Critical cPanel flaw exploited at scale in ransomware attacks

A critical cPanel and WHM authentication bypass, CVE-2026-41940, is being actively exploited to deploy the Sorry ransomware. The flaw lets unauthenticated attackers gain full administrative access to affected hosting servers, compromising websites, databases and hosted data. The campaign has been observed at scale, with tens of thousands of servers potentially impacted. Once inside, attackers run Linux-based ransomware that encrypts files and leaves ransom notes. Researchers say exploitation was under way before public disclosure.

What this means for your organisation

Most Norwegian organisations meet this case through their hosting provider rather than their own servers. If the provider is hit, website, webshop and email can disappear at the same time, with no way for you to fix it. The question then is whether you hold backups somewhere other than with that same provider, and whether you know how long a restore actually takes.

Berigo recommends

  • Ask your hosting provider whether they are affected, and whether and when the update was applied.
  • Keep your own backups of website and database outside the provider's platform.
  • Test a restore, so you know how long it takes before you need it.
  • Cover in your response plan how you inform customers if website and email are down together for several days.

Source

Related services

Security that is understood, governed and works.

Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.

Get in touch