cPanel Control Plane Breach Threatens Entire Hosting Fleets

cPanel/WHM is the control plane for hosted environments, so an auth bypass there turns one panel compromise into access across every site and account it manages. The standard response of patching the panel misses the backdoor problem already seen in the wild: attackers are keeping access with a Filemanager implant and using it to steal credentials. QiAnXin XLab tied CVE-2026-41940 exploitation to Mr_Rot13 and said more than 2,000 attacker source IPs are involved in automated attacks. The activity has already been linked to backdoor implantation, persistence, credential theft, and other abuse on cPanel and WHM systems. That changes the risk from a single vulnerable host to a durable foothold inside hosting environments. If the panel stays trusted after compromise, attackers can reuse it to reach hosted services and the credentials tied to them.

Part of the PlainSec briefing for 2026-05-17

Sources