CPanel & WHM parked/addon domain root code execution flaw (CVE-2026-65643)
Vulnerability
Summary
Hide ▲
Show ▼
cPanel has patched CVE-2026-65643 in cPanel & WHM, a flaw in parked and addon domain handling that could let an authenticated user reach root code execution on all supported versions. The fix is available in updated builds for the supported branches, including 11.110.0.141, 11.134.0.53, 11.136.0.37, 11.138.0.2, and 11.138.1.7 (WP Squared). Administrators can install the patch now, and unsupported releases must be upgraded to receive it.
Related Happenings
CPanel and WHM authentication bypass (CVE-2026-41940)
Vulnerability
H score89
First: 29.04.2026 12:37
Last: 29.04.2026 12:37
Sources 1
About this happening:
cPanel and WHM are affected by CVE-2026-41940, an authentication bypass in the login flow that can let unauthenticated remote attackers gain control-panel access....
CPanel and WHM authentication bypass (CVE-2026-41940)
VulnerabilityAbout this happening: cPanel and WHM are affected by CVE-2026-41940, an authentication bypass in the login flow that can let unauthenticated remote attackers gain control-panel access....
Timeline
-
28.08.2026 12:45 2 articles · 2h ago
cPanel patches CVE-2026-65643 in cPanel & WHM
Mitigation Patch UpdatecPanel released patched builds for CVE-2026-65643 in cPanel & WHM after identifying a flaw in parked and addon domain handling that could let an authenticated account holder create arbitrary files and reach root code execution. Fixed versions include 11.110.0.141, 11.134.0.53, 11.136.0.37, 11.138.0.2, and 11.138.1.7 for WP Squared; servers on automatic daily updates receive the patch automatically, and administrators can install it immediately with /scripts/upcp --force or through WHM.
Show sources
- Critical cPanel Flaw Could Let One Hosting Customer Take Root Control of a Whole Server — thehackernews.com — 28.08.2026 12:45
- Critical cPanel Flaw Could Let One Hosting Customer Take Root Control of a Whole Server — thehackernews.com — 28.08.2026 12:45