Home ยท Wiki ยท Incidents & Campaigns
type: incident ยท created: 2026-08-30 ยท updated: 2026-08-30 ยท tags: [incident, cpanel, whm, shared-hosting, rce, privilege-escalation, critical] ยท confidence: high ยท severity: critical ยท affected_sectors: [Global (Macro)] ยท au_impact: false

Critical cPanel Flaw Could Let One Hosting Customer Take Root Control of a Whole Server

cPanel released patches for CVE-2026-65643, a critical vulnerability in domain-parking and addon-domain functionality affecting all supported versions of cPanel and WebHost Manager. An authenticated account holder who can add parked or addon domains can create arbitrary files on the server, leading to code execution as the root user and full server compromise; cPanel described successful exploitation as giving an attacker full control of the server.

Patched builds are 11.110.0.141, 11.134.0.53, 11.136.0.37, 11.138.0.2 and 11.138.1.7 or later. It is the second critical cPanel/WHM issue of the year after the authentication-bypass flaw CVE-2026-41940 that the ACSC flagged for active exploitation in Australia in May โ€” a particularly significant combination for the shared-hosting market, where most exposure sits.

Source