Hackers target governments and MSPs via critical cPanel flaw CVE-2026-41940

2026-05-04T20:51:57Zfa390c0479d19e18c33ddff54b6ead1d348cd0e20d7cf3cb2bf9c1f8f133fa97
AI-accelerated-vuln-discoveryBluekitCISA-KEVCVE-2026-31431CVE-2026-41940CanadaIBM-ItalyLinux KernelMSPsNCSCSalt-TyphoonSoutheast-AsiaU.S.cPanelexploitationhosting-providerspatch-managementphishing-kitsupply-chainthreat-actorvoice-cloning

What happened

Multiple high-impact incidents and warnings: threat actors are actively exploiting a critical cPanel vulnerability (CVE-2026-41940, CVSS ~9.3) to target government, military and MSP/hosting networks across Southeast Asia and other countries (including the U.S. and Canada). The U.S. CISA added both the cPanel flaw and a Linux Kernel vulnerability (CVE-2026-31431, CVSS 7.8) to its Known Exploited Vulnerabilities catalog. The UK NCSC warns that AI accelerates vulnerability discovery, likely driving urgent large-scale patching. Separately, a new AI-enabled phishing kit (“Bluekit”) and a breach of

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
fa390c0479d19e18c33ddff54b6ead1d348cd0e20d7cf3cb2bf9c1f8f133fa97
Enrichment time
2026-05-04T20:51:57Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Hackers target governments and MSPs via critical cPanel flaw CVE-2026-41940 · Baitaphish