Critical cPanel Vulnerability CVE-2026-41940 Exploited to Deploy Mirai Malware
Key Takeaways A critical authentication bypass vulnerability, CVE-2026-41940, in cPanel and WHM is being actively exploited. Attackers are leveraging this flaw to deploy Mirai malware on compromised...
Key Takeaways
- A critical authentication bypass vulnerability, CVE-2026-41940, in cPanel and WHM is being actively exploited.
- Attackers are leveraging this flaw to deploy Mirai malware on compromised hosting servers.
- This activity has led to a significant increase in suspicious Telnet traffic, broadening the Mirai botnet’s reach beyond typical IoT devices to include web infrastructure.
- The vulnerability allows unauthenticated attackers to gain administrative access, enabling arbitrary file modification, configuration changes, and further attacks.
- Immediate patching and robust security practices are essential for all organizations utilizing cPanel/WHM.
Cybersecurity researchers have identified active exploitation of a severe vulnerability in cPanel and WHM, designated CVE-2026-41940. This critical flaw allows unauthorized individuals to bypass authentication and gain administrative control over affected systems. Threat actors are capitalizing on this weakness to install Mirai malware, traditionally associated with IoT devices, onto compromised web hosting servers. This shift marks a concerning expansion of the Mirai botnet’s operational scope.
Table Of Content
The exploitation has resulted in a notable surge in Telnet traffic directed at TCP port 23, highlighting a broader challenge in internet security. The targeting of conventional hosting infrastructure with Mirai malware represents a significant concern for organizations that might not typically consider their servers vulnerable to such botnet operations. The ability for an unauthenticated attacker to achieve administrative access means they can manipulate system settings, introduce malicious files, and launch attacks against other systems connected to the compromised server.
Hackers Exploit cPanel CVE-2026-41940 Authentication Bypass
CVE-2026-41940 is an authentication bypass vulnerability of critical severity impacting cPanel and WHM installations. This flaw grants an attacker full administrative privileges without requiring valid login credentials, paving the way for complete system compromise. Reports indicate that this weakness was exploited as a zero-day, meaning attackers were leveraging it before vendors could release and users could apply corrective patches.
Upon gaining unauthorized access, adversaries can transform a standard web-hosting server into a strategic operational base. This allows them to do more than just exfiltrate data; they can deploy Mirai-derived code to scan for additional vulnerable services, propagate infections to other targets, or direct distributed denial-of-service (DDoS) attacks. This capability significantly amplifies the potential impact of a single compromised control panel, particularly for hosting providers managing numerous websites.
.webp)
The observed malicious traffic predominantly targeted port 23, a port historically used by Telnet. Telnet is an outdated remote-access protocol that is inherently insecure and should not be exposed to the public internet. Mirai malware variants are notorious for exploiting weak credentials and accessible remote services to rapidly expand their botnets. The persistent evolution of the Mirai threat underscores the continuous efforts by attackers to quickly conscript new systems into their networks.
While direct evidence linking every Mirai infection to CVE-2026-41940 remains under investigation, the timing and nature of the observed activity strongly suggest a connection. JPCERT/CC said in a report that their monitoring alone cannot definitively prove the infection vector, but other reports indicate a probable link between the exploitation and Mirai or its variants. Furthermore, the authentication bypass vulnerability has been linked to other forms of malicious activity beyond Mirai, demonstrating its versatility for various types of abuse.
Worldwide Signals and Defensive Steps
The United States accounted for the largest portion of the observed source traffic, with significant increases also noted in Germany, France, and Canada around May 1st. These widespread regional patterns indicate that the infections are distributed broadly across the internet, rather than being confined to a specific country, provider, or server cluster. Japan also experienced a similar trend, with Mirai-like traffic originating from Japanese IP addresses and targeting port 23 escalating to approximately 15 times its previous level. At its peak, a substantial volume of these packets originated from addresses assigned to various hosting providers. This extensive server takeover campaign provides crucial insights into the risks posed by unpatched cPanel and WHM installations.
What You Should Do
- Apply Vendor Patches Immediately: Ensure all cPanel and WHM servers are updated with the latest security patches to address CVE-2026-41940. Verify that no outdated or unpatched instances remain accessible.
- Restrict Remote Administration: Limit remote administrative access to cPanel/WHM interfaces only to trusted IP addresses or networks. Implement VPNs for remote access where direct exposure is unavoidable.
- Disable Telnet: Deactivate Telnet on all servers if it is not absolutely essential for operations. Replace it with secure alternatives like SSH.
- Strengthen Credentials: Enforce strong, unique passwords for all administrative accounts and system users. Implement multi-factor authentication (MFA) wherever possible.
- Monitor for Anomalies: Regularly review cPanel and system logs for any unexpected administrative sessions, newly created accounts, unauthorized configuration changes, or suspicious file modifications.
- Inspect Network Traffic: Monitor outbound network connections and active processes for any unusual activity, particularly traffic related to Mirai command-and-control servers or unexpected Telnet connections.
- Regular Security Audits: Conduct frequent security audits of your hosting infrastructure to identify and remediate vulnerabilities proactively. Treat hosting control panels as high-value assets requiring stringent security measures.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.