Sorry Ransomware Victims: cPanel Zero-Day CVE-2026-41940 Attack Analysis

Hosting providers and website owners using cPanel are facing a catastrophic ransomware campaign that has already encrypted thousands of Linux servers worldwide. The attackers behind the “Sorry” ransomware family have weaponized a critical zero-day vulnerability (CVE-2026-41940) to gain root access to WebHost Manager, deploy deeply embedded backdoors, and encrypt entire hosting environments—demanding ransoms through untraceable peer-to-peer networks.

The Victims: cPanel Hosting Environments Under Siege

Unlike traditional ransomware that targets individual workstations, the 2026 “.sorry” campaign focuses exclusively on Linux servers running cPanel and WHM—infrastructure that powers an estimated 70 million domains globally. When a single server is compromised, dozens or even hundreds of websites, databases, and customer portals are encrypted simultaneously.

Victims report catastrophic losses including:

  • WordPress installations and theme configurations
  • MySQL databases containing customer records and transaction histories
  • Legacy media files (including irreplaceable SWF archives and proprietary imagery)
  • Radio station control panels and streaming configurations
  • E-commerce platforms with active shopping carts and order processing systems

All encrypted files are appended with the .sorry extension, transforming index.php into index.php.sorry and rendering entire websites inaccessible. A 404-byte ransom note named README.md is dropped in every affected directory.

How Attackers Breach cPanel Servers

The attack begins with exploitation of CVE-2026-41940, a critical authentication bypass vulnerability in cPanel’s session handling mechanism. The flaw allows unauthenticated remote attackers to achieve root administrative access without ever providing valid credentials.

Technical Attack Chain:

  1. CRLF Injection: Attackers send a malicious HTTP Basic authorization header containing raw Carriage Return Line Feed (\r\n) characters.
  2. Session File Poisoning: The cPanel daemon (cpsrvd) writes unsanitized data to the session file, allowing injection of arbitrary key-value pairs.
  3. Privilege Escalation: By injecting user=root, hasroot=1, and tfa_verified=1, attackers promote their session to full root access—bypassing passwords and two-factor authentication.
  4. SIEM Evasion: The exploit triggers a falsified log entry reading “FAILED LOGIN whostmgrd: user password incorrect,” making the breach invisible to administrators monitoring for successful logins.

Threat intelligence indicates active exploitation began as early as February 23, 2026—over two months before cPanel’s emergency patch on April 28, 2026. At disclosure time, Shodan identified approximately 1.5 million potentially vulnerable cPanel instances exposed to the internet.

Deep Persistence: Why Simple Patching Isn’t Enough

Once inside, the Sorry ransomware operators deploy a sophisticated, multi-layered persistence framework designed to survive reboots, patching, and even partial system restoration. Forensic analysis of compromised servers reveals the following backdoors installed within minutes of initial access:

  • SSH Key Injection: Attacker-controlled ed25519 public keys appended to /root/.ssh/authorized_keys for password-less backdoor access.
  • Hidden SUID Binary: A 964 KB ELF binary dropped at /usr/bin/.system_cache (note the leading dot hiding it from ls listings). The Set-User-ID bit allows instant root privilege escalation from any user account.
  • Cron Job C2 Beacons: Daily callback scripts written to /etc/cron.daily/cpanel_sync that fetch updated payloads from command-and-control servers.
  • Bashrc Execution Hooks: Malicious droppers appended to /root/.bashrc, ensuring re-infection every time an administrator logs in interactively.

This persistence model means that victims who simply apply the cPanel patch or restore encrypted files from backup without complete system sterilization will be re-compromised almost immediately.

The Ransom Demand: qTox and Operational Security

The 404-byte README.md ransom note represents a significant evolution in operational security. Unlike earlier variants that used centralized Telegram bots (which can be banned by platform administrators), the 2026 campaign demands victims download qTox—a peer-to-peer, end-to-end encrypted messaging application requiring no central servers.

Excerpt from the ransom note:

“Please contact us through the qtox tool Download qtox… If you can’t contact us, please contact some data recovery company(suggest taobao.com), may they can contact to us. Add our TOX ID and send an encrypted file and ‘Sorry-ID’ for testing decryption. Our TOX ID: 3D7889AEC00F2325E1A3FBC0ACA4E521670497F11E47FDE13EADE8FED3144B5EB56D6B198724”

The Tox protocol uses distributed hash tables (DHT) and peer-to-peer routing, making it virtually impossible for law enforcement to censor communications, seize domains, or trace attacker IP addresses. The note also suggests victims hire “data recovery companies” via Taobao.com—intermediaries who secretly negotiate with the gang and add massive markups to the ransom cost.

No Free Decryption: The Harsh Reality

Unlike the 2019 “Ims00rry” variant—which used weak AES-128 encryption that Emsisoft successfully cracked—the 2026 Linux campaign employs robust, unbreakable cryptographic standards. As of this writing, no public decryption utility exists for files encrypted with the .sorry extension.

Victims without secure, off-site, immutable backups face permanent data loss. The only guaranteed recovery method is complete system rebuild from bare metal, as attempting to manually clean a rooted server is forensically unsound.

CISA Directive and Mandatory Remediation

On April 30, 2026, CISA added CVE-2026-41940 to its Known Exploited Vulnerabilities catalog under Binding Operational Directive 22-01, mandating federal agencies to patch by May 3, 2026. Private sector organizations are strongly urged to follow the same timeline.

Required Actions for cPanel Administrators:

  1. Immediate Containment: Block external access to TCP ports 2083 (cPanel) and 2087 (WHM) at the firewall level.
  2. Sterilize Persistence Mechanisms: Audit /root/.ssh/authorized_keys, hunt for hidden SUID binaries (find / -perm -4000 -type f), remove malicious cron jobs, and cleanse .bashrc files.
  3. Emergency Patching: Execute /scripts/upcp --force to upgrade to safe versions (e.g., 11.136.0.5 or later across all release branches).
  4. Immutable Backups: Implement autonomous snapshot systems like AWS FSx ONTAP’s ARP, which detects ransomware encryption patterns and generates recovery points milliseconds before encryption completes.

The Bigger Picture: Zero-Days for Profit

The 2026 “.sorry” campaign marks a watershed moment in ransomware evolution. Historically, zero-day exploits were the exclusive domain of nation-state actors focused on espionage. Financially motivated ransomware groups relied on phishing, weak RDP credentials, or long-unpatched N-day vulnerabilities.

This campaign demonstrates definitively that cybercriminal syndicates now possess the capital, R&D resources, and technical sophistication to discover, stockpile, and weaponize zero-day vulnerabilities at scale against global infrastructure. The shift from targeting individual Windows endpoints to dominating Linux enterprise servers reflects ruthless optimization: one compromised cPanel instance paralyzes hundreds of websites simultaneously, maximizing leverage and forcing faster ransom payouts.

For hosting providers and website owners, the lesson is unforgiving: internet-facing control panels are the new frontline. Patch management measured in weeks is no longer acceptable—remediation SLAs must be measured in hours. And without immutable, offline backups, you are playing Russian roulette with your entire business.

Tzar C. Umang is a technology leader with over 15 years of experience making new technologies work for different industries. As the Chief Technology Officer at Makerspace Innovhub OPC and the Lead Developer for SUI Philippines, he leads projects that create growth and opportunities for everyone. With a strong background in blockchain development, AI engineering, and cybersecurity, Tzar has worked with organizations like the DOST Smarter Philippines Project Management Office and US startup Auto Genie. He is committed to helping the next generation of tech professionals, serving as a cybersecurity instructor at the University of Luzon and a mentor for the Saleng Mentors Group. In his free time, Tzar focuses on building practical solutions for education, healthcare, and new businesses.

Site Footer