
cPanel CVE-2026-41940 nuclear.x86 Security Audit & Cleanup Script
Complete Security Toolkit for cPanel servers infected with CVE-2026-41940 / nuclear.x86. Two scripts — one full audit and one auto cleanup with Imunify360. Works on both original license and bypass/shared license servers.
| Name | MD Mahfuz Reham |
| Role | System Admin | Web Hosting Specialist |
| Website | MahfuzReham.Com |
| +8801790614055 | |
| GitHub | github.com/mahfuzreham |
| Detail | Info |
|---|---|
| CVE ID | CVE-2026-41940 |
| CVSS Score | 9.8 — Critical |
| Affected | All supported cPanel & WHM versions |
| Exploit | Actively exploited before public disclosure |
| Malware | nuclear.x86 Linux botnet |
| Attacker IPs | 87.121.84.78 · 45.148.120.23 |
wget google.com
# "Killed" দেখালে → nuclear.x86 এখনো চলছে
# স্বাভাবিক download হলে → malware নেই বা আগেই মরেছে
| Script | Function | When to use |
|---|---|---|
cpanel_security_check.sh | Full server audit, malware kill, SSH key rotation | Run this first |
imunify360_scan_clean.sh | Scan all accounts and cleanup webshells with Imunify360 | Then run this |
cd /root && \
wget -O cpanel_security_check.sh \
https://raw.githubusercontent.com/mahfuzreham/cpanel-cve-2026-41940/main/cpanel_security_check.sh && \
wget -O imunify360_scan_clean.sh \
https://raw.githubusercontent.com/mahfuzreham/cpanel-cve-2026-41940/main/imunify360_scan_clean.sh && \
bash cpanel_security_check.sh && \
bash imunify360_scan_clean.sh
⚠️ Make sure to run as root
bash <(curl -s https://raw.githubusercontent.com/mahfuzreham/cpanel-cve-2026-41940/main/cpanel_security_check.sh)
| Check | Description |
|---|---|
| 🦠 Malware process | Detect and kill active nuclear.x86 process |
| 🌐 wget/curl test | Confirms if malware is active |
| 🔌 Attacker IPs | Checks if there is a connection to C2 IPs |
| 📜 History scan | Searches shell history for attack signatures |
| 📦 cPanel version | Check last update and patch status |
| 🔓 Port exposure | Check if 2083, 2087, 2095, 2096 are open |
| 🗝️ SSH keys | Audit private key age and authorized_keys |
| ⏰ Cron jobs | Scan for suspicious cron entries |
| 🐚 Webshells | Scan public_html for PHP shells |
| 🔐 SUID binaries | Detect unexpected SUID files |
/scripts/upcp --force)bash <(curl -s https://raw.githubusercontent.com/mahfuzreham/cpanel-cve-2026-41940/main/imunify360_scan_clean.sh)
| Step | Action |
|---|---|
| 1 | Check Imunify360 status and service |
| 2 | Update malware signature database |
| 3 | Full scan of all cPanel accounts |
| 4 | Scan for CVE-2026-41940 webshell patterns |
| 5 | Auto cleanup + quarantine |
| 6 | Delete suspicious files (with backup) |
| 7 | Enable real-time protection |
| 8 | Setup daily auto-scan cron |
| 9 | Full summary report |
wp-cache-*.php wp-check-*.php wp-sync-*.php
wp-util-*.php admin-init-*.php upgrade-*.php
class-wp-*.php task_*.php .*\.php (hidden)
eval(base64_decode system($_ passthru($_
assert($_ exec($_ shell_exec($_
| cpanel_security_check.sh | imunify360_scan_clean.sh | |
|---|---|---|
| OS | CentOS / AlmaLinux / CloudLinux / Ubuntu | CentOS / AlmaLinux / CloudLinux / Ubuntu |
| Panel | cPanel & WHM | cPanel & WHM |
| Access | Root SSH | Root SSH |
| Software | — | Imunify360 (licensed) |
wget https://repo.imunify360.cloudlinux.com/defence360/imunify-deploy.sh
bash imunify-deploy.sh --key YOUR_LICENSE_KEY
/root/cpanel_security_audit_TIMESTAMP.log ← Script 1 log
/root/imunify360_cleanup_TIMESTAMP.log ← Script 2 log
/root/imunify360_report_TIMESTAMP.txt ← Infected files list
/root/webshell_backup/ ← Deleted files backup
pkill -9 -f "nuclear.x86"
ps auxf | grep nuclear
iptables -I INPUT -p tcp --dport 2083 -j DROP
iptables -I INPUT -p tcp --dport 2087 -j DROP
iptables -I INPUT -p tcp --dport 2095 -j DROP
iptables -I INPUT -p tcp --dport 2096 -j DROP
/scripts/upcp --force
whmapi1 configureservice service=cpsrvd enabled=0 monitored=0 && \
whmapi1 configureservice service=cpdavd enabled=0 monitored=0 && \
/scripts/restartsrv_cpsrvd --stop && \
/scripts/restartsrv_cpdavd --stop
☐ Run cpanel_security_check.sh
☐ Run imunify360_scan_clean.sh
☐ Reset passwords for all cPanel accounts
☐ Reset all FTP / email / MySQL passwords
☐ Update wp-config.php / .env files
☐ Check for unknown email forwards
☐ Check for unknown cron jobs
☐ Check for unknown FTP accounts
☐ Revoke old SSH keys from GitHub / GitLab
☐ Check for unknown WordPress admin users
☐ Update all WordPress plugins and themes
| OS | Status |
|---|---|
| AlmaLinux 8/9 | ✅ |
| CloudLinux 7/8 | ✅ |
| CentOS 7 | ✅ |
| Rocky Linux 8/9 | ✅ |
| Ubuntu 20/22 (cPanel) | ✅ |
MIT License — Free to use, share, and modify. Please keep author attribution intact when sharing.
⚠️ Share this toolkit with everyone — anyone with a cPanel server can be infected by this vulnerability.
If this toolkit helped secure your server or saved you time, consider supporting future development and security research.
🔗 Donation Link: https://pay.shurjopayment.com/d21kNExwjP
Your support helps with:
Every contribution helps keep hosting servers safer. Thank you for supporting the project ❤️