[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"focus:critical-cpanel-flaw-could-let-one-hosting-customer-take-root-control-of-a-whole-mtdbnx7j":3},{"item":4},{"id":5,"title":6,"slug":7,"summary":8,"severity":9,"category":10,"cve_ids":11,"affected_products":13,"action_required":19,"article_ids":20,"ioc_summary":22,"source_urls":23,"status":25,"expires_at":26,"created_at":27,"updated_at":28,"articles":29},"ca521ca4-0a97-40e7-8259-f0254915d82d","Critical cPanel Flaw Could Let One Hosting Customer Take Root Control of a Whole Server","critical-cpanel-flaw-could-let-one-hosting-customer-take-root-control-of-a-whole-mtdbnx7j","A critical vulnerability in cPanel\u002FWHM (CVE-2026-65643) allows authenticated hosting customers to escalate privileges to root on shared servers via domain parking and addon domain features. Any customer account can exploit this to achieve full server compromise. If your infrastructure runs cPanel\u002FWHM, assume your multitenancy isolation is broken until patched.","critical","advisory",[12],"CVE-2026-65643",[14,15,16,17,18],"cPanel","WebHost Manager (WHM)","LiteSpeed cPanel plugin","Phusion Passenger","Plesk","Immediately patch all cPanel and WHM instances to patched versions. For unpatched systems, restrict addon domain and domain parking functionality at the account level until patches are deployed.",[21],"155a30a3-476a-4cda-9d7f-da75bd37bb74",null,[24],"https:\u002F\u002Fthehackernews.com\u002F2026\u002F08\u002Fcritical-cpanel-flaw-could-let-one.html","active","2026-08-30T19:05:45.018+00:00","2026-08-28T19:05:50.113086+00:00","2026-08-28T19:07:02.394739+00:00",[30],{"id":21,"title":6,"url":24}]