Breach404
Back to Insights
Secure Software2 min readMay 2, 2026

Critrical cPanel flaw mass-exploited in "Sorry" ransomware attacks

A critical vulnerability in cPanel identified as CVE-2026-41940 is currently being actively exploited by attackers to deliver the "Sorry" ransomware, allowing them to breach websites and encrypt sensitive data. Organizations using cPanel should immediatel

Could your website be vulnerable to attacks like this?

Run a free 10-point security scan on your site — headers, SSL, DNS, and more. Results in 15 seconds.

Test Your Site Now — It's Free