cPanel has released fixed builds for CVE-2026-65643, a flaw in cPanel & WHM that can let an authenticated customer with parked-domain or addon-domain rights reach root code execution on the server. The vendor’s August 27 advisory says the issue affects supported versions and that successful exploitation can give full control of the host.
The weakness sits in normal domain-management features: if a tenant can add parked or addon domains, cPanel can be led into creating files in a way that later runs with root privileges instead of the customer’s. That means the blast radius is the whole server, not just the account that triggered it.
The patch list names the 110, 134, 136, and 138 branches, plus WP Squared, but does not mention DNSOnly or the older 11.118 and 11.126 lines. For mixed cPanel estates, the open question is whether every product flavor you run is actually covered by the published fixed-build list.