Security
Sorry ransomware exploits critical cPanel authentication flaw
Sorry ransomware is targeting cPanel-hosted sites through a critical authentication bypass in cPanel and WHM, encrypting files and adding the .sorry extension.
Research published by mySites.guru says the malware is a host-level threat that can affect Joomla, WordPress, Drupal and static sites. It encrypts accessible files and appends .sorry to their names.
The entry point is CVE-2026-41940, a pre-authentication authentication-bypass flaw caused by CRLF injection in cPanel and WHM’s login and session handling. WebPros rated it CVSS 9.8. The affected surface includes cPanel and WHM releases after v11.40, while WP Squared versions through 136.1.6 are also affected. Exploitation was reportedly observed from 23 February 2026, before disclosure on 28 April.
Administrators should upgrade to a fixed release: 11.110.0.97, 11.118.0.63, 11.126.0.54, 11.132.0.29, 11.134.0.20, 11.136.0.5 or WP Squared 136.1.7. If compromise is suspected, do not reuse the host: rebuild on a patched system, restore a known-good backup and rotate every credential stored or used there.
Originally reported by mySites.guru.