cPanel has patched CVE-2026-65643, a critical flaw in cPanel & WebHost Manager (WHM) domain-parking and addon-domain functionality. A low-privileged authenticated hosting account authorized to add parked or addon domains can create arbitrary files on the underlying server, potentially leading to code execution as root and full control of the host.
The issue affects all supported cPanel & WHM release branches, with fixes issued for 11.110, 11.134, 11.136, and 11.138, including WP Squared. Shared and reseller-hosting operators should apply the relevant patched build immediately; systems on end-of-life branches must be upgraded to a supported release, and unpatched deployments should restrict parked- and addon-domain permissions. cPanel had not disclosed a CVSS score, detection guidance, interim mitigation, or confirmed in-the-wild exploitation.

Get the actors, campaigns, and ATT&CK mapping behind it.
5 events from the most recent confirmed update back to the earliest known activity.
The CVE-2026-65643 record was received by support@hackerone.com. The record characterizes the flaw as CWE-95 eval injection in cPanel 11.138.0.0 and earlier, allowing a low-privileged authenticated remote attacker to execute code as root, with a high-impact CVSS v4 vector.
The Canadian Centre for Cyber Security published advisory AV26-861 for CVE-2026-65643, advising cPanel and WHM administrators to review the vendor advisory and apply available updates. The advisory identified affected releases prior to the fixed versions across the 11.110, 11.134, 11.136, 11.138, and WP2 branches.
As of August 28, the CVE Program record store had no published record for CVE-2026-65643, and cPanel had not said whether the flaw was exploited in the wild. The vulnerability was also absent from CISA's Known Exploited Vulnerabilities catalog as of the prior day.
cPanel published a customer advisory for CVE-2026-65643, a critical domain-parking and addon-domain flaw affecting all supported cPanel & WHM versions. An authenticated account permitted to add parked or addon domains could create arbitrary server files and potentially execute code as root; cPanel released fixes for the 11.110, 11.134, 11.136, 11.138, and WP Squared branches.
Benin’s bjCSIRT published a notice concerning the cPanel & WHM domain-parking functionality vulnerability associated with CVE-2026-65643.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
9 references tracked. Mallory keeps watching after this page renders.
csirt.bj
Open sourcecvefeed.io
Open sourcemeetcyber.net
Open sourcemalware.news
Open sourcecyber.gc.ca
Open sourcecyber.gc.ca
Open sourceacn.gov.it
Open sourcethehackernews.com
Open sourcecybersecuritynews.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.