Get DeafLetter
A weekly selection of signals, vulnerabilities and guides. Critical alerts remain optional.
You can unsubscribe at any time. Privacy policy.
Editor's note: The correlation between CVE-2026-41940 and the Mirai activity described in this article is probabilistic, based on traffic observations and third-party reports. JPCERT/CC has explicitly stated that monitoring data alone does not prove the infection path. Information is drawn primarily from the cPanel advisory, JPCERT/CC observations, and the CISA KEV catalog.
On April 30, 2026, JPCERT/CC's TSUBAME sensor network recorded a spike in Mirai-like traffic targeting TCP port 23. The majority of source IP addresses were assigned to hosting providers and associated with cPanel interfaces. CISA has added CVE-2026-41940 to its Known Exploited Vulnerabilities catalog, confirming active in-the-wild exploitation.
- CVE-2026-41940 is an authentication bypass in cPanel/WHM affecting all versions after 11.40
- JPCERT/CC observed a roughly 15-fold increase in Mirai-like traffic from Japan starting April 30, 2026
- The exploit chains CRLF injection with session token leakage to gain WHM access, per the watchTowr PoC
- CISA cataloged the vulnerability as "Known" exploited; JPCERT/CC notes that traffic observation alone does not prove the infection path
The Mechanism: From CRLF Injection to WHM Access
The official cPanel advisory describes CVE-2026-41940 as "an authentication bypass security issue" affecting "all versions after 11.40," including the DNSOnly distribution. The advisory rates severity as maximum.
Technical details published by watchTowr in their PoC document an exploit chain leveraging CRLF injection combined with session token leakage. A pre-authentication attacker hijacks the session token, propagates it through the internal cache, and gains access to the WHM panel. The mechanism has been verified on builds such as 11.110.0.89.
cPanel released emergency patches on April 28, 2026, with multiple updates in the following days. The advisory also includes a detection script to identify potentially compromised systems.
The Numbers Behind the Anomalous Traffic
Data collected by JPCERT/CC's TSUBAME sensor network provides a temporal and geographic mapping. The spike began on April 30, 2026. The United States accounted for the largest share of source traffic, with significant increases also recorded in Germany, France, and Canada. Mirai-like traffic from Japan grew roughly 15-fold compared to pre-spike levels.
JPCERT/CC highlighted that "many source addresses were assigned to several hosting providers" and that "cPanel administration interfaces were on many of the hosts." The correlation between these servers and the CVE-2026-41940 exploit is considered probable by separate reports, but the organization underscores methodological limits: traffic monitoring alone cannot prove the infection path.
"the monitoring cannot prove the infection path alone. Still, separate reporting indicated exploitation was likely tied to Mirai or Mirai-variant activity" — JPCERT/CC
From IoT to Servers: Mirai's Leap
The campaign documented by JPCERT/CC represents an expansion of Mirai's traditional attack surface. The botnet, known for compromising IoT devices, is demonstrating an ability to adapt toward higher-value targets.
As JPCERT/CC observed: "Mirai and its variants are generally associated with infections of IoT devices, but infections are not limited to such devices. As this case illustrates, servers can also be compromised." A compromised cPanel/WHM panel exposes websites, databases, email accounts, and entire multi-tenant client ecosystems.
Immediate Actions for Administrators
cPanel recommends specific actions for system administrators:
- Update to the patched cPanel/WHM software version; fixed versions are listed in the April 28, 2026 advisory
- Run the detection script published by cPanel to identify any prior compromises
- Temporarily block ports 2083, 2087, 2095, and 2096 as a containment mitigation if immediate updating is not feasible
- Monitor logs for anomalous WHM access
The Parallel Campaign: "Sorry" Ransomware
BleepingComputer has documented mass exploitation of the same CVE-2026-41940 to deploy the "Sorry" ransomware, with over 44,000 compromised cPanel IP addresses. This data does not refer to the Mirai campaign: the two campaigns could be the work of the same actor or distinct actors independently exploiting the same vulnerability. The dossier does not clarify this relationship.
The existence of a public PoC and multiple active campaigns makes CVE-2026-41940 a shared attack surface: the same flaw attracts operators with different objectives, from building DDoS botnets to extortion via encryption.
Why the Transition Matters
Mirai's migration from IoT devices to cPanel servers alters the risk calculus for hosting providers. A compromised router generates malicious bandwidth; a compromised hosting control panel can catapult entire providers into a global DDoS campaign, with cascading effects on thousands of sites and services.
The presence in CISA's KEV catalog and the availability of a public PoC demand a high patching priority. The cPanel advisory of April 28, 2026 remains the authoritative reference for fixed versions and detection procedures.
Sources: CyberSecurityNews | JPCERT/CC TSUBAME | cPanel Security Advisory | CISA KEV | CyberSecurityNews/watchTowr PoC
Information has been verified against cited sources and is current as of publication.
Sources
- https://cybersecuritynews.com/cpanel-cve-2026-41940/
- https://blogs.jpcert.or.jp/en/2026/09/tsubame_overflow_2026-04-06.html
- https://support.cpanel.net/hc/en-us/articles/40073787579671-cPanel-WHM-Security-Update-04-28-2026
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-41940
- https://cybersecuritynews.com/cpanel-0-day-authentication-bypass-vulnerability/
- https://nvd.nist.gov/vuln/detail/cve-2026-41940
- https://www.cryptika.com/hackers-exploit-cpanel-cve-2026-41940-auth-bypass-to-deploy-mirai-malware/
- https://www.bleepingcomputer.com/news/security/critrical-cpanel-flaw-mass-exploited-in-sorry-ransomware-attacks/
Get DeafLetter
A weekly selection of signals, vulnerabilities and guides. Critical alerts remain optional.
You can unsubscribe at any time. Privacy policy.