Enterprise IT Support β€’ Bangkok & Nationwide

Technology newsroom

Urgent Alert! Critical cPanel & WHM Vulnerability Allows Single Customer to Seize Entire Server (CVE-2026-65643)

cPanel has identified a critical security vulnerability (CVE-2026-65643) in its Domain Parking and Addon Domain functions, which could allow a single hosting customer to escalate privileges to Root and take full control of a server. System administrators are advised to update patches immediately.

Edited by SyncTech Solution Published Source Original source
A digital illustration depicting cPanel and WHM logos with a security warning icon, symbolizing a critical server vulnerability and the need for immediate patching.

πŸ“Œ Key Highlights:
- A critical security vulnerability, CVE-2026-65643, has been found in all supported versions of cPanel & WHM.
- This vulnerability allows a single hosting customer to execute code with Root user privileges.
- The issue stems from the Domain Parking and Addon Domain functions, which are commonly used core features. System administrators must update patches urgently.

cPanel, a leading provider of control panels for web hosting, has announced the discovery of a critical security vulnerability directly impacting its cPanel and WebHost Manager (WHM) products. This issue is extremely severe as it could enable a regular user to gain complete control over a server.

🚨 Vulnerability Details
The vulnerability, assigned CVE-2026-65643, lies within the functionality of Domain Parking and Addon Domain. If exploited, a malicious hosting customer on a server could use this flaw to secretly execute harmful code with Root privileges. This means they could access all data of other customers on the same server, modify core server settings, or even command a complete system shutdown.

βš™οΈ Impact and Resolution
cPanel has confirmed that this vulnerability affects all supported versions of cPanel & WHM, rating its severity as Critical. A patch has already been released to address the flaw. All system administrators and hosting providers are strongly advised to check their cPanel & WHM versions and apply the security update immediately to prevent potential damage from attacks.

System administrators using cPanel & WHM should verify their systems and apply the patch promptly.

Let’s build what’s next

Better IT starts with understanding your business.

Tell our engineers what you need and receive an initial recommendation at no cost.