cPanel CVE-2026-41940: Active Exploitation of WordPress Backdoor

Date:

Cybersecurity Alert: Major Malware Attack Targets cPanel Users

On May 11, 2026, security researchers reported a significant malware attack linked to a threat actor known as Mr_Rot13. This attack exploits a critical vulnerability in cPanel, identified as CVE-2026-41940, which allows unauthorized access to control panels.

The breach has affected numerous web hosting environments globally, with over 2,000 IP addresses involved in the attacks. Victims are at risk of ransomware, cryptocurrency mining, and data theft as the malware installs a backdoor named “Filemanager” to maintain persistent access.

To protect against this threat, users are urged to update their cPanel software immediately, utilize strong passwords, and monitor their systems for unusual activity.

Given the scale and sophistication of the attack, the risk level is assessed as High. Cybersecurity vigilance is essential to safeguard sensitive information and prevent potential exploitation.

Source: View Original Report

Share post:

spot_imgspot_img

Popular

More like this
Related

Critical PHP Object Injection Vulnerability Found in GiveWP Plugin

A recently discovered vulnerability in the GiveWP plugin poses...

AI Advances Strengthen Cybersecurity: Wordfence Unveils Critical Vulnerability Discovery

Wordfence has revealed significant advancements in its incorporation of...

Critical Unauthenticated Account Takeover Vulnerability Found in TranslatePress Plugin

On August 11, 2026, a significant security vulnerability was...

Hackers Target WordPress Sites in miniOrange Authentication Bypass Attacks

In recent weeks, hackers have escalated their attacks on...