Panellicense

CVE-2026-65643: patch the cPanel domain parking root vulnerability

CVE-2026-65643 lets an authenticated cPanel user with parked or addon-domain access create arbitrary server files and potentially execute code as root. Check the fixed builds and update now.

cPAll cPanel articlesNews & changelogs3 min readUpdated 2026-08-27
schema: TechArticleschema: FAQPageschema: BreadcrumbList

cPanel has released emergency builds for CVE-2026-65643, a critical vulnerability in cPanel & WHM's domain parking functionality. An authenticated cPanel account that can add parked or addon domains may be able to create arbitrary files on the server. Successful exploitation can lead to code execution as root and complete server compromise.

All supported cPanel & WHM versions were listed as affected in cPanel's 27 August 2026 security advisory. Do not assume that restricting WHM access protects the server: the vulnerable operation is available to ordinary cPanel accounts when their feature permissions allow domain aliases or addon domains.

Affected and patched builds

Update to at least the fixed build for your branch:

cPanel & WHM branchFirst patched build
11.11011.110.0.141
11.13411.134.0.53
11.13611.136.0.37
11.13811.138.0.2
WP Squared 11.138.111.138.1.7

A later build in the same supported branch also contains the fix. If the server is on an end-of-life branch, move it to a supported release; an unsupported installation cannot be considered patched merely because automatic updates are enabled.

Check the installed cPanel version

Run this as root:

/usr/local/cpanel/cpanel -V

Compare the complete version with the table above. For example, 11.136.0.36 remains vulnerable, while 11.136.0.37 or later in that branch contains the hotfix.

You can also check in WHM under Server Configuration > Update Preferences.

Install the hotfix immediately

Servers configured for automatic daily updates should receive a patched build, but cPanel recommends applying this critical fix immediately rather than waiting for the next scheduled run:

/scripts/upcp --force

Alternatively, in WHM go to Home > cPanel > Upgrade to Latest Version, install the latest available update, and verify the resulting build again.

What to review after patching

The update closes the known vulnerability but cannot undo a prior compromise. If an affected server allowed customers to create parked or addon domains, review it for unexpected privileged changes:

  • recently created or modified files in root-owned and executable paths;
  • unfamiliar root SSH keys, administrator accounts, or sudoers entries;
  • unexpected services, cron jobs, systemd units, and startup scripts;
  • suspicious cPanel account activity and domain additions;
  • unexplained outbound connections or newly listening services.

If you find indicators of compromise, isolate the server, preserve evidence, rotate privileged credentials from a trusted system, and rebuild from known-good sources where appropriate.

What is CVE-2026-65643?+
It is a critical flaw in cPanel & WHM domain parking functionality. An authenticated cPanel account allowed to add parked or addon domains may create arbitrary server files, potentially leading to root code execution.
Are all cPanel versions affected?+
cPanel's 27 August 2026 advisory listed all supported versions as affected and supplied fixed builds for branches 110, 134, 136, 138, and WP Squared 138.1. Unsupported branches should be upgraded to a supported patched release.
How do I install the cPanel hotfix?+
Run /scripts/upcp --force as root, or use WHM > Home > cPanel > Upgrade to Latest Version. Verify the complete installed build afterward.
Does disabling parked and addon domains fix the vulnerability?+
No. Removing those feature permissions can temporarily reduce exposure, but only installing a patched cPanel build fixes the vulnerable code.

Next steps

Keeping a current cPanel license allows supported servers to receive security hotfixes through the normal update channel.

changelog
CVE-2026-33278: the cpanel-unbound DNSSEC RCE, and how to check for it
A critical Unbound DNSSEC validator bug shipped as cpanel-unbound puts remote code execution one malicious signed zone away, no login required. Patched builds and how to check exposure.
7 min read
changelog
CVE-2026-41940: the cPanel & WHM auth bypass, and how to check for it
A CRLF injection in cpsrvd session handling let unauthenticated attackers write user=root into their own session file. Patched versions, IOCs, and how to check if you were hit.
7 min read
changelog
EasyApache 4 25.69: cPanel patches six Tomcat CVEs in ea-tomcat101
EasyApache 4 25.69 ships Apache Tomcat 10.1.56 in ea-tomcat101, closing six CVEs — an auth-bypass on default servlet constraints among them. Here's what's fixed and how to update.
5 min read
how to
Enable DNSSEC for cPanel-hosted zones without breaking resolution
A working DNSSEC rollout for cPanel — enable per-zone signing, publish the DS record at your registrar, verify with dig, and survive the first key rollover without going dark.
8 min read
how to
Create and scope WHM API tokens for safe automation
WHM API tokens replace root passwords for billing scripts, monitoring agents, and Blesta or WHMCS integrations — here's how to scope them tightly and rotate them safely.
8 min read
how to
Tune WHM cPHulk brute force protection without lockouts
A working cPHulk configuration for shared cPanel servers — whitelist, thresholds, country blocking, notifications, and the CLI commands that get you back in when you lock yourself out.
6 min read
Switch in an afternoon

Switch from your current reseller — free.

We migrate active cPanel, Plesk, LiteSpeed and CloudLinux licenses from any reseller. We prorate the first month so you never pay twice, and your customers see zero downtime during the swap.