Hosting tenants on cPanel and WebHost Manager servers face a newly patched flaw that ends in root-level code execution. The bug lives in the domain parking and addon domain features, is tracked as CVE-2026-65643, and touches every supported version of both products.
Anyone with an authenticated account who can add parked or addon domains can plant arbitrary files on the server. The vendor’s notification spells out the risk in one line: exploitation grants root, which means total control of the box. Patched builds shipped on August 27: 11.110.0.141, 11.134.0.53, 11.136.0.37, 11.138.0.2, and 11.138.1.7 for the WP Squared edition.
Administrators running automatic daily updates will pick up the patched build without manual work. Everyone else can force it by logging in as root and running /scripts/upcp –force, or by heading to WHM, then Home, then cPanel, then Upgrade to Latest Version. The advisory names the 110, 134, 136, and 138 branches; cPanel has not said whether the 11.118 and 11.126 lines remain supported after July’s patch round.
One open question is whether Team User sub-accounts with permission to manage parked and addon domains fall in scope. Servers on end-of-life versions may not receive the fix at all.
