Security: CVE-2026-65643 Vulnerability in cPanel’s Domain Parking Functionality – August 27, 2026
An authenticated cPanel account holder who is able to add parked or addon domains can create arbitrary files on the server.
Команда обновления по умолчанию
sudo /scripts/upcp --force
Что это значит по лицензии SharedLicense
Your SharedLicense license itself is not affected — this is a vulnerability in cPanel software, not in licensing. Licenses continue to work during and after the update; there is no need to re-issue or re-activate anything. If you resell cPanel under your own brand, patch client servers too — unpatched installs put your reputation at risk, not your license.
Situation
An authenticated cPanel account holder who is able to add parked or addon domains can create arbitrary files on the server.
Affected Product Versions
| Product | Affected Versions | Patched Versions |
|---|---|---|
| cPanel/WHM | All supported versions |
|
Impact
Successful exploitation leads to code execution as the root user, giving an attacker full control of the server and every account, website, and database on it.
Call to action
Update to the latest patched version: How do I update cPanel/WHM?
Часто задаваемые вопросы
What is CVE-2026-65643?
Is CVE-2026-65643 being exploited in the wild?
How do I fix CVE-2026-65643?
Источники
Проверьте систему на уязвимости
Выберите продукт и операционную систему, чтобы увидеть точные команды исправления.
Проверьте свою систему