CVE Tools

Critical cPanel Flaw Could Let One Hosting Customer Take Root Control of a Whole Server

The Hacker NewsBy The Hacker News

PatchcPanelWebHost Manager (WHM)

Our summary

cPanel has issued a critical security patch for CVE-2026-65643, a vulnerability in its domain parking and addon domain modules that permits an authenticated user to gain root-level code execution. This flaw affects all supported versions of cPanel & WebHost Manager (WHM) and could result in full server compromise if exploited. Administrators should immediately update their systems to one of the latest fixed builds, including 11.110.0.141, 11.134.0.53, 11.136.0.37, or 11.138.x series, as no interim mitigations are currently available.

Read at The Hacker News

The Hacker News publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store