ShellCodeX
Tools • Events • News • Insights
LiveThreat
Radar
ShellCodeX Intelligence Brief
CRITICAL Vulnerabilities

cPanel and WHM patched a root RCE risk in domain parking

Source headline: Critical cPanel Flaw Could Let One Hosting Customer Take Root Control of a Whole Server

Threat level Critical
Signal strength 80/100
Source confidence 1 source
Published 2 days ago

Intelligence Summary

cPanel has released patches for a critical flaw in cPanel and WebHost Manager (WHM). The issue affects domain parking and addon domain functionality. It is assigned CVE-2026-65643 and is described as allowing code execution as the root user. The vulnerability is reported to impact all supported versions of cPanel & WHM. Users running affected cPanel/WHM installations should apply the vendor patches immediately.

Recommended Action

Check whether your WebHost Manager (WHM) deployment is affected by CVE-2026-65643 and apply the vendor fix. Until then, watch authentication and outbound traffic logs for the indicators described in the source. This signal rests on a single report, so corroborate it before acting on anything irreversible.

Topics

#cve #rce #root #cpanel #domain-parking #whm
Original reporting The Hacker News Critical cPanel Flaw Could Let One Hosting Customer Take Root Control of a Whole Server
Open original source