<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[🔴 Critical: Critical cPanel Flaw Could Let One Hosting Customer Take Root Control of a Whole Server]]></title><description><![CDATA[<p dir="auto">Patches are now available for a critical vulnerability in cPanel and WebHost Manager (WHM) that could allow a single hosting customer to execute code as the root user. The flaw resides in the domain parking and addon domain functionality, potentially enabling a full server takeover.</p>
<p dir="auto">Tracked as <strong><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-65643" target="_blank" rel="noopener noreferrer nofollow ugc">CVE-2026-65643</a></strong>, this issue affects <em>all supported versions</em> of cPanel &amp; WHM. The vendor has classified the severity as critical, urging administrators to apply the necessary updates immediately. Given that this requires no prior authentication beyond a standard hosting account, the risk of exploitation is significant for shared hosting environments.</p>
<p dir="auto"><strong>Key takeaways:</strong></p>
<ul>
<li>Vulnerability in domain parking and addon domain functions leads to root-level code execution.</li>
<li>Impacts all supported versions of cPanel &amp; WHM.</li>
<li>Patches are released; immediate updating is strongly advised.</li>
</ul>
<p dir="auto">While specific technical details of the exploit chain are not yet public, the potential impact is severe. If you manage a server running cPanel, prioritizing this update is essential to prevent unauthorized root access. Administrators should verify their current version and ensure it is patched without delay.</p>
<p dir="auto">Source: <a href="https://thehackernews.com/2026/08/critical-cpanel-flaw-could-let-one.html" target="_blank" rel="noopener noreferrer nofollow ugc">The Hacker News</a></p>
<p dir="auto">Are you running a supported version of cPanel, and how quickly do you plan to roll out these patches to mitigate the risk of exploitation?</p>
]]></description><link>https://xploitlk.com/topic/147/critical-critical-cpanel-flaw-could-let-one-hosting-customer-take-root-control-of-a-whole-server</link><generator>RSS for Node</generator><lastBuildDate>Sat, 05 Sep 2026 13:28:15 GMT</lastBuildDate><atom:link href="https://xploitlk.com/topic/147.rss" rel="self" type="application/rss+xml"/><pubDate>Sat, 29 Aug 2026 22:30:27 GMT</pubDate><ttl>60</ttl></channel></rss>