Security1 distinct publisher3 min readPublished
cPanel shipped fixes for CVE-2026-65643 on August 27 across four build branches. Administrators checking their own build get no CVSS score, no published CVE record and nothing to grep for prior abuse.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
The precondition is the finding. cPanel says an authenticated account holder who can add parked or addon domains can create arbitrary files on the server [3], and that successful exploitation "leads to code execution as the root user, giving an attacker full control of the server" [4]. Every supported version of cPanel and WHM is in scope [2]. The August 27 notification does not say whether a Team User sub-account holding permission over parked and addon domains qualifies as that account holder [c11b], while July's Exim advisory said that flaw may allow privilege escalation from Team User sub-accounts [11]. Until cPanel answers, resellers who delegate domain management should assume the sub-account counts.
Verification takes a minute. Read the installed build in WHM under Server Configuration > Update Preferences, force the update as root with /scripts/upcp --force, or take it from Home > cPanel > Upgrade to Latest Version [8]. Servers on automatic daily updates already have it [7]. Servers on an end-of-life version get nothing until they move to a supported branch [9], and that population overlaps with the next problem.
July's three cPanel advisories named fixed builds in the 11.118 and 11.126 branches [10]. The August 27 list names 11.110.0.141, 11.134.0.53, 11.136.0.37, 11.138.0.2 and, for WP Squared, 11.138.1.7 [5]. Two branches that were receiving fixes 27 days earlier are absent [24][27], and cPanel has not said whether they remain supported [10]. DNSOnly is not named either [6].
The paperwork is thin. There is no CVSS score in the customer notification, and The Hacker News found no CVE Program record for CVE-2026-65643 when it checked on August 28, one day after the advisory [12][26], though the records for CVE-2026-58048 and CVE-2026-58047 from July 31 were both live at that check [12]. cPanel has not claimed exploitation, and the flaw is absent from CISA's KEV catalog as of the August 27 release [13]. KEV already carries three cPanel-ecosystem entries [25]: the LiteSpeed plugin privilege escalation that any cPanel user account can use to run scripts as root, added May 26 [14]; a symlink-following flaw in the same plugin, added June 15 for shared hosting on CloudLinux or CageFS where the user has FTP or web shell access [15]; and April's authentication bypass, listed with known use in ransomware campaigns [16].
There is no interim mitigation and no way to check whether a server was already used [17]. cPanel produces that guidance when it decides to: for the Phusion Passenger issue on August 14 it shipped a command to grep the Apache error log [18], and Plesk, developed by parent company WebPros alongside cPanel, published a five-item compromise checklist beginning with unexpected entries in /etc/ld.so.preload [20], with the note that "patching closes the vulnerability going forward, but it does not undo anything an attacker may have already done" [21].
Keep those two threads apart. The in-the-wild exploitation Phusion reported at a shared hosting provider [23] concerns the Watchdog API flaw it fixed in Passenger 6.2.0 on August 18, which carries no CVE identifier [22] and reaches only servers where an affected Passenger package is installed [19]. Nothing public connects it to CVE-2026-65643.
Ranked by verification strength, evidence, and original report placement.
cPanel released patches for a security flaw affecting domain parking and addon domain functionality in cPanel and WebHost Manager (WHM) that could allow code execution as the root user.
The vulnerability, CVE-2026-65643, impacts all supported versions of cPanel & WHM.
cPanel described the issue as critical and said an authenticated account holder who can add parked or addon domains can create arbitrary files on the server.
cPanel told customers: "Successful exploitation leads to code execution as the root user, giving an attacker full control of the server."
The patched versions are 11.110.0.141 or later, 11.134.0.53 or later, 11.136.0.37 or later, 11.138.0.2 or later, and 11.138.1.7 or later for WP Squared.
The notification names WP Squared in its patched list and does not mention DNSOnly.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 28, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
security
Frontier AI can find the bugs faster. The patch queue is the number nobody published.1 distinct publisher
security
Johnson Controls console holds passwords in cleartext memory, and the fix line names two versions1 distinct publisher
security
Mitsubishi's CNC advisory now lists 18 models exposed on TCP port 6831 distinct publisher
security
Siemens patches a CAE overflow that lands in the sectors that patch workstations last1 distinct publisher
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
One vendor notice, two cold checks
Every load-carrying detail — the critical rating, the root outcome, the five build numbers — comes from a notification cPanel sent its own customers, relayed by The Hacker News with no advisory URL, no researcher and no second outlet. What lifts it above stenography is that the reporting went looking: the CVE record store on August 28 and CISA's August 27 catalog, both of which came back empty for CVE-2026-65643. Negative findings are real evidence, but they cannot corroborate the severity claim they surround.
Fixes shipped, uptake uncounted
What is observable is distribution, not installation: five patched builds across four branches plus WP Squared, and an auto-update channel that pushes them to servers configured for daily updates. No one counts how many shared hosts now run those builds, and the only field evidence anywhere near this story belongs to a different bug — Phusion saying it watched the Passenger Watchdog flaw being exploited at a shared hosting provider, and CISA's catalog carrying three older cPanel-ecosystem entries.
Vendor's own alarm, nobody's confirmation
The headline framing — one hosting customer takes root on the whole server — is cPanel's sentence, not the reporter's flourish, and most of the piece is spent on subtraction: no score, no record, no mitigation, no way to check the past. That restraint keeps the overhang small. It is not zero, because the scariest element is still an unranked vendor assertion one day old, with no published record, no exploitation and no independent severity assessment behind it.
Quiet channel, franker neighbours
cPanel routed a root-level flaw through a customer notification: urgent enough to drive patching, unnumbered and unrecorded enough that nobody outside can rank it or compare it. The contrast lands inside the same corporate family. Plesk, also a WebPros product, published a five-item checklist for spotting prior compromise from the Passenger bug and said plainly that patching undoes nothing an attacker already did — and cPanel itself supplied a grep command for that narrower issue two weeks before saying nothing about detection for this one. Phusion, with no platform reputation riding on it, simply admitted seeing exploitation in the wild.
Solid on the fix, blank on the blast radius
Treat the remediation half as reliable: build numbers, commands and menu paths are the kind of detail a vendor notice gets right and a reporter can transcribe faithfully. Treat the risk half as provisional. Scope, sub-account eligibility, exploitation status and the support state of two branches are all open, one publisher carries the whole account, and the record that would normally settle severity had not been published when the check was made.