# Urgent Update Needed: cPanel Vulnerability Threatens Server Security

*Published August 31, 2026*
*Source: [https://cybersecuritynews.com/critical-cpanel-vulnerability/](https://cybersecuritynews.com/critical-cpanel-vulnerability/)*

## Executive Summary

A critical vulnerability in cPanel and WHM allows low-privileged users to gain root control of servers by exploiting the domain parking functionality. The flaw affects all supported versions, and prompt patching is crucial to prevent server compromises that could lead to broad data breaches and system takeovers.

## Article

A recently disclosed vulnerability in cPanel and WHM, widely used web hosting control panel software, poses a serious security risk by allowing low-privileged authenticated users to gain root-level control of servers. Identified as CVE-2026-65643, this flaw affects the domain parking functionality within cPanel. Detailed in an advisory by cPanel support engineer Devon Courtney, the vulnerability was made public on August 27, 2026. This issue is particularly concerning because any authenticated cPanel user with permissions to manage parked or addon domains can exploit this flaw to create arbitrary files on the server.

Domain parking lets users point additional domain names to an existing website without needing separate accounts, a feature commonly enabled in shared and reseller hosting environments using cPanel. The flaw allows attackers to execute code as the root user, effectively gaining full control of the server. This means that all websites, databases, and emails hosted on compromised servers become vulnerable. For hosting providers with multi-tenant infrastructure, the risk is even greater. A single malicious user could utilize this flaw to deface websites, steal data, deploy malware, or use the server as a base for further attacks.

cPanel has confirmed that this vulnerability affects all currently supported versions of their software. Patched builds have been released, including versions 11.110.0.141 or later, 11.134.0.53 or later, 11.136.0.37 or later, and 11.138.0.2 or later, as well as WP2 build 11.138.1.7 or later. Administrators using older, unsupported versions remain vulnerable unless they upgrade to these patched versions.

Given the ease of exploitation, hosting providers and system administrators must prioritize this patch. While cPanel typically provides automatic updates, manual update policies should be reviewed to ensure that systems are safeguarded promptly. Additionally, administrators should reassess which accounts can manage parked or addon domains and consider restricting these privileges until patches are fully deployed. With cPanel being a dominant force in hosting, rapid response is essential to prevent potential exploitation.
