cPanel has released security patches addressing a critical vulnerability (CVE-2026-65643) affecting its domain parking and addon domain functionality in cPanel and WebHost Manager (WHM). The flaw could allow an attacker to execute code as the root user, potentially enabling a single hosting customer to gain root-level control over an entire shared server. The vulnerability impacts all supported versions of cPanel and WHM. cPanel classified this as a critical security issue. The patch has been released and users are urged to update immediately to mitigate the risk of privilege escalation and full server compromise.
CVE-2026-65643 is a critical vulnerability in cPanel and WebHost Manager (WHM) affecting domain parking and addon domain functionality. An authenticated account holder with permission to add parked or addon domains can create arbitrary files on the server, leading to code execution as the root user and full server control. The flaw affects all supported versions of cPanel & WHM. The advisory does not provide a CVSS score and no CVE record had been published as of August 28, 2026. It is unclear whether Team User sub-accounts with permission to parked/addon domains are in scope. No interim mitigation or compromise verification method was provided. Additionally, a separate Phusion Passenger Watchdog API privilege escalation flaw (no CVE assigned) was patched in Passenger 6.2.0 on August 18, 2026, with confirmed in-the-wild exploitation at a shared hosting provider. Plesk noted that patching does not undo prior attacker actions and provided a compromise checklist including checking /etc/ld.so.preload for unexpected entries.
1. Update cPanel & WHM to patched versions: 11.110.0.141+, 11.134.0.53+, 11.136.0.37+, 11.138.0.2+, or 11.138.1.7+ (WP Squared). 2. Servers with automatic daily updates will receive the patch automatically. 3. To apply immediately, log in as root and run: /scripts/upcp --force. 4. Alternatively, apply via WHM under Home > cPanel > Upgrade to Latest Version. 5. Verify installed build under Server Configuration > Update Preferences. 6. Servers on end-of-life versions must upgrade to a supported version to receive the fix. 7. For Phusion Passenger, upgrade to Passenger 6.2.0 or later. 8. Check /etc/ld.so.preload for unexpected entries to detect prior Passenger compromise. 9. Review Apache error logs for signs of exploitation. 10. Monitor CISA KEV catalog for additions of CVE-2026-65643. 11. Note that patching does not undo actions already taken by an attacker — perform forensic review if compromise is suspected.
Unexpected entries in /etc/ld.so.preload (indicator of Phusion Passenger Watchdog API exploitation), Unexpected entries in Apache error log (indicator of Phusion Passenger exploitation)