HIGH: cPanel Drops Three More CVEs After Sorry Ransomware Wreckage, One Is a Perl Injection in create_user
cPanel and WHM shipped fixes for three new CVEs on May 8, 2026, including a CVSS 8.8 Perl code injection in the create_user API and a CVSS 8.8 unsafe symlink handling bug. The advisory is cPanel's second emergency Targeted Security Release in ten days, following the active weaponization of CVE-2026-41940 to deliver Mirai botnet variants and the Sorry ransomware strain. No exploitation of the three new flaws yet, but attackers already tooling against cPanel will dissect these patches fast.