Critical cPanel Flaw Could Let One Hosting Customer Take Root Control of a Whole Server
Overview
cPanel has issued critical patches for a serious vulnerability identified as CVE-2026-65643, which affects the domain parking and addon domain features in cPanel and WebHost Manager (WHM). This flaw could allow a malicious hosting customer to execute code with root privileges, potentially compromising the entire server. All supported versions of cPanel & WHM are impacted, making it a widespread issue for users of this software. Given the potential for significant damage, including unauthorized access and control over server resources, it is crucial for affected users to apply the patches as soon as possible. Failure to address this vulnerability could lead to severe security breaches within hosting environments.
Key Takeaways
- Affected Systems: cPanel & WHM (all supported versions)
- Action Required: cPanel has released patches to address the vulnerability.
- Timeline: Newly disclosed
Original Article Summary
cPanel has released patches for a security flaw affecting domain parking and addon domain functionality in cPanel and WebHost Manager (WHM), which could allow code execution as the root user. The vulnerability, assigned the CVE identifier CVE-2026-65643, impacts all supported versions of cPanel & WHM. cPanel described the issue as a critical security vulnerability and said that an
Impact
cPanel & WHM (all supported versions)
Exploitation Status
No active exploitation has been reported at this time. However, organizations should still apply patches promptly as proof-of-concept code may exist.
Timeline
Newly disclosed
Remediation
cPanel has released patches to address the vulnerability. Users should update to the latest version of cPanel & WHM as soon as possible to mitigate the risk.
Additional Information
This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.
Related Topics: This incident relates to CVE, Vulnerability, Critical.