Active exploitation of cPanel authentication bypass (CVE-2026-41940) delivering Filemanager backdoor
Summary
Hide ▲
Show ▼
A threat actor identified as Mr_Rot13 is actively exploiting CVE-2026-41940, a critical authentication bypass vulnerability in cPanel and WebHost Manager (WHM), to deploy a backdoor named Filemanager across compromised environments. The flaw enables remote attackers to gain elevated control of cPanel instances, leading to post-exploitation activities including cryptocurrency mining, ransomware deployment, botnet propagation, and persistent backdoor implantation. The attack chain involves shell scripts fetching a Go-based infector from cp.dene.[de[.]com, which installs an SSH public key for persistence, drops a PHP web shell for remote command execution, and injects JavaScript into login pages to harvest credentials via a ROT13-encoded domain (wrned[.]com). The final payload is a cross-platform backdoor capable of infecting Windows, macOS, and Linux systems.
Timeline
-
11.05.2026 20:54 1 articles · 2h ago
Mr_Rot13 exploits cPanel authentication bypass (CVE-2026-41940) to deploy Filemanager backdoor
Active exploitation of CVE-2026-41940 by threat actor Mr_Rot13 began shortly after public disclosure, with observed campaigns delivering a Go-based infector that implants persistence mechanisms (SSH public key), a PHP web shell for remote operations, and a cross-platform Filemanager backdoor. The backdoor supports file management, remote command execution, and data collection, including credentials and host information, exfiltrated to attacker-controlled domains and a Telegram group.
Show sources
- cPanel CVE-2026-41940 Under Active Exploitation to Deploy Filemanager Backdoor — thehackernews.com — 11.05.2026 20:54
Information Snippets
-
CVE-2026-41940 is an authentication bypass vulnerability in cPanel and WHM enabling remote attackers to obtain elevated control of affected control panels.
First reported: 11.05.2026 20:541 source, 1 articleShow sources
- cPanel CVE-2026-41940 Under Active Exploitation to Deploy Filemanager Backdoor — thehackernews.com — 11.05.2026 20:54
-
Threat actor Mr_Rot13 is actively exploiting CVE-2026-41940 to deploy the Filemanager backdoor, with over 2,000 attacker IPs observed globally primarily originating from Germany, the United States, Brazil, and the Netherlands.
First reported: 11.05.2026 20:541 source, 1 articleShow sources
- cPanel CVE-2026-41940 Under Active Exploitation to Deploy Filemanager Backdoor — thehackernews.com — 11.05.2026 20:54
-
The exploit chain uses a shell script to download a Go-based infector from cp.dene.[de[.]com, which establishes persistence via an SSH public key and drops a PHP web shell for remote command execution and file operations.
First reported: 11.05.2026 20:541 source, 1 articleShow sources
- cPanel CVE-2026-41940 Under Active Exploitation to Deploy Filemanager Backdoor — thehackernews.com — 11.05.2026 20:54
-
The PHP web shell injects JavaScript into login pages to harvest credentials, sending stolen data to a ROT13-encoded domain (wrned[.]com) controlled by the attacker.
First reported: 11.05.2026 20:541 source, 1 articleShow sources
- cPanel CVE-2026-41940 Under Active Exploitation to Deploy Filemanager Backdoor — thehackernews.com — 11.05.2026 20:54
-
The final payload is a cross-platform backdoor supporting file management, remote command execution, and shell functionality across Windows, macOS, and Linux systems.
First reported: 11.05.2026 20:541 source, 1 articleShow sources
- cPanel CVE-2026-41940 Under Active Exploitation to Deploy Filemanager Backdoor — thehackernews.com — 11.05.2026 20:54
-
The backdoor exfiltrates sensitive host data including bash history, SSH data, device information, database passwords, and cPanel virtual aliases to a 3-member Telegram group operated by user "0xWR".
First reported: 11.05.2026 20:541 source, 1 articleShow sources
- cPanel CVE-2026-41940 Under Active Exploitation to Deploy Filemanager Backdoor — thehackernews.com — 11.05.2026 20:54
-
The C2 domain embedded in the JavaScript code was first registered in October 2020 and has been used in a PHP backdoor uploaded to VirusTotal in April 2022, indicating long-term operation by the threat actor.
First reported: 11.05.2026 20:541 source, 1 articleShow sources
- cPanel CVE-2026-41940 Under Active Exploitation to Deploy Filemanager Backdoor — thehackernews.com — 11.05.2026 20:54