A critical vulnerability in cPanel & WHM, identified as CVE-2026-65643, was discovered in a feature used to add additional domain names to a hosting account. An authenticated cPanel user with permission to use this feature could exploit the vulnerability to gain full control of the affected server.
Affected Systems:
cPanel and WHM: All supported versions prior to 11.110.0.141, 11.134.0.53, 11.136.0.37, 11.138.0.2
WP Squared (WP2): All supported versions prior to 11.138.1.7
Security Risks
Successful exploitation could allow an authenticated attacker with the required permissions to execute code with root-level privileges, resulting in full control of the server and potentially affecting all accounts, websites, and databases hosted on it.