Government of Guam

Exploitation of CVE-2026-41940 compromised Government of Guam web infrastructure and disrupted access to agency websites, downloads and public documents beginning in May 2026. The Bureau of Statistics and Plans later removed its restoration warning and repopulated report and data pages; the incident is presumed resolved because no territorial government all-clear establishes the exact recovery date.
The organization publicly identifies the event as cyber-related. The organization publicly documents the resulting service disruption.
Exploitation of a software or hardware vulnerability to gain unauthorized access or execute malicious actions.
Unauthorized access to systems, accounts, networks, or data.
Authorized users could not access required data because of the incident, even when the data was not encrypted, deleted, or destroyed.
A public-facing website was unavailable, disabled, or inaccessible.
A public, customer, employee, student, patient, vendor, or partner portal was unavailable or materially impaired.
Staff, customers, patients, students, residents, or other users could not access records or case information normally.
Public administrative, licensing, permitting, court, tax, records, benefits, or other government services were materially affected.
The organization redirected users to a different website, office, telephone number, email address, provider, or service channel.
Customers, residents, patients, students, vendors, or members of the public faced access restrictions or could not use services normally.
Available evidence indicates that no extortion demand, threat, communication, or related pressure tactic was identified.
DysruptionHub assesses with high confidence that exploitation of the critical cPanel authentication-bypass flaw CVE-2026-41940 compromised internet-facing web-hosting infrastructure used by Government of Guam agencies. The Guam Homeland Security and Office of Civil Defense announcement said the territorial government activated its cyber response May 2, 2026, after identifying a widespread incident affecting cPanel-hosted websites.
The vendor’s security update said a specially crafted request could cause an unauthenticated session to be treated as authenticated. The public record supports vulnerability exploitation and unauthorized access, but it does not identify the attacker or establish access beyond affected website infrastructure.
The incident disrupted public access to government websites, downloads and online administrative material. The Bureau of Statistics and Plans directed residents to Google Drive, email and in-person alternatives for planning documents and public comments, creating workarounds for residents and staff while essential and emergency operations remained available.
BSP later reported that downloads and embedded content were temporarily unavailable while it restored the site and re-uploaded files, data sets, reports and media. The established data effect is unavailability; the reviewed sources do not show whether information was copied, exposed or altered.
The Government of Guam directly acknowledged the incident, linked its response to exploitation of a critical cPanel vulnerability and documented practical service effects. The government has not published a complete affected-agency list, final technical report or government-wide restoration notice.
The incident is presumed resolved. August 10 was the date BSP’s undated restoration notice was observed, not the date of a new disruption or agency announcement. The notice still described unavailable content and ongoing re-upload work at that time, making August 10 the latest supported observation of operational impact.
By August 16, the warning no longer appeared on BSP’s home, about, reports or links pages. The reports catalog was populated with statistical, planning, census and coastal-management materials, and the home page linked recent reports and public notices. Those conditions are strong evidence of recovery, but they do not establish when every affected Government of Guam website was restored.
Confidence is high in both malicious exploitation and operational disruption because the territorial government linked the response to the cPanel vulnerability and agencies documented unavailable websites and public materials. Confidence is medium that operational impact has ended because BSP’s restoration warning was removed and public materials are again available, but no government-wide all-clear provides a definitive closure date.
Ransomware, data theft and attribution remain unresolved. No reviewed Guam source confirms encryption, a ransom demand, payment, leak activity or a responsible actor. The government’s initial reference to worst-case scenarios under review did not confirm that those effects occurred.
The public record does not establish the complete affected-agency list, hosting architecture, initial exploitation time, attacker identity, persistence, affected accounts, database access, email impact or credential compromise. It also does not quantify unrecoverable material or provide a final government-wide restoration date.


DysruptionHub reported that Government of Guam websites were disrupted during a widespread cyber incident involving cPanel-hosted systems. Officials activated a territorial cyber response while agencies worked to restore public-facing websites and online resources.
The Government of Guam activated its cyber incident response after identifying a widespread incident linked to a critical vulnerability affecting cPanel-hosted websites. Officials said response teams were investigating and securing affected government systems while essential and emergency operations remained available.
The Bureau of Statistics and Plans said its website was experiencing service disruption because of the widespread cPanel cyber incident. It directed residents to Google Drive, email, and in-person alternatives so public-comment access and submissions could continue.
cPanel identified CVE-2026-41940 as a critical authentication vulnerability in the cPanel & WHM session-management layer. A specially crafted request could cause an unauthenticated session to be treated as authenticated and grant access without valid credentials. Updates were released April 28, and CISA added the flaw to its Known Exploited Vulnerabilities catalog May 1.
BSP’s undated restoration warning was observed August 10, when it still described unavailable downloads and ongoing re-upload work. Direct retrieval August 16 found the warning removed from BSP’s home, about, reports and links pages, while recent reports and public notices were available.
BSP’s reports page was populated August 16 with links to statistical, planning, census, GIS and coastal-management publications. The prior website-restoration warning was no longer present on the reports page.
Signed-in members can report an error, update, or missing source.