Security Alert – Critical cPanel Vulnerability (CVE-2026-41940)

Please read this announcement carefully and take immediate action if your server is affected.

On April 28, 2026, cPanel disclosed a critical authentication bypass vulnerability (CVE-2026-41940 – CVSS 9.8) affecting all supported versions of cPanel & WHM. This vulnerability has been actively exploited prior to the official announcement.

Full advisory:
https://support.cpanel.net/hc/en-us/articles/40073787579671-Security-CVE-2026-41940-cPanel-WHM-WP2-Security-Update-04-28-2026

Immediate Required Actions

First, update your cPanel installation to the latest version:

/scripts/upcp --force

If you are unable to update immediately, you must temporarily disable cPanel/WHM services and block the following ports:
2083, 2087, 2095, 2096

You can also run:

whmapi1 configureservice service=cpsrvd enabled=0 monitored=0 && \
whmapi1 configureservice service=cpdavd enabled=0 monitored=0 && \
/scripts/restartsrv_cpsrvd --stop && \
/scripts/restartsrv_cpdavd --stop

Confirmed Threat Activity

We have identified active attacks targeting outdated cPanel servers. Attackers are deploying a Linux botnet known as nuclear.x86, which performs the following:

  • Downloads and executes malicious binaries
  • Re-runs payloads multiple times
  • Deletes traces to evade detection
  • Performs full reconnaissance on the server

Compromised Data Risk

If your server was affected, you must assume the following data has been exposed:

  • SSH private keys and authorized access
  • System password hashes (/etc/shadow)
  • Shell history (including typed commands and credentials)
  • Server environment variables
  • Database credentials and configuration files
  • Access logs and connection history

Malware Behavior Indicator

If commands like:

wget google.com
curl google.com

return “Killed”, this indicates the malware is actively running and blocking these tools.

Required Cleanup Steps

  1. Kill the Malware Process
pkill -9 -f "./nuclear.x86"
pkill -9 -f "nuclear.x86"
ps auxf | grep -i nuclear

Then verify:

wget google.com

If it works normally, the malware has been stopped.

  1. Regenerate SSH Keys

All existing SSH keys must be considered compromised.

cp -a ~/.ssh ~/.ssh.compromised.$(date +%Y%m%d)rm -f ~/.ssh/authorized_keys ~/.ssh/authorized_keys2
rm -f ~/.ssh/id_*
rm -f ~/.ssh/known_hostsssh-keygen -t ed25519 -C "new-key-$(date +%Y%m%d)"

Update the new key across all services (GitHub, servers, CI/CD, etc.) and remove old keys.

  1. Rotate All Passwords

Immediately change:

  • cPanel / WHM passwords
  • FTP / SFTP accounts
  • Email accounts
  • MySQL / database credentials
  • CMS admin logins (WordPress, Joomla, etc.)
  • API keys, SMTP credentials, environment variables
  1. Audit Your Account

Check for unauthorized changes:

  • Email forwarders
  • Cron jobs
  • FTP accounts
  • SSH access
  • Suspicious or modified files (especially in public_html)
  1. External Password Reuse

If you reused your server credentials elsewhere, change them immediately on those platforms.

Important Clarification

The root cause of this issue is a zero-day vulnerability from cPanel itself. This is a global issue affecting many servers, including those with official licenses. It is not limited to any specific provider or licensing model.

Support Assistance

If you are not comfortable performing these steps, please open a support ticket and our team will handle the cleanup and securing process for you.

Please do not ignore this notice. This is a critical security risk that may extend beyond your server if not handled properly.

Best regards,
Support Team


Comments

Leave a Reply

Your email address will not be published. Required fields are marked *