Vulnerability
Published 2026-08-27
Verified 2026-09-19

cPanel/WHM domain parking: authenticated file create to root (CVE-2026-65643)

cPanel's 27 August 2026 advisory: an authenticated account that can add parked or addon domains can create arbitrary files on the server. Successful exploitation is code execution as root, which is the whole host, not one site. All supported cPanel/WHM versions are affected. Patched builds: 11.110.0.141, 11.134.0.53, 11.136.0.37, 11.138.0.2, and WP Squared 11.138.1.7. The vendor page does not publish a CVSS score and does not say it is exploited. This is not the April login bypass (CVE-2026-41940), which is already on the desk.

Product
cPanel/WHM, WP Squared
Versions
All supported versions before the 27 August patched builds
Exploited in Australia?
unknown
Patch to
11.110.0.141, 11.134.0.53, 11.136.0.37, 11.138.0.2, or WP2 11.138.1.7 or later

Primary: cPanel advisory (27 Aug 2026) · Vendor: cPanel, CVE-2026-65643 · CVE: CVE-2026-65643, CVE-2026-41940

vulnerabilities cloud