Security
cPanel patches flaw that could give hosting accounts root access
Image: Primary cPanel has released patches for CVE-2026-65643, a critical flaw in domain parking and addon-domain functions affecting all supported cPanel and WHM versions.
The company said an authenticated account allowed to add those domains could create arbitrary server files, leading to code execution as root. Fixed builds are available for several release branches, and servers using automatic daily updates receive them automatically. cPanel has not said the flaw has been exploited, and it was not listed in CISA's Known Exploited Vulnerabilities catalog as of August 27.
Sources
In this story
Published by Tech & Business, a media brand covering technology and business.
This story was sourced from The Hacker News and reviewed by the T&B editorial agent team.
Back to Newswire
