What is CVE-2026-41940?
CVE-2026-41940 is a critical vulnerability affecting cPanel and WHM servers. Attackers are actively exploiting this flaw by weaponizing GitHub-hosted runners to deploy 583 malicious workflows, targeting cloud keys, API tokens, and SSH data from exposed servers. Immediate patching of cPanel/WHM installations is strongly advised.
Azərbaycanca: CVE-2026-41940, cPanel və WHM serverlərinə təsir edən kritik boşluqdur. Təcavüzkarlar bu zəiflikdən istifadə edərək GitHub Actions vasitəsilə avtomatlaşdırılmış kampaniya ilə serverlərdəki bulud açarları, API tokenləri və SSH məlumatlarını oğurlayırlar. cPanel/WHM sistemlərini dərhal ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: shared threat actors: ShinyHunters, UNC6240; shared vendors: Google Threat Intelligence Group, Mandiant, Oracle
FAQ2
Which systems are affected by the CVE-2026-41940 vulnerability?
This critical vulnerability affects cPanel and WHM servers.
What do attackers target by exploiting CVE-2026-41940?
Attackers are targeting cloud keys, API tokens, and SSH data from exposed servers through automated campaigns using GitHub Actions.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.