AI Weekly Malaysia

Back to items Summaries

Critical cPanel Flaw Could Let One Hosting Customer Take Root Control of a Whole Server

ID
18987
Status
summarized
Published
28 Aug 2026, 5:45 PM
Fetched
28 Aug 2026, 7:29 PM
Provider
The Hacker News
Category
security
Original URL
https://thehackernews.com/2026/08/critical-cpanel-flaw-could-let-one.html
Source URL
https://feeds.feedburner.com/TheHackersNews

Summary

Score
6.5
Created
28 Aug 2026, 7:33 PM
Tags
Audience
developersvibe_coderssaas_founders

What happened

cPanel patched CVE-2026-65643, a critical flaw in domain parking and addon domain functionality that lets any authenticated hosting customer who can add parked/addon domains create arbitrary files and escalate to root, giving full server control. Patched builds are 11.110.0.141, 11.134.0.53, 11.136.0.37, 11.138.0.2, and 11.138.1.7 (WP Squared); servers with automatic daily updates get the fix automatically, or admins can run /scripts/upcp --force.

Why it matters

If you run or rent on a cPanel/WHM shared hosting server, a single tenant on that box can now root the entire machine—so verify your provider has applied the patch or, if you administer the box, run /scripts/upcp --force immediately and confirm the build number under Server Configuration > Update Preferences. End-of-life cPanel versions cannot receive the fix and must be upgraded to a supported branch.

Discussion angle

How many Malaysian startups and agencies still ship on cPanel shared hosting, and what's the realistic migration path when a single co-tenant can now own the whole server?

Top