Back to Security Advisories

Security: CVE-2026-65643 Vulnerability in cPanel’s Domain Parking Functionality – August 27, 2026

An authenticated cPanel account holder who is able to add parked or addon domains can create arbitrary files on the server.

High
cPanel

Default Update CMD

sudo /scripts/upcp --force

Situation

An authenticated cPanel account holder who is able to add parked or addon domains can create arbitrary files on the server.

Affected Product Versions

Product Affected Versions Patched Versions
cPanel/WHM All supported versions
  • 11.110.0.141 or later
  • 11.134.0.53 or later
  • 11.136.0.37 or later
  • 11.138.0.2 or later
  • WP2: 11.138.1.7 or later

Impact

Successful exploitation leads to code execution as the root user, giving an attacker full control of the server and every account, website, and database on it.

Call to action

Update to the latest patched version: How do I update cPanel/WHM?

How to Apply the Fix

Update the affected packages on your server to the patched release, then restart the relevant services.

sudo /scripts/upcp --force

Check your system for vulnerabilities

Wählen Sie Ihr Produkt und Betriebssystem, um die passenden Fix-Befehle zu sehen.

Check Your System