Vulnerability in cPanel’s domain parking functionality - CVE-2026-65643
Surprised to see No mentions of this here.
Our server got hacked with this security lapse on 25th August 2026, and Cpanel notified me on mail about this on 27th August 2027.
|
A critical security vulnerability affecting cPanel & WHM has been identified. Patched versions are now available.
Vulnerability in cPanel’s domain parking functionality - CVE-2026-65643
Situation: An authenticated cPanel account holder who is able to add parked or addon domains can create arbitrary files on the server.
Impact: Successful exploitation leads to code execution as the root user, giving an attacker full control of the server.
Affected Versions:
Patched Versions:
Support Link: Security: CVE-2026-65643 Vulnerability in cPanel’s Domain Parking Functionality - August 27, 2026 – cPanel
Action Required > Update cPanel now
Servers configured for automatic daily updates will receive the patched build automatically. To apply it immediately, log in to the server as root and run /scripts/upcp --force. Alternatively:
If your server is running an end-of-life version, upgrade to a supported version to receive this fix. |
|
Our support team is available if you have any questions or need further guidance.
Best regards, Your cPanel Security Team |
-
Hey there! How were you able to confirm this was the specific issue that led to your compromise?
0
Please sign in to leave a comment.
Comments
1 comment