cPanel Patch Halts Mass Ransomware Attack on 44,000 Servers
Apply the WHM/cPanel emergency update immediately to fix CVE-2026-41940 and stop the Sorry ransomware spread.
Install the WHM/cPanel emergency update immediately to block the authentication bypass and prevent Sorry ransomware attacks.
Summary
In early May 2026, a critical flaw in the popular web‑hosting control panel cPanel was exploited on a massive scale, compromising roughly 44,000 servers worldwide. Attackers used the vulnerability, identified as CVE‑2026‑41940, to bypass authentication and deploy ransomware, while a threat actor known as Mr_Rot13 installed a web‑based backdoor called Filemanager. The attack spread rapidly across hosting providers, leaving administrators scrambling to contain the damage.
The flaw lies in cPanel’s authentication module, which validates user credentials. By exploiting a logic error, remote attackers can log in without valid credentials, gaining full control of the control panel. Mr_Rot13 leveraged this to run arbitrary commands and install the Filemanager backdoor, which allows uploading, downloading, and executing files on the compromised server. The backdoor also provides a persistent foothold for future attacks.
cPanel responded swiftly, releasing an emergency patch on May 8, 2026, just ten days after the vulnerability was first publicly exploited. The update fixes the authentication bypass and removes the Filemanager code, and it also addresses three additional vulnerabilities discovered later. The company urged all cPanel/WHM users to apply the patch immediately, warning that failure to do so could allow further ransomware deployment.
The incident has highlighted the fragility of shared hosting environments and the importance of rapid patch management. Hosting providers and security teams have been forced to review their update procedures, and the broader cybersecurity community has called for tighter controls on third‑party software. While the patch has closed the immediate threat, the scale of the breach underscores the need for continuous vigilance against authentication bypasses.
Key changes
- CVE-2026-41940 is an authentication bypass flaw in WHM and cPanel
- An emergency update has been released to fix the flaw
- The flaw is being exploited by the Sorry ransomware campaign
- At least 44,000 IP addresses running cPanel have been compromised
- The ransomware uses a Go encryptor that appends a .sorry extension to encrypted files
- It encrypts files with ChaCha20 and embeds an RSA-2048 public key
- Decryption requires the private RSA-2048 key, which is unavailable
- A ransom note instructs victims to contact the threat actor via a fixed Tox ID