Critical cPanel Flaw Could Allow Hosting Customer to Gain Root Control of Entire Server
CVE-2026-65643 Affects Domain Parking and Addon Domain Functionality in cPanel & WHM

Key Takeaways
- cPanel has patched a critical vulnerability (CVE-2026-65643) in cPanel & WHM affecting domain parking and addon domain functionality.
- The flaw could allow a hosting customer to execute code as the root user, potentially giving them control over the entire server and all hosted accounts.
- The vulnerability impacts all supported versions of cPanel & WHM.
Related Security News
CISA Adds Two Citrix NetScaler Vulnerabilities to Known Exploited Catalog
The Cybersecurity and Infrastructure Security Agency (CISA) has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog based on evidence of active exploitation. CVE-2026-88771 involves improper input validation and CVE-2026-88772 involves improper restriction of operations within the bounds of a memory buffer, both affecting Citrix NetScaler products. The additions trigger remediation requirements under Binding Operational Directive 26-04 for Federal Civilian Executive Branch agencies.


