Close Menu
NCIJ Network NCIJ Network
    What's Hot

    The Easiest Ways to Share Anything Between Android and iOS

    August 28, 2026

    Critical cPanel Flaw Could Let One Hosting Customer Take Root Control of a Whole Server

    August 28, 2026

    Judge Rules Trump Administration Illegally Retaliated Against Anthropic Over AI Red Lines

    August 28, 2026
    Facebook X (Twitter) Instagram
    Trending
    • The Easiest Ways to Share Anything Between Android and iOS
    • Critical cPanel Flaw Could Let One Hosting Customer Take Root Control of a Whole Server
    • Judge Rules Trump Administration Illegally Retaliated Against Anthropic Over AI Red Lines
    • Scientists tested 212 plant-based meat alternatives. Every one contained fungal toxins
    • Can California Farmers Break Free From Plastic?
    • Syracuse University Intervenes to Block Subpoena of Police Records — ProPublica
    • We need new reservoirs – and it’s a job for the state, not private companies | Water
    • John Healey to duck meeting UK defence spending target in budget | Economics
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Friday, August 28
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Critical cPanel Flaw Could Let One Hosting Customer Take Root Control of a Whole Server

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 28, 2026 Cybersecurity No Comments4 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Swati KhandelwalAug 28, 2026Vulnerability / Web Security

    cPanel has released patches for a security flaw affecting domain parking and addon domain functionality in cPanel and WebHost Manager (WHM), which could allow code execution as the root user.

    The vulnerability, assigned the CVE identifier CVE-2026-65643, impacts all supported versions of cPanel & WHM.

    cPanel described the issue as a critical security vulnerability and said that an authenticated account holder who can add parked or addon domains can create arbitrary files on the server.

    “Successful exploitation leads to code execution as the root user, giving an attacker full control of the server,” cPanel said in a notification to customers.

    cPanel has released the following patched versions –

    • 11.110.0.141 or later
    • 11.134.0.53 or later
    • 11.136.0.37 or later
    • 11.138.0.2 or later
    • 11.138.1.7 or later (WP Squared)

    The notification names WP Squared in its patched list and does not mention DNSOnly.

    cPanel patched three separate flaws in July, and the fixed builds named in those advisories included the 11.118 and 11.126 branches. The August 27 list covers the 110, 134, 136, and 138 branches, and the company has not said whether 11.118 and 11.126 remain supported.

    Cybersecurity

    cPanel said in its July advisory about the Exim flaw that it may allow privilege escalation from Team User sub-accounts. The August 27 notification does not specify whether a Team User sub-account with permission to the parked and addon domains is in scope.

    Servers configured for automatic daily updates receive the patched build automatically, according to the advisory published on August 27.

    Administrators can apply it immediately by logging in to the server as root and running /scripts/upcp –force. The update can also be installed from WHM under Home > cPanel > Upgrade to Latest Version, and the installed build can then be verified under Server Configuration > Update Preferences.

    Servers running an end-of-life version have to upgrade to a supported version to receive the fix.

    The customer notification carries no CVSS score, and The Hacker News confirmed via the CVE Program’s record store on August 28, 2026, that no record has been published for CVE-2026-65643. Records for CVE-2026-58048 and CVE-2026-58047, two cPanel flaws disclosed on July 31, were both present at the time of the check.

    cPanel has not said whether the flaw has been exploited, and it is absent from the U.S. Cybersecurity and Infrastructure Security Agency’s (CISA) Known Exploited Vulnerabilities (KEV) catalog as of the version released on August 27, 2026. The catalog already carries two flaws in a cPanel plugin.

    CISA added CVE-2026-48172, a privilege escalation issue in the LiteSpeed cPanel plugin, on May 26, 2026, and noted that it can be exploited by any cPanel user account to execute arbitrary scripts with root privileges.

    It added CVE-2026-54420, a symlink-following flaw in the same plugin, on June 15, 2026, for shared hosting servers running CloudLinux or CageFS where a user has FTP or web shell access.

    The catalog also lists CVE-2026-41940, the authentication bypass patched in April, with known use in ransomware campaigns.

    Cybersecurity

    The customer notification provides no interim mitigation and no way to verify whether a server has already been compromised.

    cPanel carried a command to grep the Apache error log for signs of exploitation in its Phusion Passenger advisory, published on August 14, 2026.

    cPanel said that the issue does not affect default installations and applies only to servers where an affected Passenger package has been installed.

    Plesk, which WebPros develops alongside cPanel, updated its own advisory for the same flaw on August 14, 2026, with a five-item checklist for spotting a prior compromise that begins with unexpected entries in /etc/ld.so.preload.

    “Patching closes the vulnerability going forward, but it does not undo anything an attacker may have already done,” Plesk said.

    Phusion, which develops Passenger, shipped a fix in Passenger 6.2.0 on August 18, 2026, for a Watchdog API flaw that does not have a CVE identifier.

    “We have seen exploitation of this vulnerability in the wild at a shared hosting provider,” Phusion said.

    control cPanel critical customer Flaw hosting Root server
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    APT28-Linked HOOKEDGE Backdoor Targets European Government and Diplomatic Organizations

    PaperCut Zero-Day Exploited in Attacks, Affecting All NG and MF Versions

    New GPUThor Rowhammer Defeats ECC on NVIDIA RTX A6000 to Gain Host Root Access

    GoCaracal Malware Uses Ethereum Smart Contract to Fetch Replacement C2 Address

    Pro-Russian Hackers Claim Responsibility for Major Cyberattack on Norway’s Public Digital Services

    What the Data Says About AI in Security Operations in 2026

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    The Easiest Ways to Share Anything Between Android and iOS

    August 28, 2026

    Critical cPanel Flaw Could Let One Hosting Customer Take Root Control of a Whole Server

    August 28, 2026

    Judge Rules Trump Administration Illegally Retaliated Against Anthropic Over AI Red Lines

    August 28, 2026

    Scientists tested 212 plant-based meat alternatives. Every one contained fungal toxins

    August 28, 2026
    Latest Posts

    NASA’s Curiosity Discovers a Field of Martian Polygons

    July 29, 2026

    As crypto perpetual futures boom, Ethereum’s role is shifting

    July 29, 2026

    Critical Rails Flaw Could Let Unauthenticated Attackers Read Server Files via Image Uploads

    July 29, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    The Easiest Ways to Share Anything Between Android and iOS

    August 28, 2026

    Critical cPanel Flaw Could Let One Hosting Customer Take Root Control of a Whole Server

    August 28, 2026

    Judge Rules Trump Administration Illegally Retaliated Against Anthropic Over AI Red Lines

    August 28, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.