DMZ//THREAT INTEL
FEED ACTIVELAST SYNC: 06:03:37ZSOURCES: 14CRITICAL: 15
⚠ ACTIVE ALERTS
SYLVANITE CRITICAL — SYLVANITE is a newly named Dragos-tracked threat group identified as a dedicated… /// @MsftSecIntel CRITICAL — We are tracking TeamPCP (UNC6780) activity following the GitHub internal repository… /// @GossiTheDog CRITICAL — The GitHub / TeamPCP breach is now being monetized on BreachForums. Listing is up — $95k… /// @struppigel CRITICAL — SUPPLY CHAIN ALERT: Laravel-Lang PHP packages backdoored May 22-23 via hijacked GitHub… /// @MalwareHunterTeam CRITICAL — Seeing fresh DebugElevator stealer log batches already appearing for sale on Exploit.in —…
15Critical Threats
8Active CVEs
0IOCs Tracked
0New Advisories
TLP:WHITEVULNERABILITY BRIEF // CVE-2026-41940PUBLISHED: 2026-04-28
CRITICALCVE-2026-41940★ CISA KEV LISTED

cPanel & WHM Pre-Auth CRLF Injection Authentication Bypass (Zero-Day, Ransomware)

VENDOR: WebPros//PRODUCT: cPanel & WHM / WP2 (WordPress Squared)
9.8
CRITICAL
CVSS 3.1
PATCH STATUS
PATCH AVAILABLE
EXPLOIT STATUS
PUBLIC EXPLOIT

A CRLF injection vulnerability in the Basic Auth login flow of cPanel & WHM allows an unauthenticated remote attacker to manipulate the session file and inject arbitrary session properties (e.g., user=root), bypassing authentication entirely and gaining full WHM root access without any credentials. The flaw was exploited as a true zero-day for approximately 64 days before patching, with active exploitation observed as early as February 23, 2026. Mass exploitation by multiple threat clusters followed a public PoC by watchTowr Labs published April 29; at least 44,000 IPs were compromised with the 'Sorry' ransomware (.sorry extension) and Mirai botnet variants deployed. A state-linked actor also targeted Southeast Asian government and military networks. CISA added to KEV May 1, 2026.

Attack Vector
NETWORK
Attack Complexity
LOW
Privs Required
NONE
User Interaction
NONE
Scope / Impact
UNCHANGED
C:H · I:H · A:H
AFFECTED VERSIONSAll supported cPanel & WHM versions after 11.40 and WP2; patched in version 136.1.7+
  • cPanel Advisory: https://support.cpanel.net/hc/en-us/articles/40073787579671-cPanel-WHM-Security-Update-04-28-2026
  • watchTowr Labs PoC: https://blog.watchtowr.com/cve-2026-41940-cpanel-whm-auth-bypass/
  • CISA KEV: https://www.cisa.gov/known-exploited-vulnerabilities-catalog
  • The Hacker News: https://thehackernews.com/2026/05/critical-cpanel-vulnerability.html
  • Malwarebytes: https://www.malwarebytes.com/blog/news/2026/05/actively-exploited-cpanel-bug-exposes-millions-of-websites-to-takeover
SHARE BRIEF:✕ Post on Xin Share on LinkedIn