Critical cPanel & WHM Security Update Required – CVE-2026-65643

  • Friday, 28th August, 2026
  • 06:09am

Dear Customer,

Important Security Advisory from Sysop Solutions
Please ignore this notice if your server does not use cPanel & WHM.

We are writing to inform you of a critical security vulnerability affecting cPanel & WHM. cPanel has released patched versions, and we strongly recommend ensuring that your server is updated as soon as possible.

Critical cPanel Security Vulnerability

Vulnerability:
CVE-2026-65643 – Vulnerability in cPanel's Domain Parking Functionality

What is the issue?
An authenticated cPanel account with permission to add parked or addon domains could potentially create arbitrary files on the server.

Potential impact:
Successful exploitation could allow an attacker to execute code with root-level privileges, potentially resulting in complete control of the affected server.

Affected Versions

The vulnerability affects all currently supported cPanel & WHM versions.

Patched Versions

Please ensure your server is running one of the following patched versions or later:

  • 11.110.0.141 or later
  • 11.134.0.53 or later
  • 11.136.0.37 or later
  • 11.138.0.2 or later
  • 11.138.1.7 or later (WP Squared)

Action Recommended

If your server is managed by Sysop Solutions, we will assess the applicable update status and take the necessary action according to your server management configuration.

If you manage your server yourself, we recommend updating cPanel & WHM immediately.

If Automatic Updates Are Enabled

Servers configured for automatic daily updates should receive the patched build automatically.

Force an Immediate Update

To apply the update immediately, log in to your server as root and run:

/scripts/upcp --force

Alternatively, Update Through WHM

  1. Log in to WHM.
  2. Navigate to Home → cPanel → Upgrade to Latest Version.
  3. Install the latest available cPanel & WHM update.
  4. Verify the installed version under Server Configuration → Update Preferences.
Important: If your server is running an end-of-life (EOL) cPanel version, you will need to upgrade to a supported version before receiving this security fix.

Official cPanel Security Advisory

For complete technical details, please refer to the official cPanel security advisory:

Security: CVE-2026-65643 – Vulnerability in cPanel's Domain Parking Functionality

We strongly recommend treating this update as a high-priority security measure to help protect your server, websites, accounts, and hosted data.

If you are unsure whether your server is affected or require assistance with the update, please contact Sysop Solutions Support.

Regards,
Sysop Solutions
Your Trusted Hosting & Server Management Partner

« Back