Advisory ID: ngCERT-2026-090003
Damage: Critical (CVSS Score: 9.8)
Probability: High
Platform(s): cPanel & WHM and WP Squared
SUMMARY
ngCERT is alerting organisations, businesses, government agencies, website administrators and hosting providers to a critical security vulnerability in cPanel & WHM and WP Squared. The vulnerability, tracked as (CVE-2026-65643), can allow an authenticated hosting customer who can add parked or add-on domains to create arbitrary files on the server. Successful exploitation could lead to code execution as the root user, giving an attacker full control of the server and every account, website and database hosted on it. The vulnerability is rated Critical with a CVSS Score of 9.8 and affects all supported versions of cPanel & WHM. Although patches have been released to fix the flaw, organisations and hosting providers are advised to treat this vulnerability as a high-priority patching requirement.
DESCRIPTION
CVE-2026-65643 is a critical vulnerability in the domain parking and add-on domain functionality of cPanel & WHM. An authenticated cPanel account holder who has permission to add parked or addon domains can exploit the flaw to create arbitrary files anywhere on the underlying server. This capability can be leveraged to achieve code execution as the root user. Domain parking is a routine feature enabled by default for most shared-hosting customers, meaning the attack surface is present on virtually every multi-tenant cPanel environment. Successful exploitation gives the attacker unrestricted control over the entire machine, including every other customer account, website, database and email service hosted on the same server. Affected products are all currently supported versions of cPanel & WHM below. However, the vendor has released security fixes in builds 11.110.0.141, 11.134.0.53, 11.136.0.37, 11.138.0.2 and later, and WP Squared 11.138.1.7 or later.
CONSEQUENCES
Successful exploitation could result to the following:
- Access to, modification and removal data belonging to every hosted account, website, application, and database.
- Deployment persistent backdoors and malware across all tenants.
- Theft of credentials, TLS certificates, and configuration secrets.
- Alteration of website content, server configurations, and service settings.
- Use of compromised server as a pivot point for further attack.
SOLUTION/MITIGATION
ngCERT recommends that organisations:
- Immediately update all affected systems to a patched build of cPanel & WHM (11.110.0.141, 11.134.0.53, 11.136.0.37, 11.138.0.2 or later) or WP Squared (11.138.1.7 or later) using /scripts/upcp --force or the WHM upgrade interface.
- Prioritise multi-tenant shared and reseller servers for patching due to the elevated risk of cross-account compromise.
- Temporarily disable the Parked Domains and Addon Domains features in customer feature lists through WHM where immediate patching is not feasible.
- Verify the installed cPanel build on every server after updating and confirm it matches a patched version.
- Audit servers for signs of prior exploitation, including unexpected files outside home directories, unauthorised root processes, new privileged accounts, and anomalous network activity.
- Isolate any system showing indicators of compromise, preserve forensic evidence, and restore from known-good backups after removing malicious artefacts.
- Reset credentials for root, WHM, and all administrative accounts on systems that may have been exposed.
- Enforce least-privilege feature lists so that ordinary customer accounts cannot manage parked or addon domains unless operationally required.
- Enable automatic daily updates for cPanel where compatible with change-management processes to reduce exposure to future similar flaws.
- Maintain a current inventory of all cPanel and WP Squared instances, retain tested backups, and continuously monitor multi-tenant hosts for suspicious behaviour.
HYPERLINK