Vulnerability
Published 2026-08-27
Verified 2026-09-19
cPanel/WHM domain parking: authenticated file create to root (CVE-2026-65643)
cPanel's 27 August 2026 advisory: an authenticated account that can add parked or addon domains can create arbitrary files on the server. Successful exploitation is code execution as root, which is the whole host, not one site. All supported cPanel/WHM versions are affected. Patched builds: 11.110.0.141, 11.134.0.53, 11.136.0.37, 11.138.0.2, and WP Squared 11.138.1.7. The vendor page does not publish a CVSS score and does not say it is exploited. This is not the April login bypass (CVE-2026-41940), which is already on the desk.
- Product
- cPanel/WHM, WP Squared
- Versions
- All supported versions before the 27 August patched builds
- Exploited in Australia?
- unknown
- Patch to
- 11.110.0.141, 11.134.0.53, 11.136.0.37, 11.138.0.2, or WP2 11.138.1.7 or later
Primary: cPanel advisory (27 Aug 2026) · Vendor: cPanel, CVE-2026-65643 · CVE: CVE-2026-65643, CVE-2026-41940
