CVE-2026-41940

Critical cPanel Vulnerability Actively Exploited in Ransomware Attacks

A critical authentication bypass (CVE-2026-41940, CVSS 9.8) in cPanel & WHM is being mass-exploited to deploy “Sorry” ransomware, compromising over 44,000 servers worldwide. Small businesses running web servers or shared Linux hosting face complete data loss. Patches are available now—immediate action is required.

Continue Reading
Scroll to top