Thehackernews
Critical cPanel Vulnerability Allows Full Server Control
Article Content
A critical vulnerability in cPanel and WHM, tracked as CVE-2026-65643, was disclosed on August 27, 2026. This flaw allows low-privileged, authenticated users to gain root-level control of the server through the domain parking functionality. Affected systems include all servers running cPanel and WHM that utilize this feature. The vulnerability poses a significant risk as it could lead to unauthorized access and control over the entire server environment. Security teams are urged to assess their systems and apply necessary patches as soon as they are available. The current status indicates that the vulnerability has been publicly disclosed, but there are no reports of active exploitation at this time.
Key Points: • CVE-2026-65643 allows root access via cPanel's domain parking feature. • All cPanel and WHM installations are potentially affected. • Immediate action is recommended to mitigate risks from this vulnerability.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.