Critical

Critical cPanel Flaw Could Let One Hosting Customer Take Root Control of a Whole Server

The Hacker News

Overview

cPanel has issued critical patches for a serious vulnerability identified as CVE-2026-65643, which affects the domain parking and addon domain features in cPanel and WebHost Manager (WHM). This flaw could allow a malicious hosting customer to execute code with root privileges, potentially compromising the entire server. All supported versions of cPanel & WHM are impacted, making it a widespread issue for users of this software. Given the potential for significant damage, including unauthorized access and control over server resources, it is crucial for affected users to apply the patches as soon as possible. Failure to address this vulnerability could lead to severe security breaches within hosting environments.

Key Takeaways

  • Affected Systems: cPanel & WHM (all supported versions)
  • Action Required: cPanel has released patches to address the vulnerability.
  • Timeline: Newly disclosed

Original Article Summary

cPanel has released patches for a security flaw affecting domain parking and addon domain functionality in cPanel and WebHost Manager (WHM), which could allow code execution as the root user. The vulnerability, assigned the CVE identifier CVE-2026-65643, impacts all supported versions of cPanel & WHM. cPanel described the issue as a critical security vulnerability and said that an

Impact

cPanel & WHM (all supported versions)

Exploitation Status

No active exploitation has been reported at this time. However, organizations should still apply patches promptly as proof-of-concept code may exist.

Timeline

Newly disclosed

Remediation

cPanel has released patches to address the vulnerability. Users should update to the latest version of cPanel & WHM as soon as possible to mitigate the risk.

Additional Information

This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.

Related Topics: This incident relates to CVE, Vulnerability, Critical.

Related Coverage

Berlin Refuses to Pay Hackers Who Stole Data From the City's State Network

The Hacker News

Berlin's state government has confirmed that it is facing an extortion attempt after hackers compromised the city's administrative network in August. The attackers have demanded a ransom, but officials have stated they will not pay. Forensic investigations have revealed additional data leaks, particularly affecting the Senate Department for Mobility, Transport, Climate Protection and Environment. This incident raises concerns about the security of public sector data and the potential risks of similar attacks on other cities and government entities. The refusal to pay may embolden attackers, while also highlighting the ongoing challenges of cybersecurity in public administration.

Aug 28, 2026

PaperCut releases second emergency patch for exploited flaws

BleepingComputer

PaperCut has issued a second emergency patch for its NG and MF print management software due to two vulnerabilities that are currently being exploited. Researchers found that there were ways to bypass the initial fixes provided in the first patch, which prompted the urgent release of this new update. Organizations using PaperCut's software should prioritize applying this patch to protect against potential attacks, as the vulnerabilities can lead to unauthorized access and exploitation. It’s critical for users to stay informed and ensure their systems are updated to mitigate these risks.

Aug 28, 2026

Attackers Chain Two PaperCut Flaws to Execute Code Without Authentication

The Hacker News

Attackers are taking advantage of a recently patched vulnerability in PaperCut NG and MF software, allowing them to execute arbitrary code without needing authentication. This flaw gives unauthorized users remote access to the application's trusted configuration, which can be exploited to run Java code within the system. PaperCut has responded by releasing an emergency fix to address this issue and enhance security measures. Organizations using these PaperCut products should act quickly to apply the latest updates to safeguard their systems from potential exploitation. Failure to patch could leave systems vulnerable to significant security breaches.

Aug 28, 2026

ownCloud Flaw Exploited to Steal Nuclear Records From Philippine Research Body

The Hacker News

A serious vulnerability in ownCloud, identified as CVE-2023-49105, has been exploited by a Chinese-speaking threat actor to steal sensitive nuclear records from a research organization in the Philippines. This flaw has a high severity rating of 9.8, which indicates a significant risk to systems using this software. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added this vulnerability to its Known Exploited Vulnerabilities catalog, alerting organizations to the potential dangers. The incident raises concerns about the security of critical infrastructure and highlights the importance of patching known vulnerabilities promptly. Organizations using ownCloud should take immediate action to secure their systems against this exploit.

Aug 28, 2026

19 Chrome and Edge Extensions Found With Wallet-Stealing and Crypto-Draining Code

The Hacker News

Researchers have identified 19 browser extensions—18 for Google Chrome and one for Microsoft Edge—that contain malicious code designed to steal cryptocurrency wallet secrets and drain funds. These extensions were published in the last six months and share similar coding techniques, suggesting they may be part of a coordinated attack. Users of these browsers who have downloaded these extensions are at risk of losing their cryptocurrency assets. This discovery highlights the need for users to scrutinize extensions before installation and for browser vendors to enhance their review processes to prevent such malicious software from being available in their stores.

Aug 28, 2026

Two Unitree G1 EDU Humanoid Robot Flaws Enable Root RCE, One Starts Over Bluetooth

The Hacker News

Security researcher Olivier Laflamme has reported two serious vulnerabilities in the Unitree G1 EDU humanoid robot that allow for root remote code execution (RCE). The vulnerabilities, identified as CVE-2026-76639 and CVE-2026-76640, can be exploited through different paths, including a Bluetooth Low Energy (BLE) method that can give attackers root access to the robot’s Locomotion PC. The first vulnerability involves a network-adjacent route via components called chat_go and bashrunner. This is a significant concern for users of the Unitree G1 EDU, as it opens the door for unauthorized control of the robot, potentially leading to malicious activities. Addressing these flaws is crucial for ensuring the security and reliability of robotic systems, especially in educational and research environments where they are increasingly being used.

Aug 28, 2026