Critical cPanel Flaw Exploited to Hit Government, Military and MSP Networks
Security researchers at Ctrl-Alt-Intel reported that a previously unseen threat actor has been exploiting a high-severity weakness in cPanel and WebHost Manager (WHM) – tracked as CVE-2026-41940 – which can be abused to bypass authentication and give remote attackers elevated control over affected control panels.
The intrusions have been traced back to the IP address 95.111.250[.]175 and appear to focus on government and military infrastructure in Southeast Asia, along with a smaller set of managed service providers and hosting firms located in the Philippines, Laos, Canada, South Africa and the United States. The actor has been leveraging publicly available proof-of-concept exploit code to carry out many of these compromises.
Ctrl-Alt-Intel also uncovered an earlier, separate exploitation chain used against an Indonesian defense-sector training portal before the cPanel campaign began. In that case, the attacker combined an authenticated SQL injection with remote code execution to compromise the application, and investigators say the adversary already possessed valid account credentials for the portal prior to launching the exploit.
According to the analysis, the attack script relied on embedded credentials and bypassed the portal’s CAPTCHA by extracting the expected CAPTCHA value from the server-issued session cookie instead of solving the challenge in the usual way. After authenticating and circumventing the CAPTCHA, the intruder focused on a document-management endpoint: the field used to store a document name was vulnerable, and the script injected SQL into that parameter when posting to the document-save function.
After gaining access, the actor deployed the AdaptixC2 command-and-control framework to manage the compromised host remotely. The campaign also used OpenVPN and Ligolo to create resilient access into victim environments, together with systemd-based persistence. Ctrl-Alt-Intel noted the attacker built a durable access layer with OpenVPN, Ligolo and systemd persistence, then pivoted into internal networks and exfiltrated a large collection of Chinese railway-sector documents.
Attribution remains unclear. Separately, Censys reported evidence that multiple third parties began weaponizing the cPanel vulnerability within 24 hours of its public disclosure, including activity associated with Mirai botnet variants and a ransomware family known as Sorry.
Data from the Shadowserver Foundation indicates that at least 44,000 IP addresses that were likely compromised via CVE-2026-41940 engaged in scanning and brute-force activity against its honeypots on April 30, 2026. That number declined to roughly 3,540 by May 3.