Report Incident
× Home DPO CyberHub Rw-CSIRT Website About Rw-CSIRT Alerts Advisories About NCSA Documentation News & Events Topics Contact us Opportunities Privacy Policy

Security Alert: Critical cPanel & WHM Vulnerability – CVE-2026-65643

A critical vulnerability in cPanel & WHM, identified as CVE-2026-65643, was discovered in a feature used to add additional domain names to a hosting account. An authenticated cPanel user with permission to use this feature could exploit the vulnerability to gain full control of the affected server.
 
Affected Systems:
 
  • cPanel and WHM: All supported versions prior to 11.110.0.141, 11.134.0.53, 11.136.0.37, 11.138.0.2
  • WP Squared (WP2): All supported versions prior to 11.138.1.7
 
Security Risks
 
Successful exploitation could allow an authenticated attacker with the required permissions to execute code with root-level privileges, resulting in full control of the server and potentially affecting all accounts, websites, and databases hosted on it.
 
For more information on this vulnerability and related updates, please refer to official cPanel security advisory for CVE-2026-65643.
 
Recommended Actions
 
The National Cyber Security Authority (NCSA) recommends users and system administrators:
 
  • Upgrade cPanel and WHM to the latest supported versions to ensure continued access to security patches and technical support.
 
The recommended versions are:
 
  • cPanel and WHM: upgrade to version 11.110.0.141 or above, 11.134.0.53 or above, 11.136.0.37 or above, 11.138.0.2 or above.
  • WP Squared (WP2): Upgrade to version 11.138.1.7 or above.
  • Review and restrict permissions for cPanel accounts that can add additional domain names, ensuring that access is granted only to authorized users.
  • Verify that the installed cPanel & WHM version meets one of the fixed versions specified by cPanel.
  • Ensure valid backups are available before applying updates.
 
For further information and support, please contact the National Cyber Security Authority (NCSA) by emailto rwcsirt@ncsa.gov.rw or call us on 9009.
 
References

31 August 2026

© 2026 National Cyber Security Authority