-customer organizations | No validated public end-customer company/org compromise list retained in this run. | Aggregate telemetry, exposed-instance counts, public targeting reports, provider-wide notices, and community victim anecdotes do not create a verified end-customer victim list. | Do not convert Shadowserver telemetry/report tags, Censys open-directory counts, CrowdSec IP counts, exposed-instance totals, provider support queues, provider-wide port restrictions, provider exception lists, provider access-attempt counts, or individual/forum anecdotes into organization-level customer victim claims. 6 7 8 20 21 24 25 26 30 31 32 33 34 36 | Ask policyholders, hosting providers, MSPs, and web agencies for local evidence instead of relying on public victim naming. |
22-Associated Campaigns / Activity Clusters
This card tracks source-backed activity associated with CVE-2026-41940 without confusing those activity clusters with named victim organizations. A cluster can be useful for scoping even when public sources do not identify the operator, campaign name, or victim companies.
| Campaign / Activity Cluster | Activity Type | Source-Backed Evidence | Defensive Use | Boundary |
|---|---|---|---|---|
| CISA KEV-recognized exploitation 28-Jun-2026 · Newly retained (>24h) | Known exploited vulnerability activity | CISA's official KEV feed records April 30 catalog addition, May 3 due date, and known ransomware-campaign-use status; cPanel's response separately references May 1 confirmation. 2 4 | Use KEV status to justify emergency patch validation, provider outreach, and evidence preservation. | KEV status does not identify a specific actor, victim list, or single campaign. |
| Sorry ransomware exploitation reporting 26-Jun-2026 · Newly retained (>24h) | Reported ransomware follow-on activity | BleepingComputer reports CVE-2026-41940 exploitation in Sorry ransomware attacks, including Linux-host encryption indicators. 03-Jul-2026 · Newly retained (>24h) ThreatLocker adds malware-analysis detail for Sorry host markers, service/process disruption, SSH propagation attempts, and recovery scoping; Censys separately observed thousands of cPanel/WHM hosts exposing open directories where filenames ended in .sorry; Shadowserver later describes sorry-ransomware report tags for CVE-2026-41940-related compromise reporting. Freshness: Newly retained (>24h). 7 16 20 24 27 | Scope for ransomware notes, .sorry extensions, host-level marker files, Linux encryptor activity, service/process interruption, SSH propagation attempts, backup impact, and hosted-site recovery needs. | Treat Sorry as a reported exploitation outcome; do not assume every cPanel compromise became ransomware or used the same payload path. |
| Mirai-pattern post-compromise activity 26-Jun-2026 · Newly retained (>24h) | Botnet / DDoS-client deployment signal | Censys reported malicious-host classifications with patterns consistent with Mirai and noted at least two distinct active attack paths: Mirai-variant deployment and .sorry ransomware activity. 20 | Check compromised cPanel hosts for DDoS clients, miners, new privileged users, firewall changes, suspicious processes, outbound attack traffic, and customer-hosted credential exposure. | Censys did not prove that the malware binary itself exploited cPanel directly; treat this as post-compromise deployment activity tied to the broader CVE-2026-41940 exploitation window. |
| South-East Asia government/military public-PoC targeting 26-Jun-2026 · Newly retained (>24h) | Targeted exploitation attempts / public PoC operationalization | Ctrl-Alt-Intel reported an unknown actor interactively attempting CVE-2026-41940 exploitation against named South-East Asian government/military entities and MSP/hosting-provider targets using public PoC tooling. 21 | For government, defense-sector, MSP, and hosting-provider environments, raise urgency from opportunistic-only assumptions to targeted-exploitation scoping and review for pivot tooling or persistence. | No firm attribution. Reported targeting/attempted exploitation does not equal confirmed compromise for every named organization. |
| Mr_Rot13 / Filemanager backdoor activity 27-Jun-2026 · Newly retained (>24h) | Named threat-actor activity / backdoor and credential-theft follow-on | QiAnXin XLab attributed one CVE-2026-41940 exploitation stream to Mr_Rot13 and reported automated attacks that deployed Filemanager remote-control tooling, PHP webshells, SSH-key persistence, login-page tampering, credential collection, and backdoor components. Shadowserver later added mr-rot13 report tags for related backdoors. Freshness: Newly retained (>24h). 22 24 | For any host with suspected exposure or compromise, hunt beyond ransomware: review SSH keys, cPanel-facing assets, webshells, credential access, remote-control services, suspicious processes, and persistence mechanisms. | This is a source-backed activity cluster, not a complete attribution for all exploitation and not a named-victim disclosure. Keep raw attacker infrastructure out of broad public summaries. |
| Shadowserver compromised-website report tags 28-Jun-2026 · Newly retained (>24h) | Security-vendor report / activity-tag cluster | Shadowserver describes cPanel and related Roundcube instances attempting honeypot exploitation or seen in darknets as likely CVE-2026-41940-related compromise, with sorry-ransomware, whmstealer, and mr-rot13 tags. Freshness: Newly retained (>24h). 24 | Use Shadowserver notifications and tags to route provider/ASN follow-up, website integrity checks, credential-stealer review, ransomware scoping, and Mr_Rot13/Filemanager hunts. | Report tags and telemetry are not named-victim disclosures, and raw event lists should not be republished. |
| CrowdSec reconnaissance and detection-control telemetry 20-Jul-2026 · Newly retained (>24h) | Reconnaissance / detection coverage / WAF virtual patching | CrowdSec reported first observed CVE-2026-41940 activity on April 27, 282 distinct IPs tied to the vulnerability between April 27 and May 4, a significant reconnaissance campaign since April 30, dedicated detection coverage, and WAF virtual patching for exposed setups. Freshness: Newly retained (>24h). 34 | Use as a bounded activity-cluster signal for exposed cPanel/WHM discovery pressure and as a control-evidence prompt for SOC/WAF teams that use CrowdSec. | This does not name victims, prove each observed IP achieved compromise, or replace vendor patch and local forensic evidence. |
| Hosting-provider remediation and customer-notice pattern 20-Jul-2026 · Newly retained (>24h) | Provider advisory / fleet remediation / customer-support cluster | Liquid Web publicly described CVE-2026-41940-related patching, support-volume impact, and restoration where compromise was evident; InMotion reported network-edge blocking, fleet patching, 99% of potentially affected customers protected without service disruption, direct remediation for a small subset of customer environments, blocked exceptions, customer outreach, and post-patch customer actions; Bluehost described active exploitation, temporary port restrictions for affected VPS/Dedicated servers, CentOS 6 migration guidance, backups/log review, and compromise-check categories; BinaryLane described active exploitation on its network and customer/provider mitigation responsibilities; KnownHost described port blocking, managed-customer patch rollout, access restoration, log review, and bounded access-attempt findings; Beazley Security adds insurer-adjacent exposure-management and MDR hunt language. Freshness: Newly retained (>24h). 25 26 30 31 32 33 35 36 | Use as a checklist for provider/MSP outreach: fixed builds, port restrictions, exception handling for unsupported cPanel versions, OS migration, customer notifications, unmanaged-VPS responsibility, restore status, backups/log review, access-attempt findings, MDR hunts, and compromise-review evidence. | This is a provider-response pattern, not attribution to a threat actor and not a public list of customer victims. |
| Compromised-website web-inject chains / TA569-SocGholish lens 13-Jul-2026 · Newly retained (>24h) | Compromised-website abuse / traffic-delivery and web-inject activity | Proofpoint's May 27 network-telemetry report says CVE-2026-41940 exploitation evolved into a multi-actor campaign and that Proofpoint increasingly observed the vulnerability in attack chains used by actors that compromise legitimate websites via web inject, such as TA569/SocGholish. Freshness: Newly retained (>24h). 29 | For compromised cPanel/WHM hosts and hosted sites, include website-defacement, injected JavaScript, redirect, traffic-distribution, and downstream visitor-impact checks in addition to ransomware and backdoor hunts. | Use this as an activity-cluster and scoping lens only. Proofpoint does not provide a named victim list here and this does not prove every CVE-2026-41940 compromise involved TA569 or SocGholish. |
| Shadowserver large-scale telemetry signal | Aggregate scanning / likely compromise telemetry | Shadowserver reported at least 44,000 likely compromised IPs observed scanning honeypots. 7 8 | Use as scale and urgency signal for exposure validation, not as a customer notification list. | Aggregate telemetry is not named-victim evidence and does not prove unique organizations compromised. |
| Public PoC / copycat exploitation risk | Exploit reproducibility after public technical analysis | watchTowr published technical analysis and PoC after vendor fixes, and Rapid7 described exploitability and exposed-instance context. 5 6 | Assume opportunistic exploitation becomes easier after public PoC; prioritize patch and log review over passive waiting. | PoC availability is an activity-enablement factor, not attribution to a named campaign. |
| Exposed hosting-control-plane scanning | Internet-facing cPanel/WHM discovery and exploitation pressure | Rapid7, CyCognito, Picus, and Qualys frame the issue as internet-facing hosting-control-plane exposure with downstream hosted-asset impact. 6 9 10 11 | Ask providers/MSPs to identify exposed cPanel/WHM/WP Squared assets, patch state, service restrictions, and detection-script results. | Exposure and scanning pressure are not the same as confirmed compromise or victim naming. |
| Future AI Agent population rule | Monitor-maintained activity cluster | Populate only when a reliable public source ties a ransomware family, intrusion set, botnet, scanning cluster, exploit campaign, hosting-provider advisory pattern, or named actor to CVE-2026-41940. | When a cluster is source-backed, update Timeline, Real World Examples, Source Deconfliction, AI Agent Delta Updates, Citations, and any affected response guidance. | Do not turn SEO rewrites, exploit reposts, unverified forum claims, or aggregate exposure counts into campaign claims. |
23-Threat Actor Glossary
Public attribution for CVE-2026-41940 is mixed and should stay bounded to the specific source-backed activity being discussed. This card separates named activity clusters from universal attribution claims.
| Name / Label | How To Use It | Boundary |
|---|---|---|
| Sorry ransomware | Use as a reported ransomware follow-on outcome after CVE-2026-41940 exploitation; scope for .sorry extensions, ransom notes, backup impact, and Linux-host encryption. 7 16 24 | Reported ransomware linkage does not mean every exposed or compromised cPanel host was encrypted. |
| Mr_Rot13 / Filemanager 27-Jun-2026 · Newly retained (>24h) | Use as a source-backed hunt lens for backdoors, webshells, SSH-key persistence, login-page tampering, credential collection, and Filemanager-style remote control. 22 24 | Do not attribute all CVE-2026-41940 exploitation to Mr_Rot13; apply only where local or source-backed evidence supports it. |
| Unknown South-East Asia public-PoC operator | Use for targeted-exploitation scoping against the named government/military targets and MSP/hosting-provider patterns reported by Ctrl-Alt-Intel. 21 | Reported targeting or attempted exploitation is not the same as confirmed compromise. |
| whmstealer report tag | Use as a Shadowserver reporting/tagging signal for credential-theft-oriented compromise follow-up. 24 | Treat report tags as defensive routing metadata, not as standalone attribution or victim evidence. |
24-Term Glossary
| Term | Definition | Why It Matters |
|---|---|---|
| WHM | WebHost Manager; server-level administration interface associated with cPanel hosting environments. | Compromise can affect multiple hosted accounts and sites. |
| cPanel | A widely used web-hosting control panel for managing websites, CMS installs, files, domains, databases, email, customer accounts, and hosting administration. | It is the affected control-plane layer, not a WordPress component. |
| WP Squared / WP2 | A WebPros/cPanel product listed in the vendor advisory as affected before fixed build 136.1.7; treat it as part of the hosting control-plane scope, not as WordPress core, a plugin, or a theme. | Scope should not stop at cPanel & WHM only, and the WP2 name can cause confusion with WordPress. |
| Hosted workload relationship | WordPress, other CMS platforms, ecommerce sites, custom sites, databases, and mail may be downstream workloads managed through cPanel, but CVE-2026-41940 is in the cPanel & WHM / WP Squared control plane. | Prevents inaccurate stakeholder messaging and patch ownership confusion. |
| CRLF injection | Injection of carriage-return/line-feed characters to manipulate line-oriented parsing or file content. | Public analyses frame the exploit around CRLF manipulation of session handling. |
| cpsrvd | cPanel service daemon referenced in vendor restart and mitigation guidance. | Patch validation requires service restart and version confirmation. |
| CISA KEV | Known Exploited Vulnerabilities catalog. | KEV status means active exploitation is officially recognized. |
26-Talking Points
| Audience | Talk Track |
|---|---|
| Executives | This is a hosting control-plane issue, not just a website bug. If our business depends on hosted sites, portals, mail, or databases running behind cPanel/WHM, we need assurance that the environment is patched and checked for compromise. |
| IT / MSP | Confirm exact fixed build, restart cpsrvd, run the vendor detection script, preserve logs, and review session/access artifacts before cleanup. |
| Claims / counsel | For affected SMBs, the key question is whether a vulnerable control panel was merely exposed or whether administrative access, website content, customer data, backups, or ransomware impact occurred. |
| Client-facing advisor | Ask the hosting provider or web agency for patch attestation, detection-script results, exposure window, and evidence of post-exploitation review. |
Scoping Call Quote
“CVE-2026-41940 is a critical cPanel and WHM authentication bypass. The practical concern is that an attacker may not need a password to reach administrative control of a hosting environment. For an SMB, that may mean the risk sits with a hosting provider, reseller, agency, or MSP rather than inside the company's own IT stack. This is not limited to WordPress; any website, CMS, mail, database, file, or customer-hosting workflow managed through the vulnerable control panel can be in scope. The first question is not only whether the patch was applied, but whether the environment was checked for session artifacts, admin activity, hosted-asset changes, and ransomware traces during the exposure window.”
27-Common Questions Q&A
| Question | Answer |
|---|---|
| Is CVE-2026-41940 a WordPress vulnerability? | No. This is a critical authentication bypass in cPanel & WHM and WP Squared, not a WordPress core, plugin, or theme vulnerability. WordPress is only one common downstream workload. The same control panel can manage many kinds of websites, CMS platforms, databases, mailboxes, domains, customer accounts, and hosted services. 3 13 17 18 |
| Why should website owners care if the flaw is not in their website software? | Because the vulnerable layer can sit above the sites. cPanel & WHM can manage websites, domains, databases, email, files, accounts, and server configuration; compromise of the hosting control plane can cascade into all hosted websites, whether they run WordPress, another CMS, ecommerce software, custom code, or static content. 6 11 17 18 |
| What is the shortest accurate description? | CVE-2026-41940 is a critical authentication bypass in the cPanel & WHM hosting control panel. It is not a WordPress vulnerability and is not limited to WordPress environments. Successful exploitation can give attackers administrative access to the hosting control plane and the websites, databases, files, mail, and customer environments managed through it. 3 6 13 17 |
| Does patching alone close the incident? | Patching is mandatory, but it does not prove the host was clean during the exposure window. Run the vendor detection script, preserve and review session files and access logs, and scope administrative actions, hosted-site changes, ransomware traces, SSH-key or persistence changes, cPanel template tampering, and hosted-account impact. 3 4 7 31 |
| Do the exposed-instance and telemetry numbers equal confirmed victims? | No. Rapid7 exposed-instance context and Shadowserver telemetry are useful urgency signals, but they are not verified named-victim lists or customer compromise counts. Use them for scoping priority, not victim assertions. 6 8 |
| Who is behind exploitation, and is Icarus involved? | The retained public source set ties exploitation to Sorry ransomware reporting, large-scale scanning/compromise telemetry, and a Mr_Rot13/Filemanager activity stream. 27-Jun-2026 · Newly retained (>24h) QiAnXin XLab attributes one exploitation stream to Mr_Rot13, but that should not be treated as universal attribution for every exposed or compromised cPanel host. The source set still does not attribute CVE-2026-41940 exploitation to Icarus, UNC6395, or another named SaaS-extortion actor. 2 7 8 22 |
| How would a threat actor find a cPanel URL before reconnaissance? | It is usually exposure enumeration, not luck. Threat actors can look for common cPanel and WHM hostnames, common management ports, HTTP titles, TLS certificates, provider fingerprints, passive attack-surface data, search-engine indexed panels, hosting-provider patterns, and previously shared target lists where locally evidenced. The defensive answer is to know where cPanel/WHM is exposed, restrict management access, and require the operator to provide version, patch, and log-review evidence. 3 6 10 17 |
| What is WP Squared? | WP Squared, also referenced as WP2 in the cPanel advisory, is a WebPros/cPanel product included in the affected product family for this CVE. It should be scoped as part of the hosting control plane, not as WordPress core, a WordPress plugin, or a WordPress theme. If a provider uses WP Squared, ask for the fixed build, patch timestamp, service restart, detection-script output, and log review just as you would for cPanel & WHM. 3 6 |
| Can an insurer remotely check whether a policyholder uses cPanel? | Partially. With appropriate authorization, an insurer or assessor can use passive attack-surface data, DNS names such as cpanel, whm, or webmail, common service ports such as 2082/2083/2086/2087/2095/2096, HTTP titles, TLS certificates, and provider fingerprints to identify probable cPanel/WHM exposure. That does not prove patch status or compromise; the policyholder or provider still needs to produce version, patch, detection-script, and log-review evidence. 3 6 10 |
Expansion Research Add
Expansion research was used specifically to prevent a misleading WordPress-only framing. WordPress can be a downstream workload managed through cPanel, but so can other CMS platforms, ecommerce sites, custom websites, mail, files, databases, and customer-hosting workflows. The vulnerability is in the cPanel & WHM / WP Squared control plane.
28-Tier 0 Through Tier 8 Source Summary
| Tier | Checked | Useful Hits | Used | Not Used |
|---|---|---|---|---|
| Tier 0 - Government / CVE authority | 3 | 3 | 3 | 0 |
| Tier 1 - Vendor / CNA / primary advisory | 7 | 4 | 4 | 3 |
| Tier 2 - Practitioner / telemetry / security research | 29 | 20 | 20 | 9 |
| Tier 3 - Corroborating security media | 11 | 2 | 2 | 9 |
| Tier 4 - Community signal | 4 | 1 | 0 | 4 |
| Tier 5 - Custom Source (defined by user) | 0 | 0 | 0 | 0 |
| Tier 6 - Custom Integrations with API/Keys | 1 | 0 | 0 | 1 |
| Tier 7 - Inner Discovery / Carved URLs | 5 | 3 | 3 | 2 |
| Tier 8 - Expansion Research | 6 | 5 | 5 | 1 |
| Total | 66 | 38 | 35 | 29 |
29-Source Deconfliction
| Source Issue | Agreement / Difference | Tension or Contradiction | How To Use It |
|---|---|---|---|
| Vulnerable product vs. downstream workload | Sources identify cPanel & WHM / WP Squared as the affected product, while expansion sources show cPanel is a broader hosting control plane for websites, CMS platforms, mail, databases, files, and customer accounts. | Calling this a WordPress vulnerability would be inaccurate, but calling it unrelated to WordPress would miss one common downstream SMB exposure path. | Say “not a WordPress vulnerability; any cPanel-managed hosted workload, including WordPress, may be downstream affected through vulnerable hosting control panels.” 3 13 17 18 |
| Vulnerability naming | Sources agree this is a critical authentication bypass; practitioner analyses explain the CRLF/session-file handling path. | Executive summaries can over-focus on CRLF and obscure the practical admin-access risk. | Use “authentication bypass” for business audiences and preserve CRLF/session details for technical teams. 1 4 5 6 |
| KEV and exploitation status 28-Jun-2026 · Newly retained (>24h) | CISA alert/catalog JSON records April 30, 2026 as the KEV addition date, with May 3 due date and known ransomware-campaign-use status; cPanel's response separately references May 1 confirmation. | KEV status establishes active exploitation urgency but not every exposed host is compromised, and date references can differ depending on whether the source is the CISA feed or vendor response post. | Use April 30 for official KEV catalog timing, preserve the May 1 cPanel response reference where discussing vendor communications, and validate exposure locally. Freshness: Newly retained (>24h). 2 4 |
| Public exploitability | watchTowr published technical analysis and PoC after vendor patches. | PoC availability increases copycat risk but does not replace local evidence. | Prioritize patch validation, detection-script results, logs, and session artifacts. 5 6 |
| Detection script vs. behavior detections 08-Jul-2026 · Newly retained (>24h) | cPanel's vendor script remains the highest-priority local artifact check, while Unfold adds behavior-based session/access-log correlation guidance for exploit mechanics. | Detection teams should not depend only on public PoC strings or one script run; local log schemas, retention windows, and cleanup timing affect what can be proven. | Run the vendor script, preserve session files and access logs, and add behavior detections for abnormal session promotion and cpsess usage without a normal login path. Freshness: Newly retained (>24h). 3 4 28 |
| Exposure vs. victim count | Rapid7 and Shadowserver provide exposure and telemetry context. | 1.5M exposed instances and 44K IP telemetry are not verified named victims. | Use these numbers for urgency and scoping scale, not victim notification claims. 6 8 |
| CrowdSec reconnaissance telemetry vs. compromise proof 20-Jul-2026 · Newly retained (>24h) | CrowdSec adds bounded telemetry for first observed activity, distinct IPs tied to the vulnerability, reconnaissance pressure, dedicated detection coverage, and WAF virtual patching. | CrowdSec's IP count and control guidance improve scoping and defensive validation, but they do not identify named victims or prove every observed source achieved compromise. | Use as activity-cluster and control-evidence context; continue to require fixed-build evidence, vendor-script output, and local log/session review before compromise conclusions. Freshness: Newly retained (>24h). 34 |
| Ransomware linkage 03-Jul-2026 · Newly retained (>24h) | BleepingComputer reports Sorry ransomware as one exploitation outcome; ThreatLocker adds older but newly retained malware-analysis detail for host markers, process/service disruption, SSH propagation attempts, and recovery scoping. | The ransomware linkage does not mean every CVE-2026-41940 compromise followed that path, and malware-analysis indicators are not named-victim disclosures. | Mention Sorry ransomware as a known reported outcome, use ThreatLocker detail for bounded hunting and recovery, and still scope other post-exploitation possibilities. Freshness: Newly retained (>24h). 7 27 |
| Activity clusters vs. named victims | Sources support multiple activity lenses: KEV exploitation, Sorry ransomware reporting, Shadowserver telemetry, public PoC-driven exploitation pressure, and exposed hosting-control-plane scanning. | Those are useful scoping clusters, but they are not public named-victim disclosures. | Use the activity-cluster card for defensive scoping and keep the victim/disclosure matrix reserved for named organizations. 2 5 6 7 8 10 |
| Provider notices vs. end-customer victim list 20-Jul-2026 · Newly retained (>24h) | Liquid Web, InMotion Hosting, Bluehost, BinaryLane, and KnownHost publish named provider-response evidence tied to CVE-2026-41940, including fleet patching, access restrictions, blocked exceptions, support/remediation activity, customer outreach, customer-environment handling, unmanaged-VPS responsibilities, CentOS 6 migration pressure, backup/log-review guidance, compromise-check categories, and provider log-review outcomes. Beazley Security adds insurer-adjacent exposure-management and MDR hunt framing. | Provider-wide response evidence is valuable for scoping, but it does not identify every affected customer and does not prove all potentially exposed customer environments were compromised. | Use provider notices to shape policyholder/provider questions and remediation benchmarks; keep raw customer identities, raw command bodies, raw log lines, hashes, aggregate support queues, provider exception lists, and unsupported victim inferences out of public victim claims. Freshness: Newly retained (>24h). 25 26 30 31 32 33 35 36 |
| Mr_Rot13 attribution vs. universal attribution 27-Jun-2026 · Newly retained (>24h) | QiAnXin XLab attributes one exploitation stream to Mr_Rot13 and describes Filemanager backdoor, webshell, SSH-key persistence, login-page tampering, and credential-theft behavior after CVE-2026-41940 exploitation. | The report improves activity-cluster and hunt guidance, but it does not prove that every exposed cPanel/WHM host was compromised by Mr_Rot13 or provide a verified named-victim list. | Use Mr_Rot13/Filemanager as a bounded campaign/hunting lens and keep broad victim or universal-attribution claims out of the executive summary. 22 |
| Official CVE metadata changes 26-Jun-2026 · Newly retained (>24h) | NVD's June 17 change history adds CISA SSVC metadata and expanded VulnCheck affected-record detail that aligns with the page's emergency-risk framing. | The June 17 metadata is newly retained by this monitor but older than 24 hours; it should not be presented as a fresh breaking update. | Label as Newly retained (>24h) and use it to reinforce active exploitation, automatable exploitation, total technical impact, and branch-specific affected-version scoping. 1 |
| Named targets vs. confirmed victims 26-Jun-2026 · Newly retained (>24h) | Ctrl-Alt-Intel publicly names several government/military entities as targets of CVE-2026-41940 public-PoC use by an unknown actor. | The same source does not establish that every named target was compromised, suffered ransomware impact, or issued a victim statement. | Populate the matrix as reported targeting/attempted exploitation only; do not call the named entities confirmed breached victims without later source confirmation. 21 |
| Censys activity telemetry vs. victimology 26-Jun-2026 · Newly retained (>24h) | Censys adds useful activity-cluster evidence for a cPanel-concentrated malicious-host spike, Mirai-pattern behavior, and .sorry open-directory telemetry. | Censys host counts and open-directory observations are not organization-level victim disclosures. | Use for scoping botnet/ransomware checks and exposure urgency; keep it out of the named-victim matrix except as a boundary caveat. 20 |
| WAF coverage vs. patch status 28-Jun-2026 · Newly retained (>24h) | Cloudflare published an emergency managed WAF rule for CVE-2026-41940-related cPanel & WHM authentication-bypass traffic and still recommended official vendor patches. | WAF coverage can reduce exploit traffic or add logs for assets in path, but it does not prove the underlying cPanel & WHM / WP Squared service is patched or uncompromised. | Treat WAF rule status and logs as compensating-control evidence only; continue to require fixed-build, restart, detection-script, and log-review evidence. Freshness: Newly retained (>24h). 23 |
| Shadowserver report tags vs. victimology 28-Jun-2026 · Newly retained (>24h) | Shadowserver's compromised-website report page ties CVE-2026-41940-related cPanel/Roundcube compromise reporting to sorry-ransomware, whmstealer, and mr-rot13 tags. | Those tags improve routing, hunting, and provider notification workflows, but they are still not publishable named-victim evidence. | Use tags for authorized network follow-up and defensive scoping; do not republish raw event lists or infer named victims from aggregate reporting. Freshness: Newly retained (>24h). 24 |
| Web-inject activity vs. cPanel compromise proof 13-Jul-2026 · Newly retained (>24h) | Proofpoint adds network-telemetry evidence that CVE-2026-41940 exploitation appeared in multi-actor mass exploitation and in compromised-website web-inject chains such as TA569/SocGholish. | The source improves activity-cluster mapping, but it does not name victim organizations, prove every affected cPanel host was used for web injects, or universally attribute CVE-2026-41940 exploitation to TA569. | Use Proofpoint to add hosted-site integrity, redirect, injected-script, and traffic-delivery checks to scoping playbooks. Freshness: Newly retained (>24h). 29 |
| Threat actor attribution | Sources support exploitation, KEV status, public PoC, Shadowserver telemetry/report tags, CrowdSec reconnaissance telemetry, Sorry ransomware reporting, whmstealer report tags, a Mr_Rot13/Filemanager activity stream, and Proofpoint's TA569/SocGholish web-inject scoping lens. | The retained evidence does not attribute this CVE to Icarus/UNC6395 or another named SaaS-extortion actor, and Mr_Rot13 or TA569/SocGholish should not be treated as responsible for all exploitation. | Keep attribution bounded to the specific source-backed activity stream, report tag, or reported ransomware outcome. 2 7 8 22 24 29 34 |
| Remote checks vs. proof 20-Jul-2026 · Newly retained (>24h) | Attack-surface sources support identifying exposed cPanel/WHM-like services from outside the network, and Beazley Security explicitly frames perimeter exposure management plus MDR hunts as response support. | External checks can suggest cPanel usage, but cannot prove patch status, detection-script results, or absence of compromise. | Use remote findings to prioritize policyholder/provider outreach, then request version, patch, log, detection, exposure-management, and MDR hunt evidence. Freshness: Newly retained (>24h). 3 6 10 35 |
30-About the Contributors
| Contributor | Role | Value To This Brief |
|---|---|---|
| NVD, CISA, CVE.org, VulnCheck, and cPanel | Authoritative CVE, KEV, CNA, and vendor record | Anchor the identity, affected products, fixed versions, KEV timing, ransomware-use flag, and vendor response posture. 1 2 3 4 13 14 |
| watchTowr Labs, Rapid7, Unfold Security, CrowdSec, Picus, CyCognito, and Qualys | Technical analysis, detection, and exposure framing | Explain exploit mechanics, public PoC availability, behavior-based detection opportunities, reconnaissance/detection telemetry, exposed-instance context, and control-plane blast radius. 5 6 9 10 11 28 34 |
| Shadowserver, Censys, Ctrl-Alt-Intel, QiAnXin XLab, Cloudflare, Proofpoint, Beazley Security, and hosting-provider notices | Telemetry, activity clusters, targeting, and compensating controls | Add source-backed evidence for compromise telemetry, activity tags, named-target caveats, Mr_Rot13/Filemanager hunting, WAF mitigation context, compromised-website web-inject activity mapping, insurer scoping, and provider-response patterns. 8 20 21 22 23 24 29 35 36 |
| BleepingComputer, TechRadar, and framework sources | Stakeholder framing and ATT&CK mapping | Support ransomware-impact framing, accessible explanation for non-technical stakeholders, and defensive mapping language. 7 12 15 16 |
31-Source Weighting / Relevance
| Source Tier | Use In This Brief | Publication Boundary |
|---|---|---|
| Tier 0 / Tier 1 | Controls CVE identity, KEV status, fixed builds, vendor instructions, affected-version ranges, and official response language. | Use for facts that must survive legal, client, and provider challenge. |
| Tier 2 | Adds exploit mechanics, telemetry, WAF mitigation context, activity clusters, detection/hunting value, and web-inject scoping signals. | Use when it materially improves scoping or action; keep raw operational details out of broad stakeholder copy. |
| Tier 3 | Helps explain ransomware linkage and stakeholder urgency when corroborated by stronger sources. | Do not let media-only claims override NVD, CISA, vendor, CNA, or primary research. |
| Tier 8 / Expansion Research | Clarifies cPanel as a hosting control plane and prevents inaccurate WordPress-only framing. | Use for context, not as primary exploitation proof. |
32-Additional IntelliOS Threat Intel Products on This Topic
33-Notes
Create an account and sign-in to use this card.
Record your personal notes and comments in this card related to this brief.
35-Version Change Log
| Version | Date | Change |
|---|---|---|
| v1.0 | 23-Jun-2026 | Initial CVE / Exploit Watch Brief created from NVD, CISA KEV, cPanel, watchTowr, Rapid7, BleepingComputer, Shadowserver, and supporting sources. |
| v1.1 | 25-Jun-2026 Revised | Clarified pre-recon target discovery for cPanel/WHM endpoints; clarified WP Squared / WP2 as an affected WebPros/cPanel hosting-control-plane product; added AI Agent #3 monitor metadata, delta rules, and scheduled monitoring status. |
| v1.2 | 25-Jun-2026 Added | Added a dedicated Victim Matrix card so future AI Monitoring Agent runs can populate named public victim organizations only when reliable public sources specifically support them. |
| v1.3 | 25-Jun-2026 Added | Added a dedicated Associated Campaigns / Activity Clusters card and monitor rules so exploitation clusters, ransomware associations, telemetry clusters, and public PoC-driven activity can be tracked separately from named victim disclosures. |
| v1.4 | 25-Jun-2026 Revised | Strengthened the IOCs / Observables card with a forensicator-focused compromise proof matrix, explicitly distinguishing the absence of a universal public IOC blocklist from local evidence needed to prove or refute compromise. |
| v1.5 | 26-Jun-2026 Newly retained | AI Monitoring Agent run at 10:02 AM ET retained NVD's June 17 metadata update, Censys May 1 activity-cluster telemetry, and Ctrl-Alt-Intel May 2 public targeting reporting. Added named-target caveats to the Public Victim / Disclosure Matrix, revised Associated Campaigns / Activity Clusters for Mirai-pattern and targeted public-PoC activity, updated Timeline, Real World Examples, Source Deconfliction, Citations, and PANDA index timestamps. No Freshly reported (<24h) source was identified. |
| v1.6 | 27-Jun-2026 Newly retained | AI Monitoring Agent run at 10:02 AM ET retained QiAnXin XLab's May 11 Mr_Rot13/Filemanager activity-cluster reporting as Newly retained (>24h). Revised Associated Campaigns / Activity Clusters, Timeline, Real World Examples, IOCs / Observables, Detection & Hunting, TTPs, Source Deconfliction, Public Victim / Disclosure Matrix caveat, AI Agent Delta Updates, Citations, and PANDA index timestamps. No Freshly reported (<24h) source or new named victim organization was identified. |
| v1.7 | 28-Jun-2026 Newly retained | AI Monitoring Agent run at 10:02 AM ET retained CISA KEV JSON details, Cloudflare's April 30 emergency WAF release, and Shadowserver's compromised-website report tags as Newly retained (>24h). Corrected official KEV timing to April 30, added May 3 due-date and known-ransomware-use context, added compensating-control guidance, revised Associated Campaigns / Activity Clusters for sorry-ransomware/whmstealer/mr-rot13 report tags, updated Timeline, Real World Examples, Public Victim / Disclosure Matrix caveat, Source Deconfliction, Citations, and PANDA index timestamps. No Freshly reported (<24h) source or new named victim organization was identified. |
| v1.7 | 29-Jun-2026 10:03 AM ET | AI Monitoring Agent checked public sources; no source-backed content update identified. No version increment; no findings added, modified, subtracted, or newly qualified. Named-victim search found no reliable public organization or company confirmed compromised by CVE-2026-41940, and associated-campaign/activity-cluster search found no new or changed source-backed cluster. PANDA index date updated to Updated Jun 29, 2026. |
| v1.7 | 30-Jun-2026 10:01 AM ET | AI Monitoring Agent checked public sources; no source-backed content update identified. No version increment; no findings added, modified, subtracted, or newly qualified. Named-victim search found no reliable public organization or company confirmed compromised by CVE-2026-41940, and associated-campaign/activity-cluster search found no new or changed source-backed cluster. PANDA index date updated to Updated Jun 30, 2026. |
| v1.8 | 01-Jul-2026 10:02 AM ET Newly retained | AI Monitoring Agent retained Liquid Web's April 28-May 18 status incident and InMotion Hosting's May 26 provider-response report as Newly retained (>24h). Added hosting-provider disclosure and remediation-pattern evidence to Executive Summary, AI Agent Delta Updates, Why It Matters, Insurance Policyholder Scoping Lens, Timeline, Real World Examples, Public Victim / Disclosure Matrix, Associated Campaigns / Activity Clusters, Source Deconfliction, Citations, and PANDA index timestamps. No Freshly reported (<24h) source, new actor/ransomware family, or reliable named end-customer victim list was identified. |
| v1.8 | 02-Jul-2026 10:04 AM ET | AI Monitoring Agent checked public sources; no source-backed content update identified. No version increment; no findings added, modified, subtracted, or newly qualified. Named-victim search found no reliable public organization or company confirmed compromised by CVE-2026-41940, and associated-campaign/activity-cluster search found no new or changed source-backed cluster. PANDA index date updated to Updated Jul 2, 2026. |
| v1.9 | 03-Jul-2026 10:03 AM ET Newly retained | AI Monitoring Agent retained ThreatLocker's May 15 Sorry ransomware analysis as Newly retained (>24h). Added bounded ransomware hunt and recovery detail to Executive Summary, AI Agent Delta Updates, Timeline, Detection & Hunting, Incident Response Playbook Ideas, IOCs / Observables, TTPs, Real World Examples, Public Victim / Disclosure Matrix caveat, Associated Campaigns / Activity Clusters, Source Deconfliction, Citations, and PANDA index timestamps. No Freshly reported (<24h) source, new named victim organization, new actor, or new ransomware family was identified. |
| v1.9 | 04-Jul-2026 10:02 AM ET | AI Monitoring Agent checked public sources; no source-backed content update identified. No version increment; no findings added, modified, subtracted, or newly qualified. Named-victim search found no reliable public organization or company confirmed compromised by CVE-2026-41940, and associated-campaign/activity-cluster search found no new or changed source-backed cluster. PANDA index date updated to Updated Jul 4, 2026. |
| v1.9 | 05-Jul-2026 10:02 AM ET | AI Monitoring Agent checked public sources; no source-backed content update identified. No version increment; no findings added, modified, subtracted, or newly qualified. Named-victim search found no reliable public organization or company confirmed compromised by CVE-2026-41940, and associated-campaign/activity-cluster search found no new or changed source-backed cluster. PANDA index date updated to Updated Jul 5, 2026. |
| v1.9 | 06-Jul-2026 10:01 AM ET | AI Monitoring Agent checked public sources; no source-backed content update identified. No version increment; no findings added, modified, subtracted, or newly qualified. Named-victim search found no reliable public organization or company confirmed compromised by CVE-2026-41940, and associated-campaign/activity-cluster search found no new or changed source-backed cluster. PANDA index date updated to Updated Jul 6, 2026. |
| v1.9 | 07-Jul-2026 10:04 AM ET | AI Monitoring Agent checked public sources; no source-backed content update identified. No version increment; no findings added, modified, subtracted, or newly qualified. Named-victim search found no reliable public organization or company confirmed compromised by CVE-2026-41940, and associated-campaign/activity-cluster search found no new or changed source-backed cluster. PANDA index date updated to Updated Jul 7, 2026. |
| v1.10 | 08-Jul-2026 10:03 AM ET Newly retained | AI Monitoring Agent retained Unfold Security's May 6 detection research as Newly retained (>24h). Added behavior-based session/access-log correlation guidance to Executive Summary, AI Agent Delta Updates, Timeline, Action Rows, IOCs / Observables, Detection & Hunting, Source Deconfliction, contributor/source weighting context, Citations, and PANDA index timestamps. No Freshly reported (<24h) source, new named victim organization, new activity cluster, new actor, or new ransomware family was identified. |
| v1.10 | 09-Jul-2026 10:03 AM ET | AI Monitoring Agent checked public sources; no source-backed content update identified. No version increment; no findings added, modified, subtracted, or newly qualified. Named-victim search found no reliable public organization or company confirmed compromised by CVE-2026-41940, and associated-campaign/activity-cluster search found no new or changed source-backed cluster. PANDA index date updated to Updated Jul 9, 2026. |
| v1.10 | 10-Jul-2026 10:01 AM ET | AI Monitoring Agent checked public sources; no source-backed content update identified. No version increment; no findings added, modified, subtracted, or newly qualified. Named-victim search found no reliable public organization or company confirmed compromised by CVE-2026-41940, and associated-campaign/activity-cluster search found no new or changed source-backed cluster. PANDA index date updated to Updated Jul 10, 2026. |
| v1.10 | 11-Jul-2026 10:03 AM ET | AI Monitoring Agent checked public sources; no source-backed content update identified. No version increment; no findings added, modified, subtracted, or newly qualified. Named-victim search found no reliable public organization or company confirmed compromised by CVE-2026-41940, and associated-campaign/activity-cluster search found no new or changed source-backed cluster. PANDA index date updated to Updated Jul 11, 2026. |
| v1.10 | 12-Jul-2026 10:02 AM ET | AI Monitoring Agent checked public sources; no source-backed content update identified. No version increment; no findings added, modified, subtracted, or newly qualified. Named-victim search found no reliable public organization or company confirmed compromised by CVE-2026-41940, and associated-campaign/activity-cluster search found no new or changed source-backed cluster. Freshness labels applied to retained sources: none. PANDA index date updated to Updated Jul 12, 2026. |
| v1.11 | 13-Jul-2026 10:03 AM ET Newly retained | AI Monitoring Agent retained Proofpoint's May 27 network-telemetry report as Newly retained (>24h). Added source-backed activity-cluster mapping for multi-actor cPanel exploitation and compromised-website web-inject chains such as TA569/SocGholish. Updated BLUF, Executive Summary, AI Agent Delta Updates, Timeline, Real World Examples, Associated Campaigns / Activity Clusters, Source Deconfliction, Citations, and PANDA index timestamps. No Freshly reported (<24h) source or new named victim organization was identified. PANDA index date updated to Updated Jul 13, 2026. No external email or notification was sent under the current automation no-email policy. |
| v1.11 | 14-Jul-2026 10:02 AM ET | AI Monitoring Agent checked public sources; no source-backed content update identified. No version increment; no findings added, modified, subtracted, or newly qualified. Named-victim search found no reliable public organization or company confirmed compromised by CVE-2026-41940, and associated-campaign/activity-cluster search found no new or changed source-backed cluster. Freshness labels applied to retained sources: none. PANDA index date updated to Updated Jul 14, 2026. No external email or notification was sent under the current automation no-email policy. |
| v1.11 | 15-Jul-2026 10:01 AM ET | AI Monitoring Agent checked public sources; no source-backed content update identified. No version increment; no findings added, modified, subtracted, or newly qualified. Named-victim search found no reliable public organization or company confirmed compromised by CVE-2026-41940, and associated-campaign/activity-cluster search found no new or changed source-backed cluster. Freshness labels applied to retained sources: none. PANDA index date updated to Updated Jul 15, 2026. No external email or notification was sent under the current automation no-email policy. |
| v1.11 | 16-Jul-2026 10:03 AM ET | AI Monitoring Agent checked public sources; no source-backed content update identified. No version increment; no findings added, modified, subtracted, or newly qualified. Named-victim search found no reliable public organization or company confirmed compromised by CVE-2026-41940, and associated-campaign/activity-cluster search found no new or changed source-backed cluster. Freshness labels applied to retained sources: none. PANDA index date updated to Updated Jul 16, 2026. No external email or notification was sent under the current automation no-email policy. |
| v1.12 | 17-Jul-2026 10:11 AM ET Newly retained | AI Monitoring Agent retained Bluehost's July 9 VPS/Dedicated customer guidance and May 6 compromise-check guide as Newly retained (>24h). Added named hosting-provider disclosure evidence and provider-scoped compromise-review categories to Executive Summary, AI Agent Delta Updates, Why It Matters, Action Rows, IOCs / Observables, Detection & Hunting, Insurance Policyholder Scoping Lens, Patch & Mitigation Guidance, Timeline, Real World Examples, Public Victim / Disclosure Matrix, Associated Campaigns / Activity Clusters, Source Deconfliction, Citations, and PANDA index timestamps. No Freshly reported (<24h) source, new named end-customer victim organization, new actor, new ransomware family, or new public PoC-driven exploitation cluster was identified. No external email or notification was sent under the current automation no-email policy. |
| v1.12 | 18-Jul-2026 10:02 AM ET | AI Monitoring Agent checked public sources; no source-backed content update identified. No version increment; no findings added, modified, subtracted, or newly qualified. Named-victim search found no reliable public organization or company confirmed compromised by CVE-2026-41940, and associated-campaign/activity-cluster search found no new or changed source-backed cluster. Freshness labels applied to retained sources: none. PANDA index date updated to Updated Jul 18, 2026. No external email or notification was sent under the current automation no-email policy. |
| v1.13 | 19-Jul-2026 10:04 AM ET Newly retained | AI Monitoring Agent retained InMotion Hosting's May 20 direct customer follow-up and BinaryLane's May 5 provider advisory as Newly retained (>24h). Added provider-response/customer-notice evidence for port-blocking windows, blocked patch exceptions, customer outreach, unmanaged-VPS responsibility, credential/log/account review, detection-script execution, provider remediation-pattern scoping, Public Victim / Disclosure Matrix provider rows, Associated Campaigns / Activity Clusters provider-remediation revision, Source Deconfliction, Citations, and PANDA index timestamps. No Freshly reported (<24h) source, new named end-customer victim organization, new actor, new ransomware family, intrusion set, botnet, exploit wave, or new public PoC-driven exploitation cluster was identified. No external email or notification was sent under the current automation no-email policy. |
| v1.14 | 20-Jul-2026 10:02 AM ET Newly retained | AI Monitoring Agent retained CrowdSec's May 4 telemetry/detection report, Beazley Security's May 2026 insurer-adjacent advisory, and KnownHost's April 28-30 provider response thread as Newly retained (>24h). Added bounded reconnaissance telemetry, CrowdSec detection/WAF virtual-patching control evidence, insurer exposure-management/MDR scoping, KnownHost provider port-blocking, patch-rollout, log-review, and access-attempt context, Public Victim / Disclosure Matrix provider caveats, Associated Campaigns / Activity Clusters reconnaissance and provider-remediation revisions, Source Deconfliction, Citations, and PANDA index timestamps. No Freshly reported (<24h) source, new named end-customer victim organization, new actor, new ransomware family, intrusion set, botnet, exploit wave, or new public PoC-driven exploitation cluster was identified. No external email or notification was sent under the current automation no-email policy. |
34-Citations
Baseline Retained Sources
| # | Source | Publisher | Published | Why Used |
|---|---|---|---|---|
| 1 | CVE-2026-41940 Detail | NVD / NIST | April 29, 2026; last modified June 17, 2026 26-Jun-2026 · Newly retained (>24h) | Official vulnerability record for description, CVSS severity, affected cPanel & WHM versions, reference set, and June 17 CISA SSVC / affected-record metadata. Freshness: Newly retained (>24h); retrieved June 26, 2026 at 10:02 AM ET. |
| 2 | Known Exploited Vulnerabilities Catalog: CVE-2026-41940 | CISA | April 30, 2026 28-Jun-2026 · Newly retained (>24h) | Authoritative KEV status, April 30 catalog addition, May 3 due date, and known ransomware-campaign-use flag. Freshness: Newly retained (>24h); retrieved June 28, 2026 at 10:02 AM ET. |
| 3 | Security: CVE-2026-41940 - cPanel & WHM / WP2 Security Update 04/28/2026 | cPanel Support | April 28, 2026; updated May 22, 2026 | Vendor advisory for affected versions, patched builds, required actions, mitigation options, and official detection script guidance. |
| 4 | CVE-2026-41940: Response, Actions and Next Steps | cPanel | May 10, 2026 | Vendor response timeline, root-cause framing in session management, CISA KEV confirmation, and response posture including more than 98% update adoption claim. |
| 5 | The Internet Is Falling Down, Falling Down, Falling Down | watchTowr Labs | April 29, 2026 | Practitioner root-cause analysis and public PoC for the CRLF/session-file authentication bypass chain. |
| 6 | CVE-2026-41940: cPanel & WHM Authentication Bypass | Rapid7 | April 29, 2026; updated May 5, 2026 | Technical overview, impact assessment, fixed-version summary, approximately 1.5 million exposed-instance context, and authenticated-check availability. |
| 7 | Critical cPanel flaw mass-exploited in Sorry ransomware attacks | BleepingComputer | May 2, 2026 | Security-media reporting that ties exploitation to Sorry ransomware, reports widespread exploitation, and cites Shadowserver 44,000-IP compromise telemetry. |
| 8 | Trending query: cPanel/WHM CVE-2026-41940 attacks ongoing | Shadowserver Foundation | April 30, 2026 | Telemetry signal reporting at least 44,000 likely compromised IPs observed scanning Shadowserver honeypots. |
| 9 | CVE-2026-41940 Explained: The cPanel & WHM Authentication Bypass That Hit 1.5M Servers | Picus Security | May 1, 2026 | Practitioner explainer on CRLF injection, session-writer behavior, CISA KEV status, exploitation timing, and session-directory triage. |
| 10 | Emerging Threat: CVE-2026-41940 cPanel & WHM Authentication Bypass via CRLF Injection | CyCognito | May 2026 | Attack-surface perspective on pre-authentication remote authentication bypass and exposure-management implications. |
| 11 | cPanel and WHM Authentication Bypass Vulnerability Exploited in the Wild | Qualys Threat Protection | April 30, 2026 | Practitioner corroboration that exploitation can allow control over host configuration, databases, and managed websites. |
| 12 | Critical cPanel CRLF injection vulnerability puts websites at risk | TechRadar | April 30, 2026 | Corroborating mainstream technology coverage used only for accessible stakeholder framing and patch urgency. |
| 13 | WebPros cPanel and WHM Authentication Bypass via Login Flow | VulnCheck | April 29, 2026 | CNA/advisory source for affected-version ranges, CVE assignment context, and severity metadata. |
| 14 | CVE-2026-41940 CVE Record | CVE.org | April 2026 | Official CVE-listing source for stable identifier and description cross-checking. |
| 15 | T1190 - Exploit Public-Facing Application | MITRE ATT&CK | Living framework | TTP mapping for remote exploitation of internet-facing cPanel/WHM services. |
| 16 | T1486 - Data Encrypted for Impact | MITRE ATT&CK | Living framework | TTP mapping for reported Sorry ransomware encryption impact after exploitation. |
Expansion Research / AI Monitor Delta Sources
| # | Source | Publisher | Published | Why Used |
|---|---|---|---|---|
| 17 | cPanel: Web Hosting Control Panel & Server Management Tools | cPanel | Living product page | Expansion context explaining cPanel as a hosting control panel for managing servers, websites, domains, files, databases, email, and hosted services at scale; used to clarify business impact and hosting-control-plane exposure. |
| 18 | How to Install WordPress with cPanel | cPanel Documentation | Living documentation | Expansion context showing cPanel's WordPress-management relationship through WP Toolkit; used to clarify that CVE-2026-41940 affects the hosting control panel, not WordPress core, themes, or plugins. |
| 19 | Critical cPanel and WHM bug exploited as a zero-day, PoC now available | BleepingComputer | April 30, 2026 | Expansion corroboration that cPanel, WHM, and WP Squared exploitation attempts were reported before public disclosure and that a public PoC became available after patches. |
| 20 | The cPanel Situation Is... | Censys ARC | May 1, 2026 26-Jun-2026 · Newly retained (>24h) | Retained for source-backed activity-cluster detail: Censys observed a May 1 malicious-host surge concentrated on cPanel/WHM, Mirai-pattern activity, and thousands of cPanel/WHM hosts exposing files renamed with the .sorry extension. Freshness: Newly retained (>24h); retrieved June 26, 2026 at 10:02 AM ET. |
| 21 | South-East Asian Military Entities Targeted via cPanel (CVE-2026-41940) | Ctrl-Alt-Intel | May 2, 2026; updated May 2, 2026 26-Jun-2026 · Newly retained (>24h) | Retained for named public targeting and activity-cluster mapping: an unknown actor reportedly used public CVE-2026-41940 PoC tooling against South-East Asian government/military entities and MSP/hosting-provider targets, with no firm attribution. Freshness: Newly retained (>24h); retrieved June 26, 2026 at 10:02 AM ET. |
| 22 | Threat Actor Mr_Rot13 Actively Exploits CVE-2026-41940 for Backdoor Deployment | QiAnXin XLab | May 11, 2026 27-Jun-2026 · Newly retained (>24h) | Retained for source-backed activity-cluster and hunting guidance: XLab attributed one exploitation stream to Mr_Rot13 and described post-exploitation backdoor, webshell, SSH-key, credential-theft, and Filemanager remote-control activity tied to CVE-2026-41940. Freshness: Newly retained (>24h); retrieved June 27, 2026 at 10:02 AM ET. |
| 23 | WAF Release - 2026-04-30 - Emergency | Cloudflare | April 30, 2026 28-Jun-2026 · Newly retained (>24h) | Retained for compensating-control guidance: Cloudflare introduced a managed WAF rule to block cPanel & WHM authentication-bypass traffic related to CVE-2026-41940 while still recommending official vendor patches. Freshness: Newly retained (>24h); retrieved June 28, 2026 at 10:02 AM ET. |
| 24 | Compromised Website Report | Shadowserver Foundation | Last updated June 18, 2026; cPanel tags first added May 4 / May 13, 2026 28-Jun-2026 · Newly retained (>24h) | Retained for reporting and activity-tag guidance: Shadowserver describes cPanel/Roundcube instances attempting honeypot exploitation or seen in darknets as likely CVE-2026-41940-related compromise, with sorry-ransomware, whmstealer, and mr-rot13 tags. Freshness: Newly retained (>24h); retrieved June 28, 2026 at 10:02 AM ET. |
| 25 | Critical Authentication Vulnerability on cPanel/WHM | Liquid Web | Incident updates April 28-May 18, 2026 01-Jul-2026 · Newly retained (>24h) | Retained for hosting-provider customer-notice and remediation evidence: Liquid Web described CVE-2026-41940 patching, support-volume impact, remaining remediation, and restoring servers where compromise was evident. Freshness: Newly retained (>24h); retrieved July 1, 2026 at 10:02 AM ET. |
| 26 | InMotion Hosting Keeps Customer Sites Online Through Industry-Wide cPanel Security Response | InMotion Hosting | May 26, 2026 01-Jul-2026 · Newly retained (>24h) | Retained for hosting-provider advisory-pattern evidence: InMotion reported network-edge blocking, fleet patching, 99% of potentially affected customers protected without service disruption, and direct remediation for a small subset of customer environments. Freshness: Newly retained (>24h); retrieved July 1, 2026 at 10:02 AM ET. |
| 27 | Sorry ransomware exploits cPanel authentication bypass | ThreatLocker | May 15, 2026 03-Jul-2026 · Newly retained (>24h) | Retained for source-backed Sorry ransomware activity-cluster and hunting detail: ThreatLocker analyzed Linux encryptor behavior, host-level markers, service/process disruption, SSH propagation attempts, and recovery implications after CVE-2026-41940 compromise. Freshness: Newly retained (>24h); retrieved July 3, 2026 at 10:03 AM ET. |
| 28 | Searching for bulletproof detections in cPanel Land | Unfold Security Research Lab | May 6, 2026 08-Jul-2026 · Newly retained (>24h) | Retained for source-backed detection guidance: Unfold describes behavior-based cPanel session/access-log hunting focused on exploit mechanics instead of brittle PoC strings. Freshness: Newly retained (>24h); retrieved July 8, 2026 at 10:03 AM ET. |
| 29 | More CVEs, Same Playbook: 2026 Vulnerability Exploitation in the Wild | Proofpoint | May 27, 2026 13-Jul-2026 · Newly retained (>24h) | Retained for source-backed activity-cluster refinement: Proofpoint observed CVE-2026-41940 in network telemetry, framed the cPanel exploitation pattern as multi-actor mass exploitation, and tied some compromised-website web-inject chains to threat actors such as TA569/SocGholish. Freshness: Newly retained (>24h); retrieved July 13, 2026 at 10:03 AM ET. |
| 30 | cPanel Vulnerability for VPS & Dedicated Customers | Bluehost | Updated July 9, 2026 17-Jul-2026 · Newly retained (>24h) | Retained for named hosting-provider customer guidance: Bluehost described active exploitation, temporary port restrictions for affected VPS/Dedicated cPanel servers, CentOS 6 migration pressure, backup and log-review advice, and customer-facing outage/data-impact language. Freshness: Newly retained (>24h); retrieved July 17, 2026 at 10:11 AM ET. |
| 31 | Bluehost: CVE-2026-41940: Compromise Check Guide | Bluehost | Updated May 6, 2026 17-Jul-2026 · Newly retained (>24h) | Retained for provider-scoped compromise-review guidance: Bluehost lists checks for patched version validation, Sorry ransomware markers, suspicious process and shell-startup evidence, root SSH-key changes, cPanel template tampering, shell history review, evidence preservation, credential rotation, and hosted-account review. Freshness: Newly retained (>24h); retrieved July 17, 2026 at 10:11 AM ET; raw command bodies and hashes are not republished in this brief. |
| 32 | CVE-2026-41940: Full Technical Details and InMotion's Response | InMotion Hosting | Updated May 20, 2026 19-Jul-2026 · Newly retained (>24h) | Retained for direct hosting-provider customer-notice detail: InMotion described fleet port blocking, patching, blocked exceptions for systems that could not receive updates, customer outreach, credential/log/account review, and detection-script use. Freshness: Newly retained (>24h); retrieved July 19, 2026 at 10:04 AM ET; exploit-chain specifics and raw commands are not republished in this brief. |
| 33 | Critical cPanel/WHM/WP2 Vulnerability - CVE-2026-41940 (Authentication Bypass) | BinaryLane | Last updated May 5, 2026 19-Jul-2026 · Newly retained (>24h) | Retained for provider advisory-pattern detail: BinaryLane described CVE-2026-41940 active exploitation against cPanel servers on its network, provider-side mitigation/notification, and unmanaged-VPS patch-validation responsibilities. Freshness: Newly retained (>24h); retrieved July 19, 2026 at 10:04 AM ET. |
| 34 | CVE-2026-41940: cPanel & WHM Authentication Bypass Puts Millions of Servers at Risk | CrowdSec | May 4, 2026 20-Jul-2026 · Newly retained (>24h) | Retained for telemetry and detection-control detail: CrowdSec reported first observed CVE-2026-41940 activity on April 27, 282 distinct IPs tied to the issue through May 4, a significant reconnaissance campaign, dedicated detection coverage, and WAF virtual patching guidance. Freshness: Newly retained (>24h); retrieved July 20, 2026 at 10:02 AM ET. |
| 35 | Critical Vulnerability in cPanel and WHM Under Active Exploitation (CVE-2026-41940) | Beazley Security | May 2026 20-Jul-2026 · Newly retained (>24h) | Retained for insurer-adjacent scoping: Beazley Security described hosting-provider port blocking, review of internet-exposed self-hosted cPanel, vendor detection-script use, Exposure Management perimeter identification, and MDR threat hunts. Freshness: Newly retained (>24h); retrieved July 20, 2026 at 10:02 AM ET; raw exploit examples are not republished in this brief. |
| 36 | cPanel Zero Day Exploit - Network wide protections in place for cPanel and WHM logins/ports | KnownHost | April 28-30, 2026 20-Jul-2026 · Newly retained (>24h) | Retained for direct hosting-provider response and bounded telemetry: KnownHost described network-level blocking of cPanel, WHM, Webmail, and WebDisk ports, managed-customer patch rollout, access restoration after patching, review of server logs, and a small number of access-attempt findings without active-compromise signs in reviewed cases. Freshness: Newly retained (>24h); retrieved July 20, 2026 at 10:02 AM ET; raw sample log lines are not republished in this brief. |
