Hackers are exploiting a critical cPanel and WHM flaw to place Mirai malware on exposed servers, extending a botnet threat normally associated with connected devices.
The activity produced a sharp rise in suspicious Telnet traffic and exposed a wider Internet security problem. Its use directly against servers creates concern for organizations that may not associate conventional hosting infrastructure with Mirai-driven botnet operations.
The issue, CVE-2026-41940, lets an unauthenticated attacker bypass the login process on vulnerable cPanel and WHM systems. With administrative access, an intruder can alter settings, add malicious files, and attack other systems.
The campaign shows why unpatched management interfaces remain targets. Analysts at JPCERT/CC identified a sudden increase in Mirai-like packets aimed at TCP port 23 in early May.
The surge began on April 30 and then gradually declined, but connected compromised hosting infrastructure to a botnet ecosystem.
Many observed source addresses belonged to hosting providers, and researchers found cPanel administration interfaces when they visited those addresses.
JPCERT/CC said in a report shared with Cyber Security News (CSN) that the monitoring cannot prove the infection path alone. Still, separate reporting indicated exploitation was likely tied to Mirai or Mirai-variant activity.
Hackers Exploit cPanel CVE-2026-41940 Auth Bypass
CVE-2026-41940 is a severe authentication-bypass flaw affecting cPanel and WHM deployments. It enables access to administrative functions without a valid account, creating a route to complete compromise.
Earlier coverage of active cPanel zero-day exploitation detailed how the weakness was exploited before organizations had time to apply emergency fixes.
Once inside, attackers can turn a web-hosting server into an operational foothold instead of simply stealing hosted data.
Mirai-derived code can use that foothold to probe exposed services, spread through additional targets, or supply traffic for denial-of-service operations. This broadens the impact beyond one breached control panel, especially where providers manage many sites.

The observed traffic focused on port 23, commonly used by Telnet, a legacy remote-access protocol that should not be exposed.
Mirai families have repeatedly abused weak credentials and reachable remote services; the evolving Mirai botnet threat shows why attackers seek fast ways to add systems to their networks.
The activity may have involved Mirai infections exploiting CVE-2026-41940. The organization also noted reports of other harm unrelated to Mirai, showing that authentication bypass enables other abuse.
Worldwide Signals and Defensive Steps
The United States accounted for the largest source-traffic share. Sharp increases also appeared around May 1 in Germany, France, and Canada.
Changing regional patterns suggested that infections were distributed across the Internet rather than limited to a single country, provider, or cluster of servers.
Japan reflected the same trend. Mirai-like traffic from Japanese addresses targeting port 23 rose to roughly 15 times the level seen before the increase.
At the peak, many packets came from addresses assigned to several hosting providers. The server takeover campaign analysis provides useful context on the risk created by exposed cPanel and WHM installations.
For defenders, the first priority is to install the vendor fixes for CVE-2026-41940 on every affected server and verify that no outdated instance remains reachable.
Administrators should also restrict remote administration to trusted networks, disable Telnet where it is not essential, and replace weak or reused passwords with strong unique credentials.
Organizations that suspect compromise should inspect active processes and outbound network connections, checking whether each service has a clear operational purpose.
They should also review cPanel and system logs for unexpected administrative sessions, new accounts, configuration changes, or unexplained files.
The new cPanel flaw disclosures reinforce the need to treat hosting panels as high-value systems requiring regular patching and monitoring. The incident is a reminder that Mirai is not confined to cameras, routers, and other Internet of Things devices.
A compromised server can become another botnet node, exposing its operator and customers to disruption and further abuse. Prompt patching, limited remote access, and continuous review of unusual traffic remain the most practical safeguards.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
The post Hackers Exploit cPanel CVE-2026-41940 Auth Bypass to Deploy Mirai Malware appeared first on Cyber Security News.
