www.securityweek.com 5/4/2026, 8:51:42 AM · via preferred

Attackers hit over 40k cPanel servers via CVE-2026-41940 flaw

Attackers hit over 40k cPanel servers via CVE-2026-41940 flaw

DomainTools Investigations | Cybersecurity Reading List - Week of 2026-05-04

The Cybersecurity Reading List for the week of 2026-05-04 highlights a mix of official reports, agency guidance and research reflecting a broad threat landscape. Notable items include FBI/IC3 reporting a surge in cyber-enabled strategic cargo theft, and UK NCSC sharing fresh advice for defending against China-linked covert networks as PRC activity evolves.…

First seen 2026-04-29T22:19:56.188Z · Last seen 2026-05-07T23:32:47.959Z

CyberSIXT Evidence Panel
Primary Source x.com
CISA KEV Listed in KEV
Patch Patch Available

OVER 40,000 servers have likely been compromised as attackers intensified exploitation of a recently patched cPanel zero-day, CVE-2026-41940. According to The Shadowserver Foundation, threat actors are exploiting this critical authentication-bypass vulnerability in cPanel & WHM, disclosed on 28 April, to gain unauthenticated administrative access.

The issue can be exploited via special characters in authorization headers to write parameters to a session file and then trigger a reload to authenticate with injected credentials. CVE-2026-41940 was likely exploited as a zero-day since late February, with activity spiking after the public disclosure and after WatchTowr published technical details.

Last week Rapid7 warned that roughly 1.5 million cPanel instances were accessible from the internet, and as of 3 May, tens of thousands of potentially compromised systems were being observed by Shadowserver. Most affected systems are in the US, with France and the Netherlands in the top three, and cPanel urges updating to patch releases across affected versions. The US agency context includes CISA adding CVE-2026-41940 to its KEV catalog, urging agencies to patch promptly.

View Primary Source Via www.securityweek.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline