<img height="1" width="1" style="display:none;" alt="" src="https://px.ads.linkedin.com/collect/?pid=10643465&amp;fmt=gif">

Hackers Exploit Critical cPanel Flaw to Breach Military Servers and Steal 4GB of Sensitive Data

Hackers exploit CVE-2026-41940, breaching SE Asian military data. 110 files stolen. Patch cPanel urgently to secure systems.
Content Team

A sophisticated hacking campaign hit South-East Asian government and military targets by exploiting CVE-2026-41940, a critical CVSS 9.8 authentication bypass in cPanel and WHM. Attackers gained root-level access without valid credentials before a patch dropped on April 28, 2026. Beyond cPanel, hackers also cracked an Indonesian defense training portal using a CAPTCHA bypass and SQL injection, escalating to full OS access via PostgreSQL. The operation ended with 110 files (~4.37GB) stolen from the China Railway Society Electrification Committee, including financial records with national ID numbers and bank account details. The Shadowserver foundation tracked 44,000 IPs actively scanning for vulnerable servers. Patch cPanel immediately.

Source: Cybersecurity News

Share this article
Share on facebook Share on linkedin Share on twitter Share on email
blog_book_a_demo_cta_3x
Have questions about protecting your software?
Our escrow experts are standing by to help.
Book a free demo