Exposed cPanel servers are being pulled into Mirai botnets

Exposed cPanel servers are being pulled into Mirai botnets. Hosting providers and their customers face disruption as attackers exploit a critical authentication bypass in cPanel and WHM.

This is a DailyCyber.News update, brought to you by BareMetalCyber.com, for Monday, September 21st, 2026.

Hosting providers and their customers face disruption as attackers exploit a critical authentication bypass in cPanel and WHM. The weakness lets an attacker reach administrative functions without a valid account, creating a path to server takeover. Monitoring found a sharp increase in Mirai-like traffic targeting Telnet, and many source addresses were linked to hosting providers running cPanel interfaces. That monitoring alone cannot prove how each server was infected, but separate reporting indicated the exploitation was likely connected to Mirai or one of its variants. Once compromised, a hosting server can probe other systems, spread attacks, or support denial-of-service operations. A provider may also expose multiple customer sites through a single breached management layer. Leaders should treat hosting control panels with the same urgency as other internet-facing privileged systems. Defenders should install the vendor fixes, restrict administration to trusted networks, disable unnecessary Telnet access, and review logs for unexplained sessions, accounts, configuration changes, or files. Patch every affected cPanel instance immediately and investigate exposed systems for unauthorized administrative activity.

For the sources and the full Daily Cyber newsletter, visit DailyCyber.News.

Exposed cPanel servers are being pulled into Mirai botnets
Broadcast by