cPanel CVE-2026-41940 compromise check
Your cPanel/WHM is patched, but were you compromised between Feb 23 and the day you patched? I run the cPanel-official IOC script on your server, audit your /home, /var/cpanel, /etc/cron, /tmp, SSH keys, bash history, and Filemanager backdoor signatures (Mr_Rot13 group). You get a clear report: clean / suspicious / confirmed compromised, with the exact next-step playbook.
What you get
- Full cPanel IOC scan report (PDF, English + Chinese)
- Filemanager / Mr_Rot13 backdoor signature check
- /etc/cron, SSH authorized_keys, bash history audit
- Concrete cleanup playbook if anything is found
- 1 follow-up email after you act on it