CVE Tools
Back to feed
Patch released cPanel web-app WebHost Manager (WHM) privilege-escalation

Critical cPanel Flaw Could Let One Hosting Customer Take Root Control of a Whole Server

The Hacker News·By The Hacker News··3 min read
CVE Tools coverage

cPanel has issued a critical security patch for CVE-2026-65643, a vulnerability in its domain parking and addon domain modules that permits an authenticated user to gain root-level code execution. This flaw affects all supported versions of cPanel & WebHost Manager (WHM) and could result in full server compromise if exploited. Administrators should immediately update their systems to one of the latest fixed builds, including 11.110.0.141, 11.134.0.53, 11.136.0.37, or 11.138.x series, as no interim mitigations are currently available.