
Erkennungssignaturen für CVE-2026-41940 und Schemas für cPanel-Logs
Erkennungsregeln und Log-Schemas für die cPanel/WHM-Authentifizierungsumgehung (CVE-2026-41940), von Unfold Security.
Blogbeitrag: cPanel-Exploit — CVE-2026-41940
├── cpanel_cve_2026_41940_mal_get.yml # SIGMA-Regel — erkennt die CRLF-Injection-Anfrage
├── cpanel_session_mal_authorization.yml # SIGMA-Regeln — erkennt Sitzungsnutzung ohne vorherigen Login
├── Schemas/
│ ├── Microsoft Sentinel/ # ARM-Vorlagen für DCR-basierte Log-Erfassung in Sentinel
│ └── Splunk/ # props.conf-Strophen für cPanel-Log-Sourcetypes
├── Sentinel_Detections/ # Microsoft Sentinel-Analyseregeln (KQL-Abfragen)
└── Splunk_Detections/ # Splunk Enterprise Security-Korrelationssuchen