Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

Critical cPanel Flaw Exposes Vulnerability to Code Execution as Root User, Threatens Server Control




A critical security flaw in cPanel has been discovered, allowing a malicious user to gain root control of a whole server. The vulnerability, CVE-2026-65643, impacts all supported versions of cPanel & WHM and could lead to code execution as the root user. Administrators are advised to apply the patch immediately to prevent potential exploitation. Stay up-to-date with the latest security news and expert analysis on The Hacker News.

  • The tech world has been alerted to a critical security flaw in cPanel, a popular web hosting control panel, identified as CVE-2026-65643.
  • The vulnerability affects domain parking and addon domain functionality, allowing a malicious user to create arbitrary files on the server and gain root control.
  • The vulnerability was discovered by The Hacker News and can be exploited by an authenticated account holder with the ability to add parked or addon domains.
  • cPanel has released patched versions of its software, including versions 11.110.0.141 or later, to mitigate the issue.
  • The vulnerability does not affect default installations of cPanel and only applies to servers with the affected Passenger package installed.
  • It is essential for web hosting customers to patch their servers and prevent potential exploitation, especially for servers running an end-of-life version.
  • CPanel has a history of disclosing security flaws, including CVE-2026-48172 and CVE-2026-54420, and recommends ongoing security monitoring and patching.



  • The tech world has been abuzz with the news of a critical security flaw in cPanel, a popular web hosting control panel. The vulnerability, assigned the CVE identifier CVE-2026-65643, has been reported to impact all supported versions of cPanel & WHM. According to cPanel, the issue affects domain parking and addon domain functionality, which could allow a malicious user to create arbitrary files on the server, effectively gaining root control.

    This critical security vulnerability was discovered by The Hacker News, a trusted cybersecurity news platform with over 5.70 million followers. The platform's expert analysis reveals that an authenticated account holder with the ability to add parked or addon domains can exploit this vulnerability, leading to code execution as the root user. This means that an attacker could potentially gain full control over the server, compromising the security and integrity of the entire system.

    The severity of this vulnerability was first disclosed in a notification by cPanel on August 27, 2026. The company described the issue as a critical security vulnerability, stating that successful exploitation leads to code execution as the root user, giving an attacker full control of the server. In its notification, cPanel also released patched versions of its software, including versions 11.110.0.141 or later, 11.134.0.53 or later, 11.136.0.37 or later, 11.138.0.2 or later, and 11.138.1.7 or later (WP Squared).

    It is worth noting that the vulnerability does not affect default installations of cPanel and only applies to servers where an affected Passenger package has been installed. Additionally, cPanel has not said whether the flaw has been exploited, and it is absent from the U.S. Cybersecurity and Infrastructure Security Agency's (CISA) Known Exploited Vulnerabilities (KEV) catalog.

    cPanel has previously disclosed other security flaws in its software, including CVE-2026-48172 and CVE-2026-54420, which are also listed in the CISA KEV catalog. These vulnerabilities are related to the LiteSpeed cPanel plugin and involve privilege escalation and symlink-following issues, respectively.

    In light of this critical security vulnerability, it is essential for web hosting customers to take immediate action to patch their servers and prevent potential exploitation. Administrators can apply the patch by logging in to the server as root and running scripts/upcp --force. The update can also be installed from WHM under Home > cPanel > Upgrade to Latest Version, and the installed build can then be verified under Server Configuration > Update Preferences.

    Servers running an end-of-life version have to upgrade to a supported version to receive the fix. It is also recommended that customers monitor their servers for signs of exploitation and take steps to mitigate potential damage.

    In conclusion, the critical security flaw in cPanel highlights the importance of ongoing security monitoring and patching. It is crucial for web hosting customers to stay vigilant and take proactive measures to protect their servers from potential exploitation.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/Critical-cPanel-Flaw-Exposes-Vulnerability-to-Code-Execution-as-Root-User-Threatens-Server-Control-ehn.shtml

  • https://thehackernews.com/2026/08/critical-cpanel-flaw-could-let-one.html

  • https://nvd.nist.gov/vuln/detail/CVE-2026-65643

  • https://www.cvedetails.com/cve/CVE-2026-65643/

  • https://nvd.nist.gov/vuln/detail/CVE-2026-48172

  • https://www.cvedetails.com/cve/CVE-2026-48172/

  • https://nvd.nist.gov/vuln/detail/CVE-2026-54420

  • https://www.cvedetails.com/cve/CVE-2026-54420/


  • Published: Sat Aug 29 18:48:33 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us