Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
cPanel Flaw Risks Server Control to Attackers

cPanel Flaw Risks Server Control to Attackers

Posted on August 28, 2026 By CWS

A newly identified security flaw in cPanel and WHM, a popular web hosting control panel, could permit attackers with minimal privileges to obtain root access to an entire server.

CVE-2026-65643: A Threat to Server Security

Designated CVE-2026-65643, this vulnerability was disclosed in an advisory on August 27, 2026, by cPanel support engineer Devon Courtney. The flaw is located within the domain parking feature of cPanel, which allows authenticated users to create arbitrary files on the server.

The vulnerability is particularly concerning because it requires only a basic cPanel account with permission to add parked or addon domains. This makes it possible for attackers to exploit the bug using a simple shared hosting account or a compromised user login.

Implications for Hosting Environments

Domain parking, a common feature in web hosting, lets users direct additional domains to an existing site without needing separate accounts. This functionality is widespread across shared and reseller hosting services using cPanel, making the vulnerability especially dangerous.

By exploiting this flaw, attackers can execute code as the root user, gaining control of the entire server. This not only jeopardizes the compromised account but also every other site, database, and email hosted on the same server.

Urgent Need for Patch Implementation

cPanel has responded by releasing patches for all supported versions, including builds 11.110.0.141 and later. However, administrators using outdated versions must upgrade to receive these fixes.

Hosting providers and system administrators are urged to prioritize this patch due to the simplicity of the required exploit. While cPanel typically updates automatically, those handling manual updates must ensure they are running the patched versions immediately.

Additionally, reviewing account permissions for domain additions and restricting them temporarily can help mitigate risk until the patch is applied.

Given cPanel’s prevalence in hosting, the time between vulnerability disclosure and exploitation can be brief, emphasizing the need for swift action to protect server integrity.

Cyber Security News Tags:cPanel, CVE-2026-65643, Cybersecurity, domain parking, security patch, server security, shared hosting, Vulnerability, web hosting, WHM

Post navigation

Previous Post: Cisco Highlights Hidden Risks in AI Model Origins
Next Post: Unitree G1 EDU Robots Face Critical Security Vulnerabilities

Related Posts

RapperBot Hijacking Devices to Launch DDoS Attack In a Split Second RapperBot Hijacking Devices to Launch DDoS Attack In a Split Second Cyber Security News
Roundcube Webmail Addresses 12 Security Vulnerabilities Roundcube Webmail Addresses 12 Security Vulnerabilities Cyber Security News
Russian Hackers Exploit HOOKEDGE Backdoor in Europe Russian Hackers Exploit HOOKEDGE Backdoor in Europe Cyber Security News
Hackers Exploit Fake 7-Zip to Create Proxy Networks Hackers Exploit Fake 7-Zip to Create Proxy Networks Cyber Security News
Top 3 CISO Challenges And How To Solve Them  Top 3 CISO Challenges And How To Solve Them  Cyber Security News
Critical OpenClaw Vulnerability Allows AI Agent Hijacking Critical OpenClaw Vulnerability Allows AI Agent Hijacking Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • TP-Link Camera Vulnerabilities Threaten User Privacy
  • AI-Driven Data Breach Notified to Spanish Authorities
  • Critical Issabel Framework Vulnerability Exploited
  • Smishing Campaign Poses Major Cybersecurity Threat
  • EU Targets AI Risks and Social Media Safety

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • TP-Link Camera Vulnerabilities Threaten User Privacy
  • AI-Driven Data Breach Notified to Spanish Authorities
  • Critical Issabel Framework Vulnerability Exploited
  • Smishing Campaign Poses Major Cybersecurity Threat
  • EU Targets AI Risks and Social Media Safety

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark