importantSYS.SOURCE: The Hacker News• 2026-08-28T15:15:15+05:30
Critical cPanel Vulnerability CVE-2026-65643 Allows Root Code Execution via Domain Configuration
A critical vulnerability in cPanel and WHM enables arbitrary code execution as root through domain configuration, posing a severe risk to shared hosting environments. Patches are available, but no evidence of exploitation has been reported yet.
cPanel has released patches for a security flaw affecting domain parking and addon domain functionality in cPanel and WebHost Manager (WHM), which could allow code execution as the root user.
The vulnerability, assigned the CVE identifier CVE-2026-65643, impacts all supported versions of cPanel & WHM.
cPanel described the issue as a critical security vulnerability and said that an
*** END OF TRANSMISSION ***