cPanel has released security updates for a critical vulnerability affecting its domain parking and addon domain functionality in cPanel & WebHost Manager (WHM).

The flaw, tracked as CVE-2026-65643, could allow an authenticated account holder with permission to add parked or addon domains to create arbitrary files on a server and potentially execute code with root privileges.

cPanel described the vulnerability as critical and warned that successful exploitation could give an attacker full control over the affected server. The company said the issue affects all supported versions of cPanel & WHM.

The security fixes are included in cPanel & WHM version 11.110.0.141 or later, 11.134.0.53 or later, 11.136.0.37 or later, 11.138.0.2 or later, and 11.138.1.7 or later for WP Squared.

The August 27 security notification specifically lists WP Squared among the affected products but does not mention DNSOnly. cPanel had also patched three separate vulnerabilities in July, with those earlier advisories covering the 11.118 and 11.126 branches. The latest notification covers the 110, 134, 136 and 138 branches, but cPanel has not clarified whether the older 11.118 and 11.126 branches are still supported.

Administrators whose servers are configured for automatic daily updates should receive the patched build automatically. Those who want to install the update immediately can log in to the server as root and run /scripts/upcp --force. The update can also be installed through WHM by going to Home > cPanel > Upgrade to Latest Version. Administrators can check the installed build through Server Configuration > Update Preferences.

READ
Critical Avada WordPress Flaw Enables Zero-Click Remote Code Execution

Servers running an end-of-life cPanel version must first upgrade to a supported release before they can receive the security fix.

The advisory does not provide a CVSS score. As of August 28, 2026, the CVE Program’s record store also did not contain a published record for CVE-2026-65643, although records for two other cPanel vulnerabilities disclosed on July 31 were already available.

cPanel has not disclosed any known exploitation of CVE-2026-65643, and the vulnerability was not listed in CISA’s Known Exploited Vulnerabilities catalog as of the August 27 update. However, the catalog already includes two vulnerabilities affecting a cPanel plugin.

CISA added CVE-2026-48172, a privilege escalation vulnerability in the LiteSpeed cPanel plugin, to the catalog on May 26. The issue can allow any cPanel user account to execute arbitrary scripts with root privileges. Another LiteSpeed cPanel plugin vulnerability, CVE-2026-54420, was added on June 15. That flaw involves symlink following and affects certain shared hosting environments running CloudLinux or CageFS where users have FTP or web shell access.

CISA’s catalog also includes CVE-2026-41940, a cPanel authentication bypass vulnerability patched in April that has been associated with ransomware activity.


Buy ExpressVPN with PayPal or Credit Card

The latest cPanel notification does not provide an interim mitigation or a specific method for administrators to determine whether CVE-2026-65643 has already been exploited. This makes installing the patched version particularly important for administrators running affected servers.

Advertisement