Apply the latest cPanel & WHM updates immediately. cPanel has released patches for all supported versions. Review system logs for any unauthorized activity following update deployment.
Quick answers
What is CVE-2026-65643?
Apply the latest cPanel & WHM updates immediately. cPanel has released patches for all supported versions. Review system logs for any unauthorized activity following update deployment.
How severe is CVE-2026-65643?
critical
Is CVE-2026-65643 known to be exploited?
It is not marked known-exploited in this record.
How should CVE-2026-65643 be mitigated?
Apply the latest cPanel & WHM updates immediately. cPanel has released patches for all supported versions. Review system logs for any unauthorized activity following update deployment.
CVSS
—
Vendor
cPanel
Published
Sep 30, 2026 · 08:42
Patch
Unknown / not confirmed
Affected products
cPanel, WebHost Manager (WHM)
Mitigation
Apply the latest cPanel & WHM updates immediately. cPanel has released patches for all supported versions. Review system logs for any unauthorized activity following update deployment.
cPanel has released patches for a critical security vulnerability in cPanel and WebHost Manager (WHM) affecting domain parking and addon domain functionality. The flaw, tracked as CVE-2026-65643, could allow an attacker with access to a hosting customer account to execute code as the root user, potentially gaining full control of the entire server and all hosted data. Patches are available for all supported versions.