Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Critical cPanel Vulnerability Exploited by Hackers

Critical cPanel Vulnerability Exploited by Hackers

Posted on May 12, 2026 By CWS

A significant security flaw identified as CVE-2026-41940 is currently being exploited in cPanel and WHM servers globally, posing a severe threat to cybersecurity. This vulnerability, with a critical severity score of 9.8, enables cybercriminals to gain effortless access to systems without requiring traditional credentials.

Exploitation and Impact

Unauthenticated attackers are leveraging this vulnerability to compromise security and gain administrative control. This exploit has paved the way for various malicious activities such as ransomware deployment, cryptomining, and establishing persistent backdoors in Linux servers. Since its public disclosure in April 2026, there has been a significant increase in automated attacks targeting this flaw.

DailyDarkWeb reports indicate that over 2,000 unique IP addresses globally, predominantly from the US, Germany, Brazil, and the Netherlands, are actively exploiting this vulnerability. Security experts from Ctrl-Alt-Intel have revealed instances where hackers have breached Southeast Asian governmental networks, extracting over 4.37 GB of sensitive data.

The Role of Mr_Rot13

An advanced hacking group, referred to as Mr_Rot13 by XLab, has been linked to this sophisticated campaign. Known for deploying undetectable PHP backdoors, this group uses the Rot13 algorithm to obfuscate their command-and-control mechanisms in JavaScript payloads. Mr_Rot13’s operations are highly organized, with a history of adapting quickly to security challenges by updating their malware and communication methods.

The attack methodology involves exploiting the CVE-2026-41940 vulnerability to bypass authentication, granting attackers instant administrative privileges. A Go-based injector tool, named ‘Payload,’ is used to modify server credentials and secure backdoor access.

Technical Details and Defense

Once access is gained, the attackers alter the server root password and introduce malicious SSH public keys. A PHP webshell, dubbed ‘Cpanel-Python,’ is deployed, injecting malicious scripts into login pages to capture sensitive data. This data is then sent to a remote command-and-control server.

The attackers further employ ‘Filemanager,’ a versatile remote control Trojan compatible with multiple operating systems, to manage and execute commands on compromised servers. Stolen configuration files and database credentials are exfiltrated through secure channels to the group’s web domains and a Telegram bot.

Indicators of compromise include specific domains and MD5 hashes associated with the malicious activities. It’s crucial for organizations to monitor and mitigate these threats using controlled intelligence platforms.

The exploitation of CVE-2026-41940 underscores the importance of robust cybersecurity measures. Organizations must remain vigilant, apply timely patches, and utilize comprehensive threat detection systems to safeguard their infrastructure against such vulnerabilities.

Cyber Security News Tags:authentication bypass, Backdoors, cPanel, Cryptominers, CVE-2026-41940, Cybersecurity, Hackers, Mr_Rot13, Ransomware, Vulnerability

Post navigation

Previous Post: TanStack npm Packages Compromised in Major Attack
Next Post: iOS 26.5 Launches Default E2E Encrypted RCS Messaging

Related Posts

Longwatch RCE Vulnerability Let Attackers Execute Remote Code With Elevated Privileges Longwatch RCE Vulnerability Let Attackers Execute Remote Code With Elevated Privileges Cyber Security News
EU Pushes Google to Share Anonymized User Data EU Pushes Google to Share Anonymized User Data Cyber Security News
New Wave of Crypto-Hijacking Infects 3,500+ Websites New Wave of Crypto-Hijacking Infects 3,500+ Websites Cyber Security News
New tool to Remove Copilot, Recall and Other AI tools From Windows 11 New tool to Remove Copilot, Recall and Other AI tools From Windows 11 Cyber Security News
GitLab Halts Researcher After GitHub Suspension GitLab Halts Researcher After GitHub Suspension Cyber Security News
New PoC Exploit for Old PostgreSQL Vulnerability New PoC Exploit for Old PostgreSQL Vulnerability Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Amazon Q Extension Flaw Risks Developer Cloud Credentials
  • CISA Identifies Critical RCE Vulnerability in PTC Software
  • GIFTEDCROOK Malware Exploits WinRAR to Steal Data
  • AI and Cybersecurity Updates: Major Breaches and Layoffs
  • Amazon Q Developer Flaw Exposes Cloud Credentials

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Amazon Q Extension Flaw Risks Developer Cloud Credentials
  • CISA Identifies Critical RCE Vulnerability in PTC Software
  • GIFTEDCROOK Malware Exploits WinRAR to Steal Data
  • AI and Cybersecurity Updates: Major Breaches and Layoffs
  • Amazon Q Developer Flaw Exposes Cloud Credentials

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark