Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Critical cPanel Security Flaw Patched to Prevent Root Access

Critical cPanel Security Flaw Patched to Prevent Root Access

Posted on August 28, 2026 By CWS

cPanel has urgently addressed a significant security flaw that could potentially allow unauthorized users to gain root access to a server. The vulnerability, identified as CVE-2026-65643, affects all supported versions of cPanel and WebHost Manager (WHM). This issue involves a security gap in the domain parking and addon domain functionality that could lead to arbitrary code execution.

Details of the Vulnerability

According to cPanel, the flaw is categorized as critical, enabling authenticated users with the ability to add parked or addon domains to create arbitrary files on the server. If exploited, this could result in an attacker obtaining complete control over the server by executing code as the root user.

The company has released several updated versions to address this issue, including versions 11.110.0.141, 11.134.0.53, 11.136.0.37, 11.138.0.2, and 11.138.1.7. Notably, WP Squared is included in this patch list, while DNSOnly is not mentioned.

Impact and Advisory

Previously, cPanel fixed other vulnerabilities in July, and those updates included versions 11.118 and 11.126. However, the latest advisory does not confirm whether these branches remain supported. The flaw has not been listed in the U.S. Cybersecurity and Infrastructure Security Agency’s (CISA) Known Exploited Vulnerabilities catalog as of the latest update.

Servers configured for automatic daily updates will receive the patched versions automatically. Administrators can also manually apply the updates by executing specific commands or through the cPanel interface. Systems running outdated versions must upgrade to supported versions to receive the necessary security fixes.

Future Outlook and Recommendations

Currently, there is no interim mitigation provided by cPanel to verify if a server has been compromised. Users are encouraged to apply the patches immediately to prevent potential exploitation. Despite the absence of a CVSS score, the urgency conveyed in cPanel’s communications underlines the severity of this flaw.

In addition, cPanel has shared a command to inspect Apache error logs for any signs of exploitation, particularly in cases involving the Phusion Passenger package. Users are advised to remain vigilant and ensure that their systems are updated regularly to protect against such critical vulnerabilities.

As cybersecurity threats continue to evolve, maintaining updated software and following best practices are essential for safeguarding server environments against potential breaches.

The Hacker News Tags:cPanel, CVE-2026-65643, Cybersecurity, Patch, root access, Security, software update, Vulnerability, web hosting, WHM

Post navigation

Previous Post: Dark Caracal Hackers Leverage Ethereum for Malware Resilience
Next Post: Hackers Exploit SPN Gaps for Stealthy Kerberoasting

Related Posts

Why Non-Human Identity Management is the Next Cybersecurity Frontier Why Non-Human Identity Management is the Next Cybersecurity Frontier The Hacker News
B Crypto Bust, Satellite Spying, Billion-Dollar Smishing, Android RATs & More $15B Crypto Bust, Satellite Spying, Billion-Dollar Smishing, Android RATs & More The Hacker News
Linux Rootkit and macOS Crypto Stealer Dominate Headlines Linux Rootkit and macOS Crypto Stealer Dominate Headlines The Hacker News
 Battering RAM Attack Breaks Intel and AMD Cloud Security Protections $50 Battering RAM Attack Breaks Intel and AMD Cloud Security Protections The Hacker News
Microsoft Unveils DNS ClickFix Attack Using Nslookup Microsoft Unveils DNS ClickFix Attack Using Nslookup The Hacker News
Emerging Cyber Threats: OAuth Abuse and Beyond Emerging Cyber Threats: OAuth Abuse and Beyond The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Leaked Russian University Records Reveal GRU Cyber Training
  • Global Tech Leaders Rally for Enhanced AI Cyber Defense
  • Critical ServiceNow Vulnerabilities Demand Urgent Attention
  • Hackers Exploit SPN Gaps for Stealthy Kerberoasting
  • Critical cPanel Security Flaw Patched to Prevent Root Access

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Leaked Russian University Records Reveal GRU Cyber Training
  • Global Tech Leaders Rally for Enhanced AI Cyber Defense
  • Critical ServiceNow Vulnerabilities Demand Urgent Attention
  • Hackers Exploit SPN Gaps for Stealthy Kerberoasting
  • Critical cPanel Security Flaw Patched to Prevent Root Access

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark