Attackers exploit cPanel CVE-2026-41940 to deploy Filemanager Backdoor
2026-05-12T14:51:41Z•d039fe3676382724719af25428d33f3e714325a847a2daa576b4031684464daa
AI-enabled attacksAndroid banking trojanBerriAICISA KEVCVE-2026-41940CVE-2026-42208Crimenetwork takedownFilemanager backdoorGitHub breachInstagram E2EE removalJDownloaderPython RATSailPointTON networkTrickMocPanelremote code executionsupply chainvulnerability disclosurezero-day exploitation
What happened
Multiple active and high-impact threats reported: attackers are actively exploiting a critical cPanel vulnerability (CVE-2026-41940, CVSS 9.3) to deploy a Filemanager backdoor and gain admin access; CISA added a critical BerriAI LiteLLM flaw (CVE-2026-42208, CVSS 9.3) to its KEV catalog following rapid exploitation; the official JDownloader site was compromised to distribute installers containing a Python RAT (supply-chain malware); TrickMo Android banking malware evolved to use the TON network for C2 to improve stealth; SailPoint disclosed a GitHub repository breach (no customer data reported
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- d039fe3676382724719af25428d33f3e714325a847a2daa576b4031684464daa
- Enrichment time
- 2026-05-12T14:51:41Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.