JPCERT/CC’s quarterly TSUBAME internet-threat monitoring dispatch for April through June 2026 flags one standout event: a sudden, sharp spike in Mirai-like traffic hitting port 23/TCP that traces back to a critical authentication-bypass flaw in cPanel and WHM.
The report, now folded into JPCERT/CC’s broader Quarterly Report structure starting this fiscal year, otherwise found no anomalies severe enough to warrant a special advisory, but the Telnet surge alone makes this edition worth a close read for defenders running exposed hosting infrastructure.
The surge mainly involved Telnet traffic on TCP port 23, which Mirai-style attacks target commonly. Organizations running internet-facing cPanel/WHM servers should prioritize patching and monitoring suspicious network activity.
Critical cPanel/WHM Bypass
TSUBAME’s Japan-based sensors registered a dramatic jump in Mirai-signature packets aimed at port 23 beginning April 30, 2026, peaking in early May before tapering off over subsequent weeks. Traffic originating from Japan followed the same arc, climbing to roughly 15 times pre-surge levels at its height.
Investigators who pivoted to the source IPs found many belonged to commercial hosting providers, and browsing to those addresses frequently surfaced live cPanel administration login pages, a strong hint that the compromised hosts were servers, not the IoT devices Mirai typically infects.

JPCERT/CC couldn’t establish causation from sensor data alone, but corroborating research from Censys and Japan’s NICTER analysis team pointed to the same culprit during the same window: CVE-2026-41940, a critical authentication-bypass vulnerability in cPanel, WHM, and the WordPress-hosting variant WP Squared.
The flaw, disclosed April 29, 2026, carries a CVSS score of 9.8 and stems from a CRLF injection in the login and session-handling logic.
An unauthenticated attacker can smuggle carriage-return and line-feed characters into a Basic Auth header, corrupting server-side session files to plant fabricated properties like user=root and a forged authentication timestamp.
The result is instant, unauthenticated root access to the control panel, with no user interaction required. It affects every supported cPanel & WHM branch released after version 11.40, a codebase lineage stretching back to 2013.

Regional breakdowns show the United States generated the largest share of Mirai-like packets, with parallel spikes around May 1 in Germany, France, and Canada.
Crucially, the distribution shifted across regions over time rather than clustering in one place, evidence of broad, opportunistic scanning rather than a targeted campaign against a specific country or sector.
National CERTs in Australia, Canada, Singapore, and Belgium all issued independent advisories on CVE-2026-41940 within days of disclosure, reflecting how quickly exploitation went global.
A sensor-by-sensor comparison across Japan, North America, Europe, and other regions confirmed 23/TCP as the most-observed destination port at nearly every location, though a few sensors saw more 443/TCP traffic.
Ports 80, 8080, and 22 appeared consistently across nearly all sensors, indicating that generic scanning against these services persists globally regardless of geography.
Overseas sensors logged higher packet volumes than domestic ones overall, and Japan’s domestic sensors saw volumes recede again by June.
JPCERT/CC’s guidance echoes standard Mirai hardening: patch promptly (cPanel & WHM 11.136.0.5 and WP Squared 136.1.7 or later close the hole), restrict remote administrative access, eliminate weak or default credentials, and audit running processes and network connections for signs of compromise.
Given that WHM/cPanel manages an estimated tens of millions of domains worldwide, unpatched instances remain a high-value target for botnet operators well beyond this reporting quarter.
Site: Thecyberdef.com
Follow TheCyberDef on Google News, LinkedIn & X for the latest cybersecurity updates. Stay informed.