Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
cPanel Flaw Risks Server Control to Attackers

cPanel Flaw Risks Server Control to Attackers

Posted on August 28, 2026 By CWS

A newly identified security flaw in cPanel and WHM, a popular web hosting control panel, could permit attackers with minimal privileges to obtain root access to an entire server.

CVE-2026-65643: A Threat to Server Security

Designated CVE-2026-65643, this vulnerability was disclosed in an advisory on August 27, 2026, by cPanel support engineer Devon Courtney. The flaw is located within the domain parking feature of cPanel, which allows authenticated users to create arbitrary files on the server.

The vulnerability is particularly concerning because it requires only a basic cPanel account with permission to add parked or addon domains. This makes it possible for attackers to exploit the bug using a simple shared hosting account or a compromised user login.

Implications for Hosting Environments

Domain parking, a common feature in web hosting, lets users direct additional domains to an existing site without needing separate accounts. This functionality is widespread across shared and reseller hosting services using cPanel, making the vulnerability especially dangerous.

By exploiting this flaw, attackers can execute code as the root user, gaining control of the entire server. This not only jeopardizes the compromised account but also every other site, database, and email hosted on the same server.

Urgent Need for Patch Implementation

cPanel has responded by releasing patches for all supported versions, including builds 11.110.0.141 and later. However, administrators using outdated versions must upgrade to receive these fixes.

Hosting providers and system administrators are urged to prioritize this patch due to the simplicity of the required exploit. While cPanel typically updates automatically, those handling manual updates must ensure they are running the patched versions immediately.

Additionally, reviewing account permissions for domain additions and restricting them temporarily can help mitigate risk until the patch is applied.

Given cPanel’s prevalence in hosting, the time between vulnerability disclosure and exploitation can be brief, emphasizing the need for swift action to protect server integrity.

Cyber Security News Tags:cPanel, CVE-2026-65643, Cybersecurity, domain parking, security patch, server security, shared hosting, Vulnerability, web hosting, WHM

Post navigation

Previous Post: Cisco Highlights Hidden Risks in AI Model Origins
Next Post: Unitree G1 EDU Robots Face Critical Security Vulnerabilities

Related Posts

RainyDay, Turian and Naikon Malwares Abuse DLL Search Order to Execute Malicious Loaders RainyDay, Turian and Naikon Malwares Abuse DLL Search Order to Execute Malicious Loaders Cyber Security News
New Sophisticated Attack Bypasses Content Security Policy Using HTML-Injection Technique New Sophisticated Attack Bypasses Content Security Policy Using HTML-Injection Technique Cyber Security News
Oblivion RAT: New Android Threat with Hidden Control Oblivion RAT: New Android Threat with Hidden Control Cyber Security News
Web3 Developers Targeted by Fake Recruiters Web3 Developers Targeted by Fake Recruiters Cyber Security News
Critical CosmosEscape Flaw in Azure Cosmos DB Uncovered Critical CosmosEscape Flaw in Azure Cosmos DB Uncovered Cyber Security News
Threat Actors Using Stealerium Malware to Attack Educational Organizations Threat Actors Using Stealerium Malware to Attack Educational Organizations Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Fake Resume Malware Targets Academic Researchers
  • OpenAI Agents Exploit Linux Vulnerability on Internal Systems
  • Unitree G1 EDU Robots Face Critical Security Vulnerabilities
  • cPanel Flaw Risks Server Control to Attackers
  • Cisco Highlights Hidden Risks in AI Model Origins

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Fake Resume Malware Targets Academic Researchers
  • OpenAI Agents Exploit Linux Vulnerability on Internal Systems
  • Unitree G1 EDU Robots Face Critical Security Vulnerabilities
  • cPanel Flaw Risks Server Control to Attackers
  • Cisco Highlights Hidden Risks in AI Model Origins

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark