cPanel CVE-2026-41940 Under Active Exploitation to Deploy Filemanager Backdoor

A threat actor named Mr_Rot13 has been attributed to the exploitation of a recently disclosed critical cPanel flaw to deploy a backdoor codenamed Filemanager on compromised environments. The attack exploits CVE-2026-41940, a vulnerability impacting cPanel and WebHost Manager (WHM) that could result
ORIGINAL SOURCE →via The Hacker News
ADVERTISEMENT
⚡ STAY AHEAD
Events like this, convergence-verified across 689 sources, land in your inbox every Sunday. Free.
GET THE SUNDAY BRIEFING →RELATED · cyber
- [CYBER] Google says hackers used AI to exploit ‘zero-day’ flaw
- [CYBER] CVE-2026-42871 - WeGIA: Error Handling familiar_docfamiliar
- [CYBER] Google says hacker used Mythos-like AI for zero-day exploit
- [CYBER] CVE-2026-42866 - Tookie: Arbitrary file write via path traversal in -u username / -U userfile output filename
- [CYBER] CVE-2026-42864 - FireFighter: Unauthenticated SSRF in Raid jira_bot endpoint allows IAM credential theft
- [CYBER] CVE-2026-8305 - OpenClaw bluebubbles Webhook monitor.ts handleBlueBubblesWebhookRequest improper authentication