The record
Written from the 2 reports below. Nothing here is unsourced.
- cPanel has released patches for a critical vulnerability, tracked as CVE-2026-65643, affecting domain parking and addon domain functionality in cPanel and WHM.
- A hosting customer who can add parked or addon domains could use the flaw to create arbitrary files and run code with root privileges, giving full control of the server.
- All supported versions of cPanel and WHM are affected, and patched builds are available across the 110, 134, 136, and 138 branches, including WP Squared.
- Servers with automatic daily updates get the fix on their own, and administrators can also apply it manually by running /scripts/upcp --force as root or upgrading from WHM.
- The flaw matters because a single hosting customer could seize root control of a shared server, and cPanel has not confirmed whether any exploitation has occurred or provided any way to check for a past compromise.
What to watch next
- Whether cPanel clarifies support status for the 11.118 and 11.126 branches, which were named in July advisories but not in the August 27 list.
- Whether cPanel confirms or denies active exploitation, including any entry in CISA's Known Exploited Vulnerabilities catalog.
- Whether a CVE record and CVSS score are eventually published for CVE-2026-65643.
What changed2
Every report on this story, newest first. Times are when each outlet published.
Who said what3
Only words found exactly in the article are shown, attributed and linked to the line they came from.
Acronis
spokesperson for Acronis
1 quote · 1 outlet
“This update contains fixes for 1 high-severity security vulnerability and should be installed immediately by all users”
In the article
…to escalate their permissions on a susceptible Linux version, potentially enabling them to perform unauthorized actions or run arbitrary code that could impact the confidentiality and integrity of the application. " This update contains fixes for 1 high-severity security vulnerability and should be installed immediately by all users ," Acronis noted in a separate advisory for 1.9.3 HF3. "Exploitation of this vulnerability has been detected in the wild in limited, targeted attacks." There are currently no details about the vulnerability, or who is…
cPanel
1 quote · 1 outlet
“Successful exploitation leads to code execution as the root user, giving an attacker full control of the server”
In the article
…versions of cPanel & WHM. cPanel described the issue as a critical security vulnerability and said that an authenticated account holder who can add parked or addon domains can create arbitrary files on the server. " Successful exploitation leads to code execution as the root user, giving an attacker full control of the server ," cPanel said in a notification to customers. cPanel has released the following patched versions - - 11.110.0.141 or later - 11.134.0.53 or later - 11.136.0.37 or later - 11.138.0.2 or later - 11.138.1.7 or later (WP…
Plesk
1 quote · 1 outlet
“Patching closes the vulnerability going forward, but it does not undo anything an attacker may have already done”
In the article
…WebPros develops alongside cPanel, updated its own advisory for the same flaw on August 14, 2026, with a five-item checklist for spotting a prior compromise that begins with unexpected entries in /etc/ld.so.preload. " Patching closes the vulnerability going forward, but it does not undo anything an attacker may have already done ," Plesk said. Phusion, which develops Passenger, shipped a fix in Passenger 6.2.0 on August 18, 2026, for a Watchdog API flaw that does not have a CVE identifier. "We have seen exploitation of this vulnerability in the…
Why it matters3
Who is affected first and what likely follows, with a direction and a horizon. Extracted from the reports, never invented.
- cPanel environments root level code execution risk· immediate
- Acronis backup plugin users privilege escalation risk· immediate
- System administrators patch deployment required· days
Coverage1
All filed from IndiaSingle origin
Named United States · CageFS · CloudLinux · Web Host Manager · WebHost Manager · Acronis · CISA · cPanel · Phusion · Plesk
The 2 reports are listed beside the record.
Ask this story
Answers cite the reports above, or say they can't.

