Home / Aug 30, 2026 / Story
0
#6 The Hacker News general August 28, 2026 at 09:45 UTC

Critical cPanel Flaw Could Let One Hosting Customer Take Root Control of a Whole Server

By [email protected] (The Hacker News)

AI Summary

cPanel has patched CVE-2026-65643, a critical vulnerability in cPanel & WHM's domain parking and addon domain functionality that could allow a malicious hosting customer to execute code as root, effectively taking full control of a shared server and all other customers hosted on it. The flaw affects all supported versions of cPanel & WHM, making it a high-priority patch for any managed hosting provider or shared hosting environment. Root-level compromise via a tenant boundary escape makes this a severe multi-tenant risk.

Relevance score: 72.0/100

# More from August 30