Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
CVE-2023-XXXXX: Critical Windows Defender DoS Vulnerability Patched
September 21, 2026
Critical cPanel Vulnerability CVE-2026-41940 Exploited to Deploy Mirai Malware
September 21, 2026
Blockchain-based Malware Steals Bank Logins and 2FA Codes
September 21, 2026
Home/Threats/Critical cPanel Vulnerability CVE-2026-41940 Exploited to Deploy Mirai Malware
Threats

Critical cPanel Vulnerability CVE-2026-41940 Exploited to Deploy Mirai Malware

Key Takeaways A critical authentication bypass vulnerability, CVE-2026-41940, in cPanel and WHM is being actively exploited. Attackers are leveraging this flaw to deploy Mirai malware on compromised...

Emy Elsamnoudy
Emy Elsamnoudy
September 21, 2026 4 Min Read
3 0

Key Takeaways

  • A critical authentication bypass vulnerability, CVE-2026-41940, in cPanel and WHM is being actively exploited.
  • Attackers are leveraging this flaw to deploy Mirai malware on compromised hosting servers.
  • This activity has led to a significant increase in suspicious Telnet traffic, broadening the Mirai botnet’s reach beyond typical IoT devices to include web infrastructure.
  • The vulnerability allows unauthenticated attackers to gain administrative access, enabling arbitrary file modification, configuration changes, and further attacks.
  • Immediate patching and robust security practices are essential for all organizations utilizing cPanel/WHM.

Cybersecurity researchers have identified active exploitation of a severe vulnerability in cPanel and WHM, designated CVE-2026-41940. This critical flaw allows unauthorized individuals to bypass authentication and gain administrative control over affected systems. Threat actors are capitalizing on this weakness to install Mirai malware, traditionally associated with IoT devices, onto compromised web hosting servers. This shift marks a concerning expansion of the Mirai botnet’s operational scope.

Table Of Content

  • Key Takeaways
  • Hackers Exploit cPanel CVE-2026-41940 Authentication Bypass
  • Worldwide Signals and Defensive Steps
  • What You Should Do

The exploitation has resulted in a notable surge in Telnet traffic directed at TCP port 23, highlighting a broader challenge in internet security. The targeting of conventional hosting infrastructure with Mirai malware represents a significant concern for organizations that might not typically consider their servers vulnerable to such botnet operations. The ability for an unauthenticated attacker to achieve administrative access means they can manipulate system settings, introduce malicious files, and launch attacks against other systems connected to the compromised server.

Hackers Exploit cPanel CVE-2026-41940 Authentication Bypass

CVE-2026-41940 is an authentication bypass vulnerability of critical severity impacting cPanel and WHM installations. This flaw grants an attacker full administrative privileges without requiring valid login credentials, paving the way for complete system compromise. Reports indicate that this weakness was exploited as a zero-day, meaning attackers were leveraging it before vendors could release and users could apply corrective patches.

Upon gaining unauthorized access, adversaries can transform a standard web-hosting server into a strategic operational base. This allows them to do more than just exfiltrate data; they can deploy Mirai-derived code to scan for additional vulnerable services, propagate infections to other targets, or direct distributed denial-of-service (DDoS) attacks. This capability significantly amplifies the potential impact of a single compromised control panel, particularly for hosting providers managing numerous websites.

Example of an interface that appears to be running cPanel (Source – JPCert)
Example of an interface that appears to be running cPanel (Source – JPCert)

The observed malicious traffic predominantly targeted port 23, a port historically used by Telnet. Telnet is an outdated remote-access protocol that is inherently insecure and should not be exposed to the public internet. Mirai malware variants are notorious for exploiting weak credentials and accessible remote services to rapidly expand their botnets. The persistent evolution of the Mirai threat underscores the continuous efforts by attackers to quickly conscript new systems into their networks.

While direct evidence linking every Mirai infection to CVE-2026-41940 remains under investigation, the timing and nature of the observed activity strongly suggest a connection. JPCERT/CC said in a report that their monitoring alone cannot definitively prove the infection vector, but other reports indicate a probable link between the exploitation and Mirai or its variants. Furthermore, the authentication bypass vulnerability has been linked to other forms of malicious activity beyond Mirai, demonstrating its versatility for various types of abuse.

Worldwide Signals and Defensive Steps

The United States accounted for the largest portion of the observed source traffic, with significant increases also noted in Germany, France, and Canada around May 1st. These widespread regional patterns indicate that the infections are distributed broadly across the internet, rather than being confined to a specific country, provider, or server cluster. Japan also experienced a similar trend, with Mirai-like traffic originating from Japanese IP addresses and targeting port 23 escalating to approximately 15 times its previous level. At its peak, a substantial volume of these packets originated from addresses assigned to various hosting providers. This extensive server takeover campaign provides crucial insights into the risks posed by unpatched cPanel and WHM installations.

What You Should Do

  • Apply Vendor Patches Immediately: Ensure all cPanel and WHM servers are updated with the latest security patches to address CVE-2026-41940. Verify that no outdated or unpatched instances remain accessible.
  • Restrict Remote Administration: Limit remote administrative access to cPanel/WHM interfaces only to trusted IP addresses or networks. Implement VPNs for remote access where direct exposure is unavoidable.
  • Disable Telnet: Deactivate Telnet on all servers if it is not absolutely essential for operations. Replace it with secure alternatives like SSH.
  • Strengthen Credentials: Enforce strong, unique passwords for all administrative accounts and system users. Implement multi-factor authentication (MFA) wherever possible.
  • Monitor for Anomalies: Regularly review cPanel and system logs for any unexpected administrative sessions, newly created accounts, unauthorized configuration changes, or suspicious file modifications.
  • Inspect Network Traffic: Monitor outbound network connections and active processes for any unusual activity, particularly traffic related to Mirai command-and-control servers or unexpected Telnet connections.
  • Regular Security Audits: Conduct frequent security audits of your hosting infrastructure to identify and remediate vulnerabilities proactively. Treat hosting control panels as high-value assets requiring stringent security measures.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

BreachCVEExploitHackerMalwarePatchSecurityThreatVulnerabilityzero-day

Share Article

Emy Elsamnoudy

Emy Elsamnoudy

Emy is a cybersecurity analyst and reporter specializing in threat hunting, defense strategies, and industry trends. With expertise in proactive security measures, Emily covers the tools and techniques organizations use to detect and prevent cyber attacks. She is a regular speaker at security conferences and has contributed to industry reports on threat intelligence and security operations. Emily's reporting focuses on helping organizations improve their security posture through practical, actionable insights.

Previous Post

Blockchain-based Malware Steals Bank Logins and 2FA Codes

Next Post

CVE-2023-XXXXX: Critical Windows Defender DoS Vulnerability Patched

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Top 10 Identity Governance & Administration (IGA) Tools for 2026
September 21, 2026
Top 10 Best Single Sign-On (SSO) Solutions in 2024
September 21, 2026
Best Multi-Factor Authentication (MFA) Solutions for 2026
September 21, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us