Linux hosting providers hit by ransomware, Mirai botnet and kernel privilege‑escalation exploits
Criminal groups have been exploiting a critical authentication‑bypass flaw in cPanel and WebHost Manager (WHM) identified as CVE‑2026‑41940. The vulnerability, active since late February, allowed unauthenticated remote access to the control panels of Linux‑based hosting servers, enabling attackers to encrypt files with the "Sorry" ransomware and to deploy a Mirai‑derived botnet for DDoS attacks. Researchers at Censys detected more than 7,100 compromised servers running cPanel or WHM and estimated up to ten thousand servers infected with the Mirai variant. Patches for CVE‑2026‑41940 have been available since 28 April, but many installations remain vulnerable.
Separately, a Linux kernel local‑privilege‑escalation flaw, CVE‑2026‑31431 (nicknamed "Copy Fail"), allows any unprivileged user to obtain root privileges via a 732‑byte Python exploit. All kernel versions released since 2017 are affected. CloudLinux, AlmaLinux and other RHEL‑derived distributions are preparing patches and KernelCare live‑patches, with mitigation guidance that involves blacklisting the algif_aead module via grubby. The security vendor Imunify360 also offers detection of exploit indicators. These developments underscore the ongoing risk landscape for web‑hosting environments that rely on cPanel/WHM and Linux kernels.