Patch released cPanel web-app WebHost Manager (WHM) privilege-escalation
Critical cPanel Flaw Could Let One Hosting Customer Take Root Control of a Whole Server
CVE Tools coverage
cPanel has issued a critical security patch for CVE-2026-65643, a vulnerability in its domain parking and addon domain modules that permits an authenticated user to gain root-level code execution. This flaw affects all supported versions of cPanel & WebHost Manager (WHM) and could result in full server compromise if exploited. Administrators should immediately update their systems to one of the latest fixed builds, including 11.110.0.141, 11.134.0.53, 11.136.0.37, or 11.138.x series, as no interim mitigations are currently available.