Critical cPanel Vulnerability Exposes Servers to Full Root Takeover
A newly patched cPanel flaw allows attackers to escalate privileges and gain full control of hosting servers. All supported cPanel & WHM versions are affected by this critical vulnerability.
TL;DR
- CVE-2026-65643 affects all supported cPanel & WHM versions
- Exploitation could grant attackers root access to entire servers
- Vulnerability resides in domain parking and addon domain functionality
- cPanel has released urgent security patches
- Hosting providers should update immediately to prevent server-wide compromise
Web hosting platforms using cPanel and WebHost Manager (WHM) are facing a severe security threat following the discovery of a critical vulnerability that could allow malicious actors to escalate privileges and take complete control of servers. The flaw, identified as CVE-2026-65643, affects core domain management features and has prompted an urgent response from cPanel with released patches.
This vulnerability poses significant risk to hosting providers and their customers, as successful exploitation could enable a single compromised account to gain root-level access across the entire server infrastructure. The widespread impact makes this a high-priority issue requiring immediate attention from system administrators and security teams managing cPanel installations.
Vulnerability Details
- CVE-2026-65643 is a critical security flaw affecting cPanel and WebHost Manager domain functionality
- The vulnerability specifically impacts domain parking and addon domain features within the control panel
- Successful exploitation could allow unprivileged users to execute code as the root user
- All currently supported versions of cPanel & WHM are vulnerable until patched
- The issue was classified as critical by cPanel's security team due to potential for full server compromise
Security Recommendations
- Apply cPanel's released security patches immediately across all affected systems
- Audit server logs for any suspicious activity related to domain management functions
- Consider implementing additional monitoring on privileged account activities
- Review and restrict addon domain and parked domain configurations where possible
- Coordinate with hosting customers to ensure they understand the potential impact and remediation steps
Sources
Sources
Security email updates
One digest email when we publish new security articles (TL;DR plus links to read more). Unsubscribe anytime from the message footer. See our Privacy Policy.