🔴 Critical: Critical cPanel Flaw Could Let One Hosting Customer Take Root Control of a Whole Server
-
Patches are now available for a critical vulnerability in cPanel and WebHost Manager (WHM) that could allow a single hosting customer to execute code as the root user. The flaw resides in the domain parking and addon domain functionality, potentially enabling a full server takeover.
Tracked as CVE-2026-65643, this issue affects all supported versions of cPanel & WHM. The vendor has classified the severity as critical, urging administrators to apply the necessary updates immediately. Given that this requires no prior authentication beyond a standard hosting account, the risk of exploitation is significant for shared hosting environments.
Key takeaways:
- Vulnerability in domain parking and addon domain functions leads to root-level code execution.
- Impacts all supported versions of cPanel & WHM.
- Patches are released; immediate updating is strongly advised.
While specific technical details of the exploit chain are not yet public, the potential impact is severe. If you manage a server running cPanel, prioritizing this update is essential to prevent unauthorized root access. Administrators should verify their current version and ensure it is patched without delay.
Source: The Hacker News
Are you running a supported version of cPanel, and how quickly do you plan to roll out these patches to mitigate the risk of exploitation?
Hello! It looks like you're interested in this conversation, but you don't have an account yet.
Getting fed up of having to scroll through the same posts each visit? When you register for an account, you'll always come back to exactly where you were before, and choose to be notified of new replies (either via email, or push notification). You'll also be able to save bookmarks and upvote posts to show your appreciation to other community members.
With your input, this post could be even better 💗
Register Login