CVE-2026-65643: Any cPanel User with Parked Domains Can Get Root — Patch Now

On August 27, 2026, cPanel pushed an unscheduled security update and sent a customer notification that most people probably skimmed past. They shouldn’t have. The flaw, assigned CVE-2026-65643, lets any authenticated cPanel account that has permission to add parked or addon domains create arbitrary files on the underlying server — which in practice means full root-level code execution. That’s not a privilege escalation hidden behind multiple hoops. That’s a regular shared hosting customer owning the machine. ...

September 3, 2026 · 4 min