Critical cPanel Flaw Could Let a Single Hosting Customer Seize Full Server Control
cPanel has released urgent patches for a critical security flaw found in its domain parking and addon domain functionality within cPanel and WebHost Manager (WHM), widely used software for managing web hosting accounts. The vulnerability, tracked as CVE-2026-65643, affects all supported versions of cPanel & WHM and could allow malicious code to be executed with root-level privileges - the highest level of access on a server.
What makes this flaw especially concerning is its potential impact on shared hosting environments, where multiple websites and businesses often run on the same physical server. A single hosting customer exploiting this vulnerability could theoretically take control of the entire server, potentially exposing or compromising every other website and business hosted alongside them. cPanel has classified this as a critical vulnerability, reflecting the severity of the risk it poses.
Many Australian small businesses rely on shared hosting providers that use cPanel or WHM to manage their websites and email systems, making this a relevant issue even for businesses that don't manage their own servers directly. While the responsibility for applying server-level patches typically falls on the hosting provider, business owners should be proactive in confirming their provider's security posture.