Critical cPanel flaw allows root code execution
🛡️ cPanel released patches for a critical vulnerability (CVE-2026-65643) affecting domain parking and addon domain handling in cPanel & WHM that could let authenticated users create arbitrary files and achieve root code execution. The company published fixed builds across multiple release branches on August 27, 2026, and advised administrators to update immediately or enable automatic updates. The advisory names patched builds including a WP Squared release, omits DNSOnly, and provides no interim mitigation or CVSS score. Servers on end-of-life versions must upgrade to receive the fix.
