cPanel flaws are not just panel bugs. They hit the hosting control plane, so an authenticated account can move from one login to code execution, file reads, or permission changes that affect customer sites and data across a shared environment.
cPanel and WHM now patch CVE-2026-29201, CVE-2026-29202, and CVE-2026-29203. The issues cover arbitrary file read, arbitrary Perl code execution on behalf of an already authenticated account’s system user, and unsafe symlink handling that can alter permissions on arbitrary files; fixed builds include 11.136.0.9, 11.134.0.25, 11.132.0.31, 11.130.0.22, 11.126.0.58, 11.124.0.37, 11.118.0.66, 11.110.0.116, and 11.110.0.117 or higher.
There is no evidence of in-the-wild exploitation for these three flaws. The risk that persists is blast radius: in shared hosting, compromise does not stay confined to the panel host, because the panel is the layer that manages customer accounts, permissions, and hosted content.