An emerging ransomware group calling itself “Sorry” has surfaced with an aggressive opportunistic strategy: exploiting the cPanel authentication bypass vulnerability (CVE-2026-41940) within just 48 hours of its public disclosure. The group deploys a Linux encryptor written in Golang that appends the .sorry extension to encrypted files.
The underlying vulnerability is a CRLF injection flaw affecting cPanel versions from 11.42 (March 2014) through the patched releases issued on May 1, 2026. The exploit is elegant in its simplicity — it chains three steps: capturing a pre-auth session cookie from a failed login attempt, injecting carriage return and line feed characters into the session file to write root-level privilege values, and then forcing the server to parse those values into actual session entries. The result is unauthenticated root access to the cPanel/WHM management interface.
Rather than operating a traditional Tor leak site, the Sorry group directs victims to Tox-based chat for ransom negotiations. In an unusual twist, ransom notes also suggest contacting “data recovery companies on Taobao” — an Alibaba subsidiary — for assistance, hinting at possible ties to Chinese-speaking threat actors.
Source
ThreatLocker — Sorry Ransomware Exploits cPanel Authentication Bypass
Commentary
The 48-hour turnaround from disclosure to active exploitation is the real headline here. Patch windows are effectively collapsing — defenders who operate on “patch Tuesday, deploy next month” cadences are increasingly finding themselves compromised before they even assess the vuln. cPanel is ubiquitous in shared hosting environments, making this a target-rich scenario.
The Taobao reference in the ransom note is an interesting operational security slip. Whether it indicates geographic origin or is deliberate misdirection, it gives threat intelligence teams something to chew on. If you run cPanel/WHM and haven’t updated past the May 1 patch, you’re already overdue.
