Find notable cyber news and cases, enriched with sources, timelines, and signals.

CPanel & WHM parked/addon domain root code execution flaw (CVE-2026-65643)

Vulnerability
First reported
Last updated
Happening score
H score 9
1 unique sources, 1 articles

Summary

Hide ▲

cPanel has patched CVE-2026-65643 in cPanel & WHM, a flaw in parked and addon domain handling that could let an authenticated user reach root code execution on all supported versions. The fix is available in updated builds for the supported branches, including 11.110.0.141, 11.134.0.53, 11.136.0.37, 11.138.0.2, and 11.138.1.7 (WP Squared). Administrators can install the patch now, and unsupported releases must be upgraded to receive it.

Related Happenings

CPanel and WHM authentication bypass (CVE-2026-41940)

Vulnerability
H score89 First: 29.04.2026 12:37 Last: 29.04.2026 12:37 Sources 1

About this happening: cPanel and WHM are affected by CVE-2026-41940, an authentication bypass in the login flow that can let unauthenticated remote attackers gain control-panel access....

Timeline

  1. 28.08.2026 12:45 2 articles · 2h ago

    cPanel patches CVE-2026-65643 in cPanel & WHM

    Mitigation Patch Update

    cPanel released patched builds for CVE-2026-65643 in cPanel & WHM after identifying a flaw in parked and addon domain handling that could let an authenticated account holder create arbitrary files and reach root code execution. Fixed versions include 11.110.0.141, 11.134.0.53, 11.136.0.37, 11.138.0.2, and 11.138.1.7 for WP Squared; servers on automatic daily updates receive the patch automatically, and administrators can install it immediately with /scripts/upcp --force or through WHM.

    Show sources