cPanel and WHM patched a root RCE risk in domain parking
Source headline: Critical cPanel Flaw Could Let One Hosting Customer Take Root Control of a Whole Server
Intelligence Summary
cPanel has released patches for a critical flaw in cPanel and WebHost Manager (WHM). The issue affects domain parking and addon domain functionality. It is assigned CVE-2026-65643 and is described as allowing code execution as the root user. The vulnerability is reported to impact all supported versions of cPanel & WHM. Users running affected cPanel/WHM installations should apply the vendor patches immediately.
Recommended Action
Check whether your WebHost Manager (WHM) deployment is affected by CVE-2026-65643 and apply the vendor fix. Until then, watch authentication and outbound traffic logs for the indicators described in the source. This signal rests on a single report, so corroborate it before acting on anything irreversible.