HoneyLabs reported that analysis of more than 30 million honeypot records uncovered likely pre-disclosure probing against multiple vulnerabilities, led by a case involving CVE-2026-41940 in cPanel/WHM. Researchers said the strongest signal came from IP 85.122.114.177, which began requesting the exact WHM login path /login/?login_only=1 on port 2087 on 11 April 2026, roughly 17 to 18 days before cPanel publicly disclosed the authentication bypass flaw on 28 April. The activity suggested the actor had identified and tested the exploit path before vendor publication and before public exploit tooling was available.
To reduce false positives, the researchers applied four validation checks across 1,697 tracked CVE signatures and narrowed the findings to three actors that likely probed exploit paths ahead of disclosure. The additional cases were tied to CVE-2026-33626 in LMDeploy and CVE-2026-8181 in the Burst Statistics WordPress plugin, although the LMDeploy observation was described as less specific because it targeted a default OpenAI-compatible API endpoint. The research mapped the behavior to MITRE ATT&CK T1595.002 and T1190, reinforcing concerns that some attackers can discover and validate vulnerable paths weeks before public advisories appear.

TTPs, infrastructure, and targeting history in one profile.
4 events from the most recent confirmed update back to the earliest known activity.
HoneyLabs published research describing a methodology for detecting pre-disclosure vulnerability probing by analyzing more than 30 million honeypot records. The study said four validation checks reduced 1,697 tracked CVE signatures to three actors likely probing exploit paths before public disclosure.
CERT.hr warned that public proof-of-concept code for CVE-2026-41940 was available and that active exploitation attempts had been observed. The advisory also urged administrators to upgrade to patched cPanel versions, restrict access to ports 2083 and 2087, and review login logs for suspicious sessions.
cPanel publicly disclosed the authentication bypass vulnerability CVE-2026-41940. The prior honeypot observation was measured against this disclosure date to show the probing occurred well before public awareness.
HoneyLabs observed IP address 85.122.114.177 probing the exact WHM login path /login/?login_only=1 on port 2087, behavior later tied to CVE-2026-41940. The probing began 17 to 18 days before the vendor's public disclosure, suggesting pre-disclosure reconnaissance of the exploit path.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
4 references tracked. Mallory keeps watching after this page renders.
reddit.com
Open sourcecyberveille.ch
Open sourcehoneylabs.net
Open sourcecert.hr
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.