Monitor this situation.
Unsubscribe anytime.
[SITUATION] · [ACTIVE] · [TECHNOLOGY]
2 clusters · 5 sources · 13 days · First seen · Last updated
cPanel and WHM security vulnerabilities
Overview
A series of critical security vulnerabilities has been identified in cPanel and WHM web hosting control panel software, both of which allow authenticated users to gain root-level control of entire servers.
In late August, a vulnerability tracked as CVE-2026-65643 was discovered within the domain parking functionality. This flaw could allow low-privileged users to create arbitrary files and execute code as the root user, potentially exposing all websites, databases, and email accounts in shared hosting environments. In response, some providers temporarily disabled the creation of new subdomains, addon domains, and parked domains.
In early September, a second critical vulnerability, CVE-2026-67401, was identified involving a SQL injection within the EmailTrack function. This flaw similarly allows users with mail-related privileges to bypass security boundaries and execute code with root privileges. cPanel has since released patches across several software versions to address this second exploit.
Entities
Timeline
-
3 days ago
[TECHNOLOGY] 2 sourcescPanel patches critical vulnerability allowing root access via EmailTrackA critical cPanel vulnerability (CVE-2026-67401) allows users with mail privileges to exploit an EmailTrack SQL injection to gain full root access to servers.
-
16 days ago
[TECHNOLOGY] 3 sourcescPanel vulnerability allows attackers to seize full server controlA critical vulnerability in cPanel's domain parking feature (CVE-2026-65643) allows authenticated users to potentially seize root-level control of entire hosting servers.
Sources
blogspan.net · cybersecuritynews.com · it-boltwise.de · reclaimhosting.com · thehackernews.com