ctipilot.chSwitzerland · Europe · Public sector

cPanel/WHM authentication bypass — mass exploitation ongoing (KEV deadline 2026-05-21)

cve · CVE-2026-41940

Story timeline

  1. 2026-05-06CTI Daily Brief — 2026-05-06
    active_vulnsFirst coverage. CRLF injection auth bypass in cPanel/WHM; exploited since ~2026-02-23 (two months before patch); ~44,000 hosts likely compromised; Sorry ransomware and AdaptixC2 campaigns; CISA KEV 2026-04-30.