Dear Customer,
We are writing to inform you of a critical security vulnerability affecting cPanel & WHM. cPanel has released patched versions, and we strongly recommend ensuring that your server is updated as soon as possible.
Vulnerability:
CVE-2026-65643 – Vulnerability in cPanel's Domain Parking Functionality
What is the issue?
An authenticated cPanel account with permission to add parked or addon domains could potentially create arbitrary files on the server.
Potential impact:
Successful exploitation could allow an attacker to execute code with root-level privileges, potentially resulting in complete control of the affected server.
The vulnerability affects all currently supported cPanel & WHM versions.
Please ensure your server is running one of the following patched versions or later:
If your server is managed by Sysop Solutions, we will assess the applicable update status and take the necessary action according to your server management configuration.
If you manage your server yourself, we recommend updating cPanel & WHM immediately.
Servers configured for automatic daily updates should receive the patched build automatically.
To apply the update immediately, log in to your server as root and run:
For complete technical details, please refer to the official cPanel security advisory:
Security: CVE-2026-65643 – Vulnerability in cPanel's Domain Parking Functionality
We strongly recommend treating this update as a high-priority security measure to help protect your server, websites, accounts, and hosted data.
If you are unsure whether your server is affected or require assistance with the update, please contact Sysop Solutions Support.
Regards,
Sysop Solutions
Your Trusted Hosting & Server Management Partner