logo

Critical cPanel Flaw Could Let One Hosting Customer Take Root Control of a Whole Server

ID: bacf63e7-1c76-5404-a49d-2c9346489261

STIX ID: report--bacf63e7-1c76-5404-a49d-2c9346489261

Feed Name: The Hacker News

Threat Score
75/100

Date Published: 2026-08-28

Date Updated: 2026-08-28

Author: [email protected] (The Hacker News)

...
...

**cPanel critical vulnerability (CVE-2026-65643):** cPanel and WHM contain a flaw in domain parking/addon domain functionality that can allow an authenticated user who can add parked/addon domains to create arbitrary files and achieve code execution as root; patched builds for multiple branches were released and administrators are advised to update or enable automatic updates, though no published CVE record, CVSS score, or confirmed widespread exploitation was reported at the time.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.