WebPros security advisory (AV26-861)
Canada's Cyber Centre relayed a cPanel advisory for CVE-2026-65643, a domain parking vulnerability fixed in multiple cPanel/WHM releases; admins should update.
Canada's Cyber Centre issued advisory AV26-861 relaying cPanel's disclosure of CVE-2026-65643, a vulnerability in cPanel's Domain Parking functionality. Affected cPanel & WebHost Manager (WHM) builds include all releases prior to 11.110.0.141, 11.134.0.53, 11.136.0.37, 11.138.0.2, and WP2 11.138.1.7. Administrators are urged to review vendor guidance and apply updates. No exploitation details were provided in the advisory.
- CVE-2026-65643 affects cPanel domain parking functionality
- Fixed in 11.110.0.141, 11.134.0.53, 11.136.0.37, 11.138.0.2, and WP2 11.138.1.7
- Canadian Cyber Centre urges administrators to apply updates
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-65643 | Authenticated eval injection in cPanel enables root code execution cPanel 11.138.0.0 and earlier contains an eval injection flaw (CWE-95) in which attacker-controlled input reaches dynamic code evaluation without proper neutralization. A remote attacker holding any authenticated account on a cPanel server, such as an ordinary hosting customer, can trigger the flaw with crafted input and no user interaction. Successful exploitation yields arbitrary code execution as root, meaning a single low-privilege tenant can compromise the entire server and every site hosted on it. All deployments running version 11.138.0.0 or earlier are affected, which at disclosure covers essentially all active cPanel servers given that this was the current release. No public proof-of-concept or confirmed in-the-wild exploitation is known; the issue is not in CISA KEV and EPSS assigns only a 0.9% probability of exploitation within 30 days. Do: Upgrade cPanel/WHM to a fixed release above 11.138.0.0 published under WebPros advisory AV26-861, prioritizing multi-tenant shared servers where any customer account can reach the vulnerable code. Until patched, restrict shell and feature access for untrusted accounts and review authentication logs and unexpected root-owned processes. No workaround is documented in the available data, so updating is the primary action. | 8.7 | <1% |
| massroughly hundreds of thousands of cPanel/WHM servers (millions of hosted sites on multi-tenant shared hosting) |
Serial Number: AV26-861 Date: August 28, 2026 As of August 27, 2026, WebPros is affected by vulnerabilities in the following products: cPanel & WebHost Manager (WHM) software Prior to 11.110.0.141 Prior to 11.134.0.53 Prior to 11.136.0.37 Prior to 11.138.0.2 Prior to WP2: 11.138.1.7 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available Security: CVE-2026-65643 Vulnerability in cPanel’s Domain Parking Functionality - August 27, 2026 cPanel Security
This source does not provide full text. Read it at cyber.gc.ca.