Hackers target governments and MSPs via critical cPanel flaw CVE-2026-41940
2026-05-04T20:51:57Z•fa390c0479d19e18c33ddff54b6ead1d348cd0e20d7cf3cb2bf9c1f8f133fa97
AI-accelerated-vuln-discoveryBluekitCISA-KEVCVE-2026-31431CVE-2026-41940CanadaIBM-ItalyLinux KernelMSPsNCSCSalt-TyphoonSoutheast-AsiaU.S.cPanelexploitationhosting-providerspatch-managementphishing-kitsupply-chainthreat-actorvoice-cloning
What happened
Multiple high-impact incidents and warnings: threat actors are actively exploiting a critical cPanel vulnerability (CVE-2026-41940, CVSS ~9.3) to target government, military and MSP/hosting networks across Southeast Asia and other countries (including the U.S. and Canada). The U.S. CISA added both the cPanel flaw and a Linux Kernel vulnerability (CVE-2026-31431, CVSS 7.8) to its Known Exploited Vulnerabilities catalog. The UK NCSC warns that AI accelerates vulnerability discovery, likely driving urgent large-scale patching. Separately, a new AI-enabled phishing kit (“Bluekit”) and a breach of
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- fa390c0479d19e18c33ddff54b6ead1d348cd0e20d7cf3cb2bf9c1f8f133fa97
- Enrichment time
- 2026-05-04T20:51:57Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.