Attackers are exploiting CVE-2026-41940, a CVSS 9.8 unauthenticated authentication bypass in cPanel & WHM that can grant root-equivalent administrative access. WatchTowr Labs attributed the flaw to CRLF injection into pre-authentication session files handled by the cpsrvd daemon, enabling attackers to forge privileged session properties. Exploitation combines malformed session cookies with a cache-bypassing request that makes attacker-controlled authentication fields effective. cPanel released emergency security updates on April 28, 2026, and CISA added the vulnerability to its Known Exploited Vulnerabilities catalog on April 30; KnownHost reported exploitation dating back to late February.
Defused recorded 340 attacks across eight request variants in 48 hours against its honeypots, with follow-on reconnaissance, remote command execution checks, SSH key persistence, and attempted root password changes. CrowdSec observed 282 associated IP addresses from April 27 through May 4, but cautioned that its telemetry could not confidently establish the exploitation phase. Organizations should urgently apply the security updates, restrict internet access to management interfaces, and assess exposed servers for compromise. Patching alone does not remove unauthorized SSH keys or reverse malicious account changes, so defenders should review administrative activity and persistence before considering affected systems remediated.

See which actors are running it and whether you're in range.
13 events from the most recent confirmed update back to the earliest known activity.
At 19:48 UTC, source IP 176.65.132.199 issued four version and application-list requests across two forged session identifiers within one second. Defused observed no subsequent account listing or modification from this operator.
Source IP 103.98.152.18 generated 17 requests from May 1 at 14:46 UTC through May 2 at 05:34 UTC. The operator repeatedly validated sessions, requested account listings, and submitted a json-api/system request with command=id to check remote command execution.
Between 06:17 and 06:58 UTC, source IP 80.87.206.131 issued seven requests using root Basic Auth credentials, including account listing and an attempt to authorize an attacker-controlled SSH public key. Such authorization could preserve access independently of the cPanel vulnerability.
At 19:44 UTC, source IP 176.65.148.253 sent a forged-session request to the json-api/passwd endpoint attempting to change the root password. The observation establishes an account-takeover attempt, not a confirmed successful password change.
CrowdSec identified a significant reconnaissance campaign aimed at inventorying potential targets. Its telemetry did not establish whether the activity represented broad exploitation or selective targeting.
CrowdSec released a dedicated detection rule for activity associated with CVE-2026-41940.
CISA added the cPanel authentication bypass to its Known Exploited Vulnerabilities catalog, recognizing its exploitation in the wild.
CrowdSec published a WAF virtual patching rule for CVE-2026-41940 to provide interim protection for exposed systems.
CVE-2026-41940 was published, and technical writeups and public proof-of-concept exploits appeared. The disclosed technique uses malformed session cookies and CRLF injection to forge privileged authentication properties in cpsrvd session files.
cPanel released updates addressing CVE-2026-41940, a critical pre-authentication bypass capable of granting root-equivalent WHM access. Fixed builds included 11.136.0.5 and updates for other release branches.
CrowdSec first detected associated activity on April 27. Its monitoring identified 282 distinct IP addresses between April 27 and May 4, but could not confidently distinguish broad opportunistic exploitation from selective targeting.
KnownHost reported in-the-wild exploitation of CVE-2026-41940 dating back to late February 2026, indicating that attackers used the vulnerability as a zero-day.
Defused recorded 340 attacks during a 48-hour observation window and identified four operators reaching the privileged-request stage. Observed behaviors included reconnaissance, command-execution checks, attempted SSH persistence, and attempted root account takeover.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
3 references tracked. Mallory keeps watching after this page renders.
crowdsec.net
Open sourcedefusedcyber.com
Open sourcehostmycode.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.