A critical cPanel vulnerability CVE-2026-41940 is being actively exploited by threat actor Mr_Rot13 to deploy Filemanager backdoor, enabling credential theft, ransomware, botnet activity, and persistent system compromise across global infrastructure.