#LinuxRansomware
A critical auth bypass in WHM and cPanel (CVE-2026-41940) is being mass-exploited to deploy "Sorry" ransomware on 44,000+ servers, encrypting files with a .sorry extension. #CVE202641940 #LinuxRansomware #HostingSecurity
Critrical cPanel flaw mass-exploited in "Sorry" ransomware attacks
A critical authentication bypass in WHM and cPanel (CVE-2026-41940) is being mass-exploited to breach servers and deploy a Linux encryptor used in "Sorry" ransomware attacks. At least 44,000 cPanel hosts have been compromised and hundreds of affected sites are indexed by Google, so administrators must apply the emergency update immediately to prevent further encryption and data theft. #CVE-2026-41940 #SorryRansomware
www.hendryadrian.com
May 3, 2026 at 3:45 AM