Security: CVE-2026-65643 Vulnerability in cPanel’s Domain Parking Functionality – August 27, 2026
An authenticated cPanel account holder who is able to add parked or addon domains can create arbitrary files on the server.
Default Update CMD
sudo /scripts/upcp --force
Situation
An authenticated cPanel account holder who is able to add parked or addon domains can create arbitrary files on the server.
Affected Product Versions
| Product | Affected Versions | Patched Versions |
|---|---|---|
| cPanel/WHM | All supported versions |
|
Impact
Successful exploitation leads to code execution as the root user, giving an attacker full control of the server and every account, website, and database on it.
Call to action
Update to the latest patched version: How do I update cPanel/WHM?
How to Apply the Fix
Update the affected packages on your server to the patched release, then restart the relevant services.
sudo /scripts/upcp --force
References
Check your system for vulnerabilities
अपना उत्पाद और ऑपरेटिंग सिस्टम चुनें ताकि आपके लिए लागू सटीक फिक्स कमांड देख सकें।
Check Your System