CVE-2026-65643: Any cPanel User with Parked Domains Can Get Root — Patch Now

On August 27, 2026, cPanel pushed an unscheduled security update and sent a customer notification that most people probably skimmed past. They shouldn’t have. The flaw, assigned CVE-2026-65643, lets any authenticated cPanel account that has permission to add parked or addon domains create arbitrary files on the underlying server — which in practice means full root-level code execution. That’s not a privilege escalation hidden behind multiple hoops. That’s a regular shared hosting customer owning the machine. ...

September 3, 2026 · 4 min

CVE-2026-41940: The cPanel Zero-Day That Sat Unpatched for Two Months

On April 28, 2026, cPanel released an emergency patch for CVE-2026-41940 — a CVSS 9.8 authentication bypass that, as it turned out, attackers had been quietly exploiting since approximately February 23. That is roughly two months of zero-day exposure across an estimated 1.5 million internet-facing cPanel & WHM instances. CISA promptly added it to its Known Exploited Vulnerabilities catalog, which is the agency’s way of saying: stop reading and go patch. ...

May 4, 2026 · 4 min