Critical
KEV + Ransomware
CVE-2026-41940
Exploitation of cPanel and WHM CVE-2026-41940 in Mirai Botnet Campaign
Vendor / product: cPanel and WHM
Event date: 2026-02-23
Public PoC: Yes
First tracked by RiskWire: 2026-09-04
CISA KEV catalog
Added to KEV
Federal remediation due
2026-05-03 (143 days overdue)
Ransomware campaign use
Known
CISA description
WebPros cPanel & WHM (WebHost Manager) and WP2 (WordPress Squared) contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Named threat actors
Mirai
Sources & citations (9)
- VMware vCenter CVE-2026-59310: Babuk Hits 47 Nations tech-insider.org · 2026-09-05
- CISA: WatchGuard RCE flaw now exploited in ransomware attacks bleepingcomputer.com · 2026-09-10
- CISA: WatchGuard Firebox bug exploited in ransomware campaigns scmagazine.com · 2026-09-10
- CISA: Ransomware Now Exploits Critical VMware vCenter Bug tech-insider.org · 2026-09-15
- CISA: WatchGuard Firebox Bug Hits Ransomware List [2026] tech-insider.org · 2026-09-15
- CISA: Critical VMware RCE flaw now exploited by ransomware gangs bleepingcomputer.com · 2026-09-15
- Ransomware Groups Target Critical VMware vCenter Flaw petri.com · 2026-09-15
- Patched VMware vCenter bug targeted in ransomware campaigns scworld.com · 2026-09-15
- Hackers Exploit cPanel CVE-2026-41940 Auth Bypass to Deploy Mirai Malware cybersecuritynews.com · 2026-09-21
References
See CVE-2026-41940 in context
RiskWire tracks every exploited CVE this week, cross-referenced against CISA KEV with federal remediation deadlines. Filtered to your vendor stack.
Book a 20-min demo →